๐บ๐ธ
TPI-Abuse
2026-09-01 13:59:17
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.80.250.42 (42.250.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.250.42 (42.250.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 09:59:11.334289 2026] [security2:error] [pid 21115:tid 21115] [client 34.80.250.42:45304] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.lesdwiniarczyk.com"] [uri "/wp-config.php.swp"] [unique_id "apbaL00NS21IhTGSRfdrmgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
dbmwebdesign
2026-09-01 13:10:03
(1 day ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
๐ฉ๐ช
Vegascosmetics
2026-09-01 13:03:26
(1 day ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after PHP/CMS/webshell exploit probe (possi ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after PHP/CMS/webshell exploit probe (possible exploited host). Evidence: AttackPattern: /wp-config\.php (Match: /wp-config.php)
show less
Hacking
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 11:17:34
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.80.250.42 (42.250.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.250.42 (42.250.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 07:17:30.702409 2026] [security2:error] [pid 5769:tid 5769] [client 34.80.250.42:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.wiszen.org"] [uri "/.env.bak"] [unique_id "apa0SjG_nhcW2xEA_v4c5AAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Lunix
2026-09-01 11:13:43
(1 day ago)
Brute-Force
Web App Attack
๐ฉ๐ช
FD-IX
2026-09-01 10:57:46
(1 day ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 10:57:12
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.80.250.42 (42.250.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.250.42 (42.250.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 06:57:05.148138 2026] [security2:error] [pid 15085:tid 15085] [client 34.80.250.42:39202] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.sutherlandyogastudio.com"] [uri "/.env.production"] [unique_id "apavgWPg3nt7WI2X1kQkCAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-01 10:26:27
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
๐ธ๐ช
SkyDancer
2026-09-01 10:04:13
(1 day ago)
Multiple unauthorized attempts to access using wrong credentials. Attack automatically blocked by Sk ...
show more
Multiple unauthorized attempts to access using wrong credentials. Attack automatically blocked by SkyDancer Ai. EXT-SYS-Vx
show less
Hacking
Brute-Force
SSH
Anonymous
2026-09-01 09:36:04
(1 day ago)
Bot / scanning and/or hacking attempts: GET /.env HTTP/1.1, GET /actuator/configprops HTTP/1.1, GET ...
show more
Bot / scanning and/or hacking attempts: GET /.env HTTP/1.1, GET /actuator/configprops HTTP/1.1, GET /crusader-404-probe HTTP/1.1
show less
Hacking
Web App Attack
๐บ๐ธ
NerdyMcNerderson
2026-09-01 08:31:59
(1 day ago)
MarekCloud auto-ban: Bot honeypot: GET /actuator/env
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-01 08:18:38
(1 day ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-196)
Hacking
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-01 08:17:59
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐ฉ๐ช
maxpower
2026-09-01 08:02:31
(1 day ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.80.250.42 (TW/Taiwan/42.250.80.34.bc. ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.80.250.42 (TW/Taiwan/42.250.80.34.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.80.250.42 - - [01/Sep/2026:10:02:29 +0200] "GET /wp-config.php.bak HTTP/1.1" 403 146 "-" "crusader-worker/1.0" "-" host=samimanutenzionisrl.samitecnopetrol.it
show less
Port Scan
๐ฟ๐ฆ
conure.sh
2026-09-01 07:45:44
(1 day ago)
csagent: score 20.0: secrets grab x2; 1 domain(s) in 0s
Web App Attack