Anonymous
2026-09-06 06:20:09
(6 minutes ago)
| Suspicious URL access.
Web App Attack
Hacking
SQL Injection
🇺🇸
TPI-Abuse
2026-09-06 03:54:46
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.80.0.192 (192.0.80.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.0.192 (192.0.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:54:36.224851 2026] [security2:error] [pid 3717825:tid 3717825] [client 34.80.0.192:33004] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.joepaladino.com"] [uri "/.env"] [unique_id "apzj_GIvjHv6n0nwZJRQjgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
netclix.gr
2026-09-06 03:33:19
(2 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.80.0.192 (TW/Taiwan/192.0.80.34.bc.g ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.80.0.192 (TW/Taiwan/192.0.80.34.bc.googleusercontent.com): (CF_ENABLE)
show less
SQL Injection
🇺🇸
TPI-Abuse
2026-09-06 02:57:08
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.80.0.192 (192.0.80.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.0.192 (192.0.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:57:01.777650 2026] [security2:error] [pid 23343:tid 23343] [client 34.80.0.192:52182] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.tribalvisions.net"] [uri "/.env.production"] [unique_id "apzWfVsOzQhKRFQeqpPgbgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
neckaralb-admin.de
2026-09-06 01:31:52
(4 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇳🇱
e.fierstra
2026-09-06 00:32:34
(5 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇪🇸
tg_de
2026-09-06 00:17:52
(6 hours ago)
19 attempts since 06.09.2026 00:17:52 UTC - last search for: /.env.backup
Web App Attack
🇩🇪
seal
2026-09-05 23:57:13
(6 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
SSH
Brute-Force
🇩🇪
FeG Deutschland
2026-09-05 23:47:28
(6 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
🇩🇪
Marc
2026-09-05 22:52:07
(7 hours ago)
34.80.0.192 - - [06/Sep/2026:00:52:06 +0200] "GET /_ignition/health-check HTTP/1.1" 404 4616 "-" "cr ...
show more
34.80.0.192 - - [06/Sep/2026:00:52:06 +0200] "GET /_ignition/health-check HTTP/1.1" 404 4616 "-" "crusader-worker/1.0" 34.80.0.192 - - [06/Sep/2026:00:52:06 +0200] "GET /.env.prod HTTP/1.1" 404 4617 "-" "crusader-worker/1.0" 34.80.0.192 - - [06/Sep/2026:00:52:06 +0200] "GET /wp-config.php.swp HTTP/1.1" 404 4616 "-" "crusader-worker/1.0"
show less
Brute-Force
🇺🇸
TPI-Abuse
2026-09-05 21:41:24
(8 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.80.0.192 (192.0.80.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.80.0.192 (192.0.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 17:41:17.741251 2026] [security2:error] [pid 9366:tid 9366] [client 34.80.0.192:49124] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||virginiatouchatruck.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "virginiatouchatruck.com"] [uri "/database.sql"] [unique_id "apyMffk1DeyHkGsTwQIQnAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-05 21:13:41
(9 hours ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 21:12:51
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.80.0.192 (192.0.80.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.0.192 (192.0.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 17:12:46.953852 2026] [security2:error] [pid 22159:tid 22159] [client 34.80.0.192:53498] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "harrygant.com"] [uri "/wp-config.php~"] [unique_id "apyFzk6xepZoThq3-GwVwQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇯🇵
knock
2026-09-05 07:23:09
(23 hours ago)
Knock-Knock honeypot brute-force: HTTP (19 total hits)
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 15:20:15
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.80.0.192 (192.0.80.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.0.192 (192.0.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:20:09.514187 2026] [security2:error] [pid 22328:tid 22328] [client 34.80.0.192:60598] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.whitetaildetailing.com"] [uri "/.env.old"] [unique_id "aprhqcdfjG0xn5UhT93E9AAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack