๐ท๐ด
iulianh
2026-09-22 16:57:29
(1 day ago)
80,443
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-09-22 15:46:36
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.94.1.1 (1.1.94.34.bc.googleusercontent.com): ...
show more
(mod_security) mod_security (id:210492) triggered by 34.94.1.1 (1.1.94.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 11:46:31.460987 2026] [security2:error] [pid 7933:tid 7984] [client 34.94.1.1:46974] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "okorganicgardening.org"] [uri "/.env.save"] [unique_id "arKi16YtTkFWwP-GXBffogAAARQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Petros Stefanakis
2026-09-22 15:35:11
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted] 34.94.1.1 (US/United States/1.1.94.34.b ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.94.1.1 (US/United States/1.1.94.34.bc.googleusercontent.com)
show less
SQL Injection
๐ฉ๐ช
maxpower
2026-09-22 14:56:29
(1 day ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.94.1.1 (US/United States/1.1.94.34.bc ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.94.1.1 (US/United States/1.1.94.34.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.94.1.1 - - [22/Sep/2026:16:56:25 +0200] "GET /wp-config.php.bak HTTP/1.1" 403 146 "-" "crusader-worker/1.0" "-" host=mail.tikitakaplanet.it
show less
Port Scan
๐จ๐ฆ
polycoda
2026-09-22 14:26:44
(1 day ago)
AutoBlock: ๐ฏ Vulnerability Scanner (Non Decay-Based)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 14:20:38
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.94.1.1 (1.1.94.34.bc.googleusercontent.com): ...
show more
(mod_security) mod_security (id:210492) triggered by 34.94.1.1 (1.1.94.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 10:20:34.489189 2026] [security2:error] [pid 29151:tid 29151] [client 34.94.1.1:55924] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "knoxbestos.com"] [uri "/.env"] [unique_id "arKOsizA2PSSvx5uo2pAEQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-09-22 14:15:01
(1 day ago)
This address is looking for secret files on our sites: .git directories, .env files, credential and ...
show more
This address is looking for secret files on our sites: .git directories, .env files, credential and configuration files, database dumps, backups. This is a targeted search for credentials to break into the sites, blocked at the first request. Please check the machine behind it for an attack tool or malware. | method: GET | path: /wp-config.php.bak (+12 more) | 2026-09-22 14:15 UTC
show less
Hacking
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-22 14:13:33
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 14:02:49
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.94.1.1 (1.1.94.34.bc.googleusercontent.com): ...
show more
(mod_security) mod_security (id:210492) triggered by 34.94.1.1 (1.1.94.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 10:02:43.183746 2026] [security2:error] [pid 17774:tid 17774] [client 34.94.1.1:57122] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "israelartifact.com"] [uri "/.env.save"] [unique_id "arKKg5tcZGM4uugabv0ihQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
gadix
2026-09-22 13:38:54
(1 day ago)
[22/Sep/2026:15:38:51.933632 +0200] arKE64MyKaQyRTPbnhLpsAAAAE0 34.94.1.1 47908 127.0.0.1 7081
[22/S ...
show more
[22/Sep/2026:15:38:51.933632 +0200] arKE64MyKaQyRTPbnhLpsAAAAE0 34.94.1.1 47908 127.0.0.1 7081
[22/Sep/2026:15:38:51.934943 +0200] arKE64MyKaQyRTPbnhLpsQAAAEY 34.94.1.1 47922 127.0.0.1 7081
[22/Sep/20
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 13:29:27
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.94.1.1 (1.1.94.34.bc.googleusercontent.com): ...
show more
(mod_security) mod_security (id:210492) triggered by 34.94.1.1 (1.1.94.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 09:29:23.562028 2026] [security2:error] [pid 27223:tid 27267] [client 34.94.1.1:52954] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gotogps.com"] [uri "/.env.old"] [unique_id "arKCs_1kW2THq_56-DKvzQAAAJg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-09-22 13:01:53
(1 day ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐บ๐ธ
abuse-opdc
2026-09-22 12:35:42
(2 days ago)
Malicious HTTP requests matching injection/exploit signatures.
Web App Attack
Brute-Force
๐ณ๐ฑ
Alt255
2026-09-22 12:15:26
(2 days ago)
[ti-11al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-11al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.94.1.1 - - [22/Sep/2026:14:15:16 +0200] "GET /.env.bak HTTP/1.1" 403 4150 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-22 12:09:36
(2 days ago)
34.94.1.1 - - [22/Sep/2026:14:09:30 +0200] "GET /crusader-404-probe HTTP/1.1" 404 164 "-" "crusader- ...
show more
34.94.1.1 - - [22/Sep/2026:14:09:30 +0200] "GET /crusader-404-probe HTTP/1.1" 404 164 "-" "crusader-worker/1.0"
34.94.1.1 - - [22/Sep/2026:14:09:30 +0200] "GET /_ignition/health-check HTTP/1.1" 404 164 "-" "crusader-worker/1.0"
34.94.1.1 - - [22/Sep/2026:14:09:30 +0200] "GET /.env.example HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
34.94.1.1 - - [22/Sep/2026:14:09:30 +0200] "GET /.env.bak HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
34.94.1.1 - - [22/Sep/2026:14:09:30 +0200] "GET /.env HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
34.94.1.1 - - [22/Sep/2026:14:09:30 +0200] "GET /.env.old HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
34.94.1.1 - - [22/Sep/2026:14:09:30 +0200] "GET /.env.local HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
34.94.1.1 - - [22/Sep/2026:14:09:30 +0200] "GET /.env.backup HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
34.94.1.1 - - [22/Sep/2026:14:09:30 +0200] "GET /.env.prod HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
34.94.1.1 - - [22/Sep/2026:14:09:30 +0200] "GET /wp-
...
show less
Bad Web Bot
Web App Attack