🇦🇺
AWW-Admin
2026-09-04 14:46:06
(14 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.81.192.1 (TW/Taiwan/1.192.81.34.bc.g ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.81.192.1 (TW/Taiwan/1.192.81.34.bc.googleusercontent.com)
show less
SQL Injection
🇺🇸
TPI-Abuse
2026-09-04 14:12:21
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.81.192.1 (1.192.81.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.192.1 (1.192.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:12:13.761271 2026] [security2:error] [pid 25846:tid 25846] [client 34.81.192.1:44964] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.mountainretreatcenter.com"] [uri "/.env"] [unique_id "aprRvc1xefnkiqhKxrygdgAAADg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
raph
2026-09-04 13:45:24
(15 hours ago)
[Wordpress] crawler /wp-admin/*, /wp-content/*, etc.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 12:22:51
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.81.192.1 (1.192.81.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.192.1 (1.192.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:22:43.849618 2026] [security2:error] [pid 22981:tid 22981] [client 34.81.192.1:35988] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "icwcruisersguide.com"] [uri "/wp-config.php.swp"] [unique_id "apq4E6i66yOaCfb0p4qrbwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇪🇸
elcruzado.es
2026-09-04 12:17:08
(17 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.81.192.1 (TW/Taiwan/1.192.81.34.bc.g ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.81.192.1 (TW/Taiwan/1.192.81.34.bc.googleusercontent.com)
show less
SQL Injection
🇺🇸
TPI-Abuse
2026-09-04 11:44:21
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.81.192.1 (1.192.81.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.192.1 (1.192.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:44:13.101084 2026] [security2:error] [pid 1395:tid 1395] [client 34.81.192.1:42328] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.l39capital.com"] [uri "/wp-config.php.bak"] [unique_id "apqvDeT-gkf3AUFMC9cTkwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:15:45
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.81.192.1 (1.192.81.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.192.1 (1.192.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:15:37.610417 2026] [security2:error] [pid 31378:tid 31378] [client 34.81.192.1:51854] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.brianwhitty.com"] [uri "/wp-config.php~"] [unique_id "apqoWYe9DjB3gCQjPFne5gAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇭🇺
miszterx.hu
2026-09-04 11:03:38
(18 hours ago)
XORP (haproxy): 19x HTTP 404/403/500 or handshake failure in 24h. Automated report from log_check_ip ...
show more
XORP (haproxy): 19x HTTP 404/403/500 or handshake failure in 24h. Automated report from log_check_iptables_generator.sh (xorp.hu)
show less
Web App Attack
🇩🇪
YF
2026-09-04 11:00:24
(18 hours ago)
WordPress config file probe
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:41:14
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.81.192.1 (1.192.81.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.192.1 (1.192.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:41:10.299181 2026] [security2:error] [pid 17090:tid 17090] [client 34.81.192.1:36466] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lajoze.com"] [uri "/.env.example"] [unique_id "apqgRu4FA11LD9qTvKT0UQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-04 10:15:49
(19 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇦
URAN Publishing Service
2026-09-04 10:11:07
(19 hours ago)
[04/Sep/2026:13:11:06 +0300] -- 34.81.192.1 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env.l ...
show more
[04/Sep/2026:13:11:06 +0300] -- 34.81.192.1 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env.local HTTP/1.1
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 08:17:17
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.81.192.1 (1.192.81.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.192.1 (1.192.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 04:17:13.036519 2026] [security2:error] [pid 32151:tid 32151] [client 34.81.192.1:56828] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.tidarat.com"] [uri "/wp-config.php.bak"] [unique_id "app-ibsPZIdeG5EL8VZdtQAAACo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Bedios GmbH
2026-09-04 08:00:59
(21 hours ago)
Login credentials theft attempt
Hacking
🇺🇸
TPI-Abuse
2026-09-04 07:58:32
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.81.192.1 (1.192.81.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.192.1 (1.192.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 03:58:28.013409 2026] [security2:error] [pid 4691:tid 4789] [client 34.81.192.1:46924] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ioqm.com"] [uri "/.env.backup"] [unique_id "app6JIZiW6PqWYUwGvUTjQAAAQg"]
show less
Brute-Force
Bad Web Bot
Web App Attack