Anonymous
2026-09-01 04:21:44
(1 day ago)
Web probing (15 hits in 24h) on default-vhost: sensitive-path scans and/or 404 bursts. Reported by C ...
show more
Web probing (15 hits in 24h) on default-vhost: sensitive-path scans and/or 404 bursts. Reported by CRMON.
show less
Web App Attack
๐ณ๐ฑ
informedclearly.com
2026-09-01 03:33:54
(1 day ago)
WAF_BAN reason=ENV_PROBE rule=ENV_PATH hits=1 path=/.env? ua=crusader-worker/1.0
Hacking
๐ธ๐ช
vaia.cloud
2026-09-01 03:10:03
(1 day ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 02:33:47
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.96.210.152 (152.210.96.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.96.210.152 (152.210.96.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 22:33:42.425746 2026] [security2:error] [pid 4222:tid 4222] [client 34.96.210.152:52228] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.rockitfish.com"] [uri "/.env.dev"] [unique_id "apY5hvvOWMfuEYC3KbCAzgAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-01 02:32:17
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐บ๐ธ
chronos
2026-09-01 02:06:52
(2 days ago)
[AUTORAVALT][[31/08/2026 - 23:06:51 -03:00 UTC]
Attack from [Google LLC]
[34.96.210.152][152.210.96. ...
show more
[AUTORAVALT][[31/08/2026 - 23:06:51 -03:00 UTC]
Attack from [Google LLC]
[34.96.210.152][152.210.96.34.bc.googleusercontent.com]
Action: BLocKed
DDoS Attack -> Participating in distributed denial-of-service.
Phishing -> Phishing websites and/or email.
Web Spam -> Comment/forum spam, HTTP referer spam, or other CMS spam.
Blog Spam -> CMS blog comment spam.
Web]
...
show less
DDoS Attack
Phishing
Web Spam
Blog Spam
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 00:14:27
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.96.210.152 (152.210.96.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.96.210.152 (152.210.96.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 20:14:22.758282 2026] [security2:error] [pid 32282:tid 32282] [client 34.96.210.152:36464] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.carolynedds.com"] [uri "/.env.old"] [unique_id "apYY3nMO3-wyfTHKVF628AAAAC4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 23:33:35
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.96.210.152 (152.210.96.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.96.210.152 (152.210.96.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 19:33:32.055620 2026] [security2:error] [pid 19473:tid 19473] [client 34.96.210.152:51760] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "centralbaptistalcoa.org"] [uri "/wp-config.php.swp"] [unique_id "apYPTIh3bprMZEKMGO0VkAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Hans Wurst
2026-08-31 23:26:39
(2 days ago)
Many 404-Error: Suspicion of URL-Fuzzing/Bot-Scan.
Web App Attack
๐ซ๐ฎ
YF
2026-08-31 23:00:37
(2 days ago)
WordPress config file probe
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 22:49:12
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.96.210.152 (152.210.96.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.96.210.152 (152.210.96.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 18:49:04.829161 2026] [security2:error] [pid 5714:tid 5722] [client 34.96.210.152:55566] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bluemountainlawns.eliteproductions.tv"] [uri "/.env.bak"] [unique_id "apYE4JVtjoc0DxDRk0hXbAAAAME"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 22:20:19
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.96.210.152 (152.210.96.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.96.210.152 (152.210.96.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 18:20:13.731678 2026] [security2:error] [pid 25213:tid 25213] [client 34.96.210.152:58770] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.mspish2.com"] [uri "/.env.dev"] [unique_id "apX-HWZwgA9-5RO-nhiWJgAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FD-IX
2026-08-31 22:13:44
(2 days ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-08-31 22:10:04
(2 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 21:38:29
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.96.210.152 (152.210.96.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.96.210.152 (152.210.96.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 17:38:21.713457 2026] [security2:error] [pid 28927:tid 28927] [client 34.96.210.152:54720] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "alaskansupernip.com"] [uri "/wp-config.php.bak"] [unique_id "apX0TXM26ss5ydU8fMf8EAAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack