๐บ๐ธ
TPI-Abuse
2026-09-01 13:56:33
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 8.228.122.129 (129.122.228.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.228.122.129 (129.122.228.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 09:56:29.641761 2026] [security2:error] [pid 30095:tid 30095] [client 8.228.122.129:37934] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.gizmolabs.net"] [uri "/wp-config.php~"] [unique_id "apbZjR8NfhoG0mxw_Z3UIQAAAD4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-01 12:57:05
(1 day ago)
Bot / scanning and/or hacking attempts: GET /storage/logs/laravel.log HTTP/1.1, GET /.env.bak HTTP/1 ...
show more
Bot / scanning and/or hacking attempts: GET /storage/logs/laravel.log HTTP/1.1, GET /.env.bak HTTP/1.1, GET /.env.example HTTP/1.1, GET /wp-config.php.swp HTTP/1.1, GET /.env.backup HTTP/1.1, GET /crusader-404-probe HTTP/1.1, GET /.env HTTP/1.1
show less
Hacking
Web App Attack
๐ฉ๐ช
FD-IX
2026-09-01 12:56:10
(1 day ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-01 12:34:15
(1 day ago)
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .backup/ ...
show more
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .compositefont/ .config/ .conf/ .crt/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dist/ .dll/ .dos/ .dpkg-dist/ .drv/ .gadget/ .hta/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .inf/ .ini/ .jse/ .key/ .licx/ .lnk/ .log/ .mdb/ .msc/ .ocx/ .old/ .pass/ .pdb/ .pfx/ .pif/ .pem/ .pol/ .prf/ .printer/ .pwd/ .rdb/ .rdp/ .reg/ .resources/ .resx/ .scr/ .sct/ .shs/ .sql/ .swp/ .sys/ .tlb/ .tmp/ .url/ .vb/ .vbe/ .vbs/ .vbproj/ .vsdisco/ .vxd/ .webinfo/ .ws/ .wsc/ .wsf/ .wsh/ .xsd/ .xsx/" at TX:extension. (920440-195)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-01 12:05:43
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 8.228.122.129 (129.122.228.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.228.122.129 (129.122.228.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 08:05:35.380036 2026] [security2:error] [pid 5867:tid 5867] [client 8.228.122.129:57784] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "deepseasugar.com"] [uri "/.env.production"] [unique_id "apa_jx4VvrkLbzc-xAgOwgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-01 12:04:54
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-01 10:58:37
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 8.228.122.129 (129.122.228.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.228.122.129 (129.122.228.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 06:58:32.710688 2026] [security2:error] [pid 4824:tid 4824] [client 8.228.122.129:34048] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.alexscollay.com"] [uri "/wp-config.php.bak"] [unique_id "apav2J-o2n8ygOruyBo3mgAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Celtic
2026-09-01 10:48:18
(1 day ago)
Blocked by Fail2Ban with Jail (plesk-modsecurity)
Brute-Force
SSH
๐ฌ๐ง
Aetherweb Ark
2026-09-01 09:50:03
(1 day ago)
(mod_security) mod_security (id:949110) triggered by 8.228.122.129 (US/United States/129.122.228.8.b ...
show more
(mod_security) mod_security (id:949110) triggered by 8.228.122.129 (US/United States/129.122.228.8.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
๐ฆ๐บ
aranguren.org
2026-09-01 09:41:54
(1 day ago)
8.228.122.129 - - [01/Sep/2026:19:41:53 +1000] "GET /.env.bak HTTP/1.1" 404 999 "-" "crusader-worker ...
show more
8.228.122.129 - - [01/Sep/2026:19:41:53 +1000] "GET /.env.bak HTTP/1.1" 404 999 "-" "crusader-worker/1.0"
8.228.122.129 - - [01/Sep/2026:19:41:53 +1000] "GET /wp-config.php.swp HTTP/1.1" 404 999 "-" "crusader-worker/1.0"
8.228.122.129 - - [01/Sep/2026:19:41:53 +1000] "GET /.env.prod HTTP/1.1" 404 999 "-" "crusader-worker/1.0"
8.228.122.129 - - [01/Sep/2026:19:41:53 +1000] "GET /.env.old HTTP/1.1" 404 999 "-" "crusader-worker/1.0"
8.228.122.129 - - [01/Sep/2026:19:41:53 +1000] "GET /.env.backup HTTP/1.1" 404 999 "-" "crusader-worker/1.0"
8.228.122.129 - - [01/Sep/2026:19:41:53 +1000] "GET /.env.save HTTP/1.1" 404 999 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-01 09:36:04
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 8.228.122.129 (129.122.228.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.228.122.129 (129.122.228.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 05:35:56.684625 2026] [security2:error] [pid 8444:tid 8444] [client 8.228.122.129:38224] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "solporpoise.com.herston.net"] [uri "/.env.bak"] [unique_id "apacfKwoAmClDJU8eEyWqwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-01 09:22:45
(1 day ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 08:49:54
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 8.228.122.129 (129.122.228.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.228.122.129 (129.122.228.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 04:49:50.123366 2026] [security2:error] [pid 4508:tid 4508] [client 8.228.122.129:42196] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "seescribe.com"] [uri "/.env.production"] [unique_id "apaRroVmCr7cYpDxQ3or1gAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-01 08:30:12
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 08:27:31
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 8.228.122.129 (129.122.228.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.228.122.129 (129.122.228.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 04:27:24.788127 2026] [security2:error] [pid 31137:tid 31137] [client 8.228.122.129:59962] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "method1.net"] [uri "/.env"] [unique_id "apaMbGejU3-_vhuIHNjM9gAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack