🇬🇧
kie
2026-09-06 21:15:10
(1 hour ago)
06-09-2026:21:15:03UTC [Nginx Web Server] Suspicious web request: path:/.env path:/.aws/ (20 request ...
show more
06-09-2026:21:15:03UTC [Nginx Web Server] Suspicious web request: path:/.env path:/.aws/ (20 request(s)).
show less
Bad Web Bot
Web App Attack
🇺🇸
infra-monitor
2026-09-06 21:00:04
(1 hour ago)
Automated ban via infra-monitor: suspicious-probe, crowdsecurity/http-path-traversal-probing, crowds ...
show more
Automated ban via infra-monitor: suspicious-probe, crowdsecurity/http-path-traversal-probing, crowdsecurity/http-probing
show less
Port Scan
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 20:15:49
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.81.122.201 (201.122.81.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.81.122.201 (201.122.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 16:15:42.999570 2026] [security2:error] [pid 3693:tid 3716] [client 34.81.122.201:36410] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||michaelmercier.com|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "michaelmercier.com"] [uri "/localhost.key"] [unique_id "ap3J7uAluAXxkD5NZRaYkAAAAVU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 19:48:06
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.81.122.201 (201.122.81.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.81.122.201 (201.122.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 15:48:00.416285 2026] [security2:error] [pid 18488:tid 18488] [client 34.81.122.201:33870] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.michelehoop.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.michelehoop.com"] [uri "/rclone.conf"] [unique_id "ap3DcEq-Ue7e8CBV1CLWeAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-06 19:41:00
(2 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.aws/credentials (+3 more) | 2026-09-06 19:41 UTC
show less
Hacking
Web App Attack
Anonymous
2026-09-06 19:11:24
(3 hours ago)
34.81.122.201 - - [06/Sep/2026:21:11:22 +0200] "GET /wp-config.php.bak HTTP/2.0" 429 162 "-" "Mozill ...
show more
34.81.122.201 - - [06/Sep/2026:21:11:22 +0200] "GET /wp-config.php.bak HTTP/2.0" 429 162 "-" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/)" "-" "X"
34.81.122.201 - - [06/Sep/2026:21:11:22 +0200] "GET /wp-config.php.old HTTP/2.0" 429 162 "-" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)" "-" "X"
34.81.122.201 - - [06/Sep/2026:21:11:23 +0200] "GET /configuration.php.bak HTTP/2.0" 429 162 "-" "Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)" "-" "X"
34.81.122.201 - - [06/Sep/2026:21:11:23 +0200] "GET /.env.php.bak HTTP/2.0" 429 162 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)" "-" "X"
34.81.122.201 - - [06/Sep/2026:21:11:23 +0200] "GET /config.php.bak HTTP/2.0" 429 162 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)" "-" "X"
34.81.122.201 - - [06/Sep/2026:21:11:23 +0200] "GET /config/.env.php HTTP/2.0" 429 162 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )" "-" "X"
show less
Brute-Force
🇺🇸
deskpass.com
2026-09-06 18:07:21
(4 hours ago)
GET /login
Web App Attack
🇱🇹
Evag Touf
2026-09-06 16:41:40
(5 hours ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 34.81.122.201 (TW/Ta ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 34.81.122.201 (TW/Taiwan/201.122.81.34.bc.googleusercontent.com)
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-06 16:21:17
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.81.122.201 (201.122.81.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.122.201 (201.122.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 12:21:10.732220 2026] [security2:error] [pid 2592:tid 2592] [client 34.81.122.201:59128] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "micro-analisis.com"] [uri "/%2e%2e/.env"] [unique_id "ap2S9o0JlKWVyb6dyVVgIgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 15:46:55
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.81.122.201 (201.122.81.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.122.201 (201.122.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 11:46:47.246077 2026] [security2:error] [pid 7338:tid 7338] [client 34.81.122.201:43870] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.michaelgatley.com"] [uri "/images../.env"] [unique_id "ap2K55n_oGQyZUbkBTldYQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Octopuce
2026-09-06 15:17:40
(7 hours ago)
Aggressive web search of vulnerable pages: //.env /static//app/.env /.//.env /assets../.env /images. ...
show more
Aggressive web search of vulnerable pages: //.env /static//app/.env /.//.env /assets../.env /images../.env ...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 14:05:01
(8 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.81.122.201 (201.122.81.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.81.122.201 (201.122.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 10:04:55.627102 2026] [security2:error] [pid 31722:tid 31722] [client 34.81.122.201:47798] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.microkerneltechnologies.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.microkerneltechnologies.com"] [uri "/rclone.conf"] [unique_id "ap1zBwzOuWBam43oztglcwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇭
backslash
2026-09-06 13:27:00
(9 hours ago)
block ruleset WAF detection and high score on abuseIPDB 149EB1B42C242111FADBBC2EF8F90219570691E1
Bad Web Bot
🇳🇱
Alboweb B.V.
2026-09-06 13:11:08
(9 hours ago)
Bad web bot activity detected by Fail2Ban in plesk-apache-badbot jail
Bad Web Bot
🇳🇱
Savvii
2026-09-06 10:57:42
(11 hours ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack