🇬🇧
consul.to
2026-09-04 14:41:42
(37 minutes ago)
Web attack/malicious scanning detected
Web App Attack
🇩🇪
4server
2026-09-04 14:08:36
(1 hour ago)
[FriSep0416:08:33.1126822026][security2:error][pid247404:tid247510][client34.81.92.239:0]ModSecurity ...
show more
[FriSep0416:08:33.1126822026][security2:error][pid247404:tid247510][client34.81.92.239:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"webmail.hdcadvisory.ch\"][uri\"/wp-config.php~\"][unique_id\"aprQ4dwqFB_L3tUzwZdo4AAAANI\"]
show less
Port Scan
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 12:11:48
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.81.92.239 (239.92.81.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.92.239 (239.92.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:11:42.649223 2026] [security2:error] [pid 23318:tid 23318] [client 34.81.92.239:44904] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "franklycommerce.springmeadowventures.com"] [uri "/.env.prod"] [unique_id "apq1fkrQZ6uu3kaRyCeyjwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-04 11:07:22
(4 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-04 11:06:22
(4 hours ago)
Multiple WAF Violations
Web App Attack
🇫🇷
Baking333
2026-09-04 10:18:35
(5 hours ago)
[redacted] 34.81.92.239 - - [04/Sep/2026:11:18:31 +0100] "GET /.[redacted] HTTP/2.0" 301 295 "-" "cr ...
show more
[redacted] 34.81.92.239 - - [04/Sep/2026:11:18:31 +0100] "GET /.[redacted] HTTP/2.0" 301 295 "-" "crusader-worker/1.0" [redacted] 34.81.92.239 - - [04/Sep/2026:11:18:31 +0100] "GET /.[redacted] HTTP/2.0" 301 294 "-" "crusader-worker/1.0"
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 09:33:07
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.81.92.239 (239.92.81.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.92.239 (239.92.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 05:33:02.819678 2026] [security2:error] [pid 7994:tid 7994] [client 34.81.92.239:41464] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "qatest.soudertonbigred.org"] [uri "/.env.example"] [unique_id "apqQTkIUVuYHzKPiunqSbQAAADk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-02 23:51:08
(1 day ago)
Excessive multi-domain requests
Brute-Force
🇬🇧
openstrike.co.uk
2026-09-02 05:13:21
(2 days ago)
13 attacks on env grabbing URLs, PHP URLs:
GET /.env.prod HTTP/1.1
GET /wp-config.php.bak HTTP/1.1
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-01 13:12:37
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.81.92.239 (239.92.81.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.92.239 (239.92.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 09:12:31.466660 2026] [security2:error] [pid 19652:tid 19652] [client 34.81.92.239:53470] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kwcccarshow.com"] [uri "/wp-config.php~"] [unique_id "apbPPw5qOAmiO2_ye0mxfgAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Hans Wurst
2026-09-01 12:38:01
(3 days ago)
Many 404-Error: Suspicion of URL-Fuzzing/Bot-Scan.
Web App Attack
🇺🇸
TPI-Abuse
2026-09-01 11:07:41
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.81.92.239 (239.92.81.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.92.239 (239.92.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 07:07:33.765588 2026] [security2:error] [pid 14765:tid 14765] [client 34.81.92.239:37704] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.rockitfish.com"] [uri "/wp-config.php.swp"] [unique_id "apax9bO2_83CtPcx7r7G6gAAADU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-01 10:46:55
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.81.92.239 (239.92.81.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.92.239 (239.92.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 06:46:48.789938 2026] [security2:error] [pid 691:tid 691] [client 34.81.92.239:50610] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "peaksalesnw.com"] [uri "/wp-config.php.bak"] [unique_id "apatGKImWIAiyi6we-JwZwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-01 10:29:24
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.81.92.239 (239.92.81.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.92.239 (239.92.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 06:29:16.503212 2026] [security2:error] [pid 19095:tid 19095] [client 34.81.92.239:44076] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "usagreenrecycling.mapleleaf-marketing.com"] [uri "/.env"] [unique_id "apao_Orq-If6S42jGtQ3qQAAAIo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
raph
2026-09-01 10:26:54
(3 days ago)
[Wordpress] crawler /wp-admin/*, /wp-content/*, etc.
Bad Web Bot
Web App Attack