π«π·
rellik
2026-09-01 13:58:00
(15 hours ago)
Brute Force Scanning Critical Files & Directories
Hacking
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 13:47:12
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.85.133.105 (105.133.85.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.85.133.105 (105.133.85.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 09:47:07.078052 2026] [security2:error] [pid 23558:tid 23558] [client 34.85.133.105:52734] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.roseweddingfavors.com"] [uri "/.env.local"] [unique_id "apbXW11_pwPw54bfAN9wEQAAAD4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
Marc
2026-09-01 13:10:34
(16 hours ago)
34.85.133.105 - - [01/Sep/2026:15:10:33 +0200] "GET /.env.dev HTTP/1.1" 404 4616 "-" "crusader-worke ...
show more
34.85.133.105 - - [01/Sep/2026:15:10:33 +0200] "GET /.env.dev HTTP/1.1" 404 4616 "-" "crusader-worker/1.0" 34.85.133.105 - - [01/Sep/2026:15:10:33 +0200] "GET /.env.local HTTP/1.1" 404 4616 "-" "crusader-worker/1.0" 34.85.133.105 - - [01/Sep/2026:15:10:33 +0200] "GET /wp-config.php.bak HTTP/1.1" 404 4618 "-" "crusader-worker/1.0"
show less
Brute-Force
Anonymous
2026-09-01 12:50:46
(16 hours ago)
34.85.133.105 - - [01/Sep/2026:14:50:39 +0200] "GET /wp-config.php.bak HTTP/1.1" 403 146 "-" "crusad ...
show more
34.85.133.105 - - [01/Sep/2026:14:50:39 +0200] "GET /wp-config.php.bak HTTP/1.1" 403 146 "-" "crusader-worker/1.0"
...
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 12:38:56
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.85.133.105 (105.133.85.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.85.133.105 (105.133.85.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 08:38:49.693064 2026] [security2:error] [pid 9062:tid 9062] [client 34.85.133.105:37258] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "churchtop.com"] [uri "/wp-config.php~"] [unique_id "apbHWSGPto855Nh3KvXm5gAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¨πΏ
ddw
2026-09-01 12:38:32
(16 hours ago)
ModSecurity detection - Rules: 949110(Inbound Anomaly Score Exceeded (Total Score: 10))
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 11:07:03
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.85.133.105 (105.133.85.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.85.133.105 (105.133.85.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 07:06:59.428719 2026] [security2:error] [pid 4622:tid 4622] [client 34.85.133.105:38944] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.farmbureaugallery.com"] [uri "/.env.local"] [unique_id "apax013Ff79lvQeqaDPGdwAAADs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π§πͺ
Saec
2026-09-01 10:16:01
(19 hours ago)
Jarvis auto-ban: CF top attacker on saec.ovh (26 hits, US)
Port Scan
Web App Attack
Anonymous
2026-09-01 10:05:03
(19 hours ago)
suspicious request in access.log
Web App Attack
π«π·
masterguru
2026-09-01 09:49:34
(19 hours ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.85.133.105 (105.133.85.34.bc.googl ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.85.133.105 (105.133.85.34.bc.googleusercontent.com): 2 in the last 3600 secs (0-196)
show less
Hacking
π³π±
thedreamer.nl
2026-09-01 09:35:47
(19 hours ago)
34.85.133.105 - - [01/Sep/2026:11:34:14 +0200] "GET /wp-config.php~ HTTP/1.1" 200 29044 "-" "crusade ...
show more
34.85.133.105 - - [01/Sep/2026:11:34:14 +0200] "GET /wp-config.php~ HTTP/1.1" 200 29044 "-" "crusader-worker/1.0" "US" "Washington" "38.89400" "-77.03650"
34.85.133.105 - - [01/Sep/2026:11:34:14 +0200] "GET /wp-config.php.swp HTTP/1.1" 200 29044 "-" "crusader-worker/1.0" "US" "Washington" "38.89400" "-77.03650"
34.85.133.105 - - [01/Sep/2026:11:34:14 +0200] "GET /_ignition/health-check HTTP/1.1" 200 29044 "-" "crusader-worker/1.0" "US" "Washington" "38.89400" "-77.03650"
34.85.133.105 - - [01/Sep/2026:11:34:14 +0200] "GET /.env.prod HTTP/1.1" 200 29044 "-" "crusader-worker/1.0" "US" "Washington" "38.89400" "-77.03650"
...
show less
Hacking
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 09:18:04
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.85.133.105 (105.133.85.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.85.133.105 (105.133.85.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 05:17:59.677660 2026] [security2:error] [pid 226454:tid 226536] [client 34.85.133.105:32784] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "super-8mm.net.credit-card-cap.com"] [uri "/.env"] [unique_id "apaYR_HLbyjoqeeQ2w8-EwAAAJM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΈπͺ
vaia.cloud
2026-09-01 07:55:03
(21 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
π©πͺ
NihiliousMonk
2026-09-01 07:18:57
(22 hours ago)
Fail2Ban report from jail npm-scanners
Bad Web Bot
Web App Attack
π¬π§
consul.to
2026-09-01 07:18:08
(22 hours ago)
Web attack/malicious scanning detected
Web App Attack