🇨🇦
danieljamesbertrand
2026-09-06 06:21:53
(2 days ago)
fail2ban jail=nginx-access-exploit on canadapaywall (automatic report; categories 19,21)
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 06:12:42
(2 days ago)
B: f2b 404 5x
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:55:19
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.88.16.241 (241.16.88.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.16.241 (241.16.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:55:12.400664 2026] [security2:error] [pid 579:tid 579] [client 34.88.16.241:57710] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.taylorandatlantic.net"] [uri "/.env"] [unique_id "apzkIG1jNYhNjMU03i1tQAAAAHM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:23:23
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.88.16.241 (241.16.88.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.16.241 (241.16.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:23:16.617099 2026] [security2:error] [pid 25578:tid 25578] [client 34.88.16.241:41198] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "scr-publications.com"] [uri "/.env.example"] [unique_id "apzcpNwrPeq5khsHWeJEjQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:04:09
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.88.16.241 (241.16.88.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.16.241 (241.16.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:04:02.460385 2026] [security2:error] [pid 7016:tid 7016] [client 34.88.16.241:33876] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wetlookforum.grayhost.net"] [uri "/.env.bak"] [unique_id "apzYIppQ1Oe4WL3wMugXRwAAAD0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:26:41
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.88.16.241 (241.16.88.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.16.241 (241.16.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:26:33.696866 2026] [security2:error] [pid 8008:tid 8008] [client 34.88.16.241:36950] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "smartsolutionsgroup.info"] [uri "/.env.local"] [unique_id "apzPWfKP0uBGa9dQkE-1dQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-06 01:31:49
(2 days ago)
Multiple WAF Violations
Web App Attack
🇳🇱
e.fierstra
2026-09-06 01:27:51
(2 days ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 00:49:02
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.88.16.241 (241.16.88.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.16.241 (241.16.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:48:54.535874 2026] [security2:error] [pid 3919:tid 3919] [client 34.88.16.241:45344] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "eaglesnestfuelfarm.com"] [uri "/wp-config.php.bak"] [unique_id "apy4dsdJ7jHXv8lK941xPAAAACs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 23:58:49
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.88.16.241 (241.16.88.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.16.241 (241.16.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:58:42.809913 2026] [security2:error] [pid 4788:tid 4788] [client 34.88.16.241:33514] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kevinfranz.com"] [uri "/.env.production"] [unique_id "apysstXZ9-uxi5eGAVRfUQAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇷
P1n4
2026-09-05 23:38:51
(2 days ago)
Heimdal IDS auto-block: wordpress_probe (score=1.00)
Web App Attack
🇩🇪
pscriptos
2026-09-05 23:22:03
(2 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇨🇦
lakered
2026-09-05 23:02:39
(2 days ago)
Detectors: [NGINX] | Reasons: Nginx Honeypot: Exploitation / Shell attempt | Evidence: High-Criminal ...
show more
Detectors: [NGINX] | Reasons: Nginx Honeypot: Exploitation / Shell attempt | Evidence: High-Criminality-Signature (ja4:t13d1011h1 - Ratio:0.98), High-Criminality-Signature (ja4h:5cf9f33397d2cfab2c8ca2fd9e424522 - Ratio:0.98) | UA: crusader-worker/1.0 | TCP Fingerprint: Modern Linux (Kernel 3.x+) (Link:generic tunnel or VPN, Uptime:48417m)
show less
Hacking
🇬🇧
consul.to
2026-09-05 22:45:41
(2 days ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 22:37:03
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.88.16.241 (241.16.88.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.16.241 (241.16.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:36:55.848219 2026] [security2:error] [pid 5187:tid 5187] [client 34.88.16.241:55266] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gemconsulting.world"] [uri "/.env.save"] [unique_id "apyZh8H2NRhyWvCC5rir6wAAADE"]
show less
Brute-Force
Bad Web Bot
Web App Attack