🇬🇧
consul.to
2026-09-06 03:21:56
(3 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:57:56
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.85.249.197 (197.249.85.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.85.249.197 (197.249.85.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:57:50.295902 2026] [security2:error] [pid 8552:tid 8552] [client 34.85.249.197:40512] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.hvacs-aircon.com"] [uri "/wp-config.php.bak"] [unique_id "apzWrsexlrsOv-RVhSgDmQAAADs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Octopuce
2026-09-06 02:35:40
(4 hours ago)
Aggressive web search of vulnerable pages: /.env.local /.env /backup.sql /database.sql /backup.zip / ...
show more
Aggressive web search of vulnerable pages: /.env.local /.env /backup.sql /database.sql /backup.zip /db.sql /backup.tar ...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:25:28
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.85.249.197 (197.249.85.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.85.249.197 (197.249.85.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:25:23.391062 2026] [security2:error] [pid 5696:tid 5696] [client 34.85.249.197:40910] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "skipspsaexchange.com"] [uri "/wp-config.php~"] [unique_id "apzPEzu0km0pHZle0oEWsQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
mondor.ro
2026-09-06 01:46:41
(5 hours ago)
Cluster member 148.251.176.225 (DE/Germany/antares.webyouridea.ro) said, DENY 34.85.249.197, Reason: ...
show more
Cluster member 148.251.176.225 (DE/Germany/antares.webyouridea.ro) said, DENY 34.85.249.197, Reason:[(mod_security) mod_security (id:210492) triggered by 34.85.249.197 (US/United States/197.249.85.34.bc.googleusercontent.com): 3 in the last 3600 secs]; Ports: *; Direction: inout; Trigger: LF_CLUSTER; Logs:
show less
Port Scan
🇺🇸
TPI-Abuse
2026-09-06 01:43:15
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.85.249.197 (197.249.85.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.85.249.197 (197.249.85.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:43:09.879344 2026] [security2:error] [pid 30727:tid 30759] [client 34.85.249.197:48034] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "yubasutterphotography.com"] [uri "/.env.prod"] [unique_id "apzFLVyjTaewCShlwzfFpQAAAFY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 01:21:36
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.85.249.197 (197.249.85.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.85.249.197 (197.249.85.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:21:32.973247 2026] [security2:error] [pid 11729:tid 11740] [client 34.85.249.197:54706] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tamarkummel.com.captainpurpleproductions.com"] [uri "/wp-config.php~"] [unique_id "apzAHCdCOveZ2ZzsmBk1cwAAAUM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-06 00:37:01
(6 hours ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 00:32:10
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.85.249.197 (197.249.85.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.85.249.197 (197.249.85.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:32:06.386979 2026] [security2:error] [pid 29294:tid 29294] [client 34.85.249.197:46252] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bergenoaks.com.velvetculture.com"] [uri "/.env.old"] [unique_id "apy0hjlrwM4B5V87yLeHJQAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
BlueWire Hosting
2026-09-05 23:55:44
(7 hours ago)
Probing websites for vulnerabilities
Web App Attack
Anonymous
2026-09-05 23:39:22
(7 hours ago)
34.85.249.197 - - [05/Sep/2026:18:39:08 -0500] "GET /.env.old HTTP/1.1" 403 199 "-" "crusader-worker ...
show more
34.85.249.197 - - [05/Sep/2026:18:39:08 -0500] "GET /.env.old HTTP/1.1" 403 199 "-" "crusader-worker/1.0" 34.85.249.197
34.85.249.197 - - [05/Sep/2026:18:39:08 -0500] "GET /.env.production HTTP/1.1" 403 199 "-" "crusader-worker/1.0" 34.85.249.197
34.85.249.197 - - [05/Sep/2026:18:39:08 -0500] "GET /.env.backup HTTP/1.1" 403 199 "-" "crusader-worker/1.0" 34.85.249.197
34.85.249.197 - - [05/Sep/2026:18:39:08 -0500] "GET /.env HTTP/1.1" 403 199 "-" "crusader-worker/1.0" 34.85.249.197
34.85.249.197 - - [05/Sep/2026:18:39:08 -0500] "GET /.env.prod HTTP/1.1" 403 199 "-" "crusader-worker/1.0" 34.85.249.197
34.85.249.197 - - [05/Sep/2026:18:39:08 -0500] "GET /.env.dev HTTP/1.1" 403 199 "-" "crusader-worker/1.0" 34.85.249.197
34.85.249.197 - - [05/Sep/2026:18:39:08 -0500] "GET /.env.local HTTP/1.1" 403 199 "-" "crusader-worker/1.0" 34.85.249.197
34.85.249.197 - - [05/Sep/2026:18:39:08 -0500] "GET /.env.save HTTP/1.1" 403 199 "-" "crusader-worker/1.0" 34.85.249.197
34.85.249.197 - - [05/Sep/2026
...
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-05 22:46:04
(8 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
Anonymous
2026-09-05 22:36:51
(8 hours ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
🇳🇱
MyGlobalFlowers
2026-09-05 22:13:33
(9 hours ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 21:59:20
(9 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.85.249.197 (197.249.85.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.85.249.197 (197.249.85.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 17:59:13.468011 2026] [security2:error] [pid 5031:tid 5031] [client 34.85.249.197:54474] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||usaangelinvestors.com|F|2"] [data ".env.backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "usaangelinvestors.com"] [uri "/.env.backup"] [unique_id "apyQsSddyna-m7UkdFEBAgAAAEc"]
show less
Brute-Force
Bad Web Bot
Web App Attack