๐บ๐ธ
TPI-Abuse
2026-08-28 20:50:24
(14 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.85.198.59 (59.198.85.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.85.198.59 (59.198.85.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 16:50:18.109674 2026] [security2:error] [pid 14427:tid 14427] [client 34.85.198.59:47730] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.dodosdiscuss.flyingdodostudio.com"] [uri "/wp-config.php~"] [unique_id "apH0iov25v0wI8AgaQgr2gAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 20:12:22
(52 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.85.198.59 (59.198.85.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.85.198.59 (59.198.85.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 16:12:18.390108 2026] [security2:error] [pid 19805:tid 19805] [client 34.85.198.59:53352] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "415test.com"] [uri "/.env.production"] [unique_id "apHronZP2gynJ-RmBidebAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 18:01:11
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.85.198.59 (59.198.85.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.85.198.59 (59.198.85.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 14:01:01.725365 2026] [security2:error] [pid 17464:tid 17464] [client 34.85.198.59:45456] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "yaseminelhan.com"] [uri "/.env.production"] [unique_id "apHM3dYhwSJzvNb67JIejgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-28 18:00:12
(3 hours ago)
[ns3.backorder.gr] httpd-config-scan: sites=www.justcare.gr; logs=/var/log/httpd/domains/justcare.gr ...
show more
[ns3.backorder.gr] httpd-config-scan: sites=www.justcare.gr; logs=/var/log/httpd/domains/justcare.gr.log; samples=/.env.prod | /.env.dev | /.env.bak
show less
Hacking
Web App Attack
๐ฉ๐ช
sdos.es
2026-08-28 17:58:22
(3 hours ago)
"Restricted File Access Attempt - Matched Data: /.env found within REQUEST_FILENAME: /.env.dev"
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-08-28 17:44:26
(3 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
Anonymous
2026-08-28 16:56:05
(4 hours ago)
Bot / scanning and/or hacking attempts: GET /wp-config.php~ HTTP/1.1, GET /storage/logs/laravel.log ...
show more
Bot / scanning and/or hacking attempts: GET /wp-config.php~ HTTP/1.1, GET /storage/logs/laravel.log HTTP/1.1, GET /actuator/env HTTP/1.1, GET /.env.save HTTP/1.1
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 16:05:17
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.85.198.59 (59.198.85.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.85.198.59 (59.198.85.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 12:05:04.134133 2026] [security2:error] [pid 27404:tid 27404] [client 34.85.198.59:36758] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "iostation.com"] [uri "/.env.bak"] [unique_id "apGxsCmUCXivBiDvA54QMwAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 15:48:06
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.85.198.59 (59.198.85.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.85.198.59 (59.198.85.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 11:48:01.643367 2026] [security2:error] [pid 23530:tid 23530] [client 34.85.198.59:51890] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.saudigreenrecycling.mapleleaf-marketing.com"] [uri "/wp-config.php.swp"] [unique_id "apGtsTw3rwdzlnjB7ol4eAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Catalin Negru
2026-08-28 15:34:34
(5 hours ago)
Recidive ban by fail2ban on server.blackbit.ro
Brute-Force
๐ฉ๐ช
netclix.gr
2026-08-28 14:46:24
(6 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.85.198.59 (US/United States/59.198.8 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.85.198.59 (US/United States/59.198.85.34.bc.googleusercontent.com): (CF_ENABLE)
show less
SQL Injection
๐บ๐ธ
aks4226
2026-08-28 14:38:52
(6 hours ago)
Bot search, attacking common web applications.
Web App Attack
๐บ๐ธ
mnsf
2026-08-28 14:06:05
(6 hours ago)
Scanning/Probing (16)
Brute-Force
Web App Attack
Anonymous
2026-08-28 13:50:01
(7 hours ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 13:39:42
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.85.198.59 (59.198.85.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.85.198.59 (59.198.85.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 09:39:36.614775 2026] [security2:error] [pid 22629:tid 22629] [client 34.85.198.59:59790] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cas.majesticsolutions.co"] [uri "/.env.example"] [unique_id "apGPmEawufrWLkSDWjK7QwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack