🇳🇱
Cloud86 B.V.
2026-09-06 15:03:02
(10 hours ago)
categories: DDoS Attack
DDoS Attack
Anonymous
2026-09-06 06:08:44
(19 hours ago)
WordPress Sensitive System Files Information Disclosure.
Hacking
🇺🇸
TPI-Abuse
2026-09-06 03:03:10
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.95.191.204 (204.191.95.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.95.191.204 (204.191.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:03:04.014131 2026] [security2:error] [pid 17841:tid 17841] [client 34.95.191.204:58288] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wp.hotpay.co"] [uri "/wp-config.php~"] [unique_id "apzX6KgUcr1LxZxtBxlrDQAAACo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:34:14
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.95.191.204 (204.191.95.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.95.191.204 (204.191.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:34:10.788951 2026] [security2:error] [pid 4213:tid 4213] [client 34.95.191.204:40932] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "feministvoice.blog"] [uri "/.env.bak"] [unique_id "apzRIqLyOdl28dUutFopAwAAAGI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 02:33:50
(22 hours ago)
[da.kdns.gr] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/.env.example | /actuator/co ...
show more
[da.kdns.gr] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/.env.example | /actuator/configprops | /.env.save
show less
Hacking
Web App Attack
🇩🇪
dbmwebdesign
2026-09-06 02:05:06
(23 hours ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
🇩🇪
FeG Deutschland
2026-09-06 01:31:06
(23 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 01:09:00
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.95.191.204 (204.191.95.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.95.191.204 (204.191.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:08:53.832560 2026] [security2:error] [pid 23054:tid 23054] [client 34.95.191.204:51908] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.seads.global"] [uri "/wp-config.php.bak"] [unique_id "apy9JX2t0_rTxUxFGaTU5QAAADY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-06 00:52:12
(1 day ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 23:57:13
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.95.191.204 (204.191.95.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.95.191.204 (204.191.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:57:05.434548 2026] [security2:error] [pid 9039:tid 9039] [client 34.95.191.204:56986] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.rainwaterconstruction.net"] [uri "/.env.save"] [unique_id "apysUfSzBH0l0v4C3I1ymgAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-05 23:31:07
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-05 22:47:31
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.95.191.204 (204.191.95.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.95.191.204 (204.191.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:47:23.843536 2026] [security2:error] [pid 24279:tid 24279] [client 34.95.191.204:36668] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "doctorbalog.com"] [uri "/.env.save"] [unique_id "apyb-wSjd7SvClQyvXAbpwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 22:29:22
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.95.191.204 (204.191.95.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.95.191.204 (204.191.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:29:14.247557 2026] [security2:error] [pid 934:tid 934] [client 34.95.191.204:57022] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "toepferlab.org"] [uri "/.env.local"] [unique_id "apyXuhckpmhPd_porefiDQAAACo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 21:48:57
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.95.191.204 (204.191.95.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.95.191.204 (204.191.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 17:48:53.642683 2026] [security2:error] [pid 10350:tid 10350] [client 34.95.191.204:36646] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "howtosellmorepizza.com"] [uri "/.env"] [unique_id "apyORTomN4Uj7v16r6zkygAAAGM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-05 21:35:16
(1 day ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host