Anonymous
2026-09-22 17:09:16
(11 hours ago)
2026/09/22 19:09:15 [error] 2433725#2433725: *120887 access forbidden by rule, client: 34.10.53.48, ...
show more
2026/09/22 19:09:15 [error] 2433725#2433725: *120887 access forbidden by rule, client: 34.10.53.48, server: siteguide.co.za, request: "GET /.env.local HTTP/1.1", host: "siteguide.co.za"
2026/09/22 19:09:15 [error] 2433724#2433724: *120894 access forbidden by rule, client: 34.10.53.48, server: siteguide.co.za, request: "GET /.env.bak HTTP/1.1", host: "siteguide.co.za"
2026/09/22 19:09:15 [error] 2433725#2433725: *120888 access forbidden by rule, client: 34.10.53.48, server: siteguide.co.za, request: "GET /.env.prod HTTP/1.1", host: "siteguide.co.za"
...
show less
Hacking
Web App Attack
๐ซ๐ฎ
mnazibo
2026-09-22 17:00:30
(11 hours ago)
Date: Sep 22 19:49:03 2026 EAT | Reported IP: 34.10.53.48 mod_security | id: 920440 920500 930130 94 ...
show more
Date: Sep 22 19:49:03 2026 EAT | Reported IP: 34.10.53.48 mod_security | id: 920440 920500 930130 949110 | US/usernameab.my_domain/- | Connections: 1 | Blocked: Permanent Block: [LF_MODSEC] | Logs: ; URL file extension is restricted by policy; URL file extension is restricted by policy; URL file extension is restricted by policy; URL file extension is restricted by policy; URL file extension is restricted by policy; URL file extension is restricted by policy; URL file extension is restricted by policy; Attempt to access a backup or working file; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Restricted Fil
show less
SQL Injection
Brute-Force
Bad Web Bot
๐ฆ๐บ
electronico
2026-09-22 16:49:00
(11 hours ago)
34.10.53.48 - - [23/Sep/2026:03:48:59 +1100] "GET /wp-config.php.bak HTTP/1.1" 404 5513 "-" "crusade ...
show more
34.10.53.48 - - [23/Sep/2026:03:48:59 +1100] "GET /wp-config.php.bak HTTP/1.1" 404 5513 "-" "crusader-worker/1.0"
34.10.53.48 - - [23/Sep/2026:03:48:59 +1100] "GET /_ignition/health-check HTTP/1.1" 404 5513 "-" "crusader-worker/1.0"
34.10.53.48 - - [23/Sep/2026:03:48:59 +1100] "GET /env HTTP/1.1" 404 5513 "-" "crusader-worker/1.0"
34.10.53.48 - - [23/Sep/2026:03:48:59 +1100] "GET /wp-config.php.swp HTTP/1.1" 404 5513 "-" "crusader-worker/1.0"
34.10.53.48 - - [23/Sep/2026:03:48:59 +1100] "GET /.env.backup HTTP/1.1" 404 5513 "-" "crusader-worker/1.0"
34.10.53.48 - - [23/Sep/2026:03:48:59 +1100] "GET /.env.example HTTP/1.1" 404 5513 "-" "crusader-worker/1.0"
34.10.53.48 - - [23/Sep/2026:03:48:59 +1100] "GET /wp-config.php~ HTTP/1.1" 404 5513 "-" "crusader-worker/1.0"
34.10.53.48 - - [23/Sep/2026:03:48:59 +1100] "GET /.env.bak HTTP/1.1" 404 5513 "-" "crusader-worker/1.0"
34.10.53.48 - - [23/Sep/2026:03:48:59 +1100] "GET /.env.production HTTP/1.1" 404 5513 "-" "crusader-worker/1.0"
34.10.53
...
show less
Brute-Force
Web App Attack
๐ซ๐ฎ
Kimmo Rieskaniemi
2026-09-22 16:48:54
(11 hours ago)
CrowdSec triggered crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-22 16:15:14
(12 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ซ๐ท
ingroscart.it
2026-09-22 15:39:29
(12 hours ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-09-22 15:24:36
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.10.53.48 (48.53.10.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.10.53.48 (48.53.10.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 11:24:32.675474 2026] [security2:error] [pid 24448:tid 24651] [client 34.10.53.48:46984] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mwcecommerce.com"] [uri "/.env"] [unique_id "arKdsO_9QIngvDelSBg70gAAAVA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-22 15:16:12
(13 hours ago)
[ti-11al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-11al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.10.53.48 - - [22/Sep/2026:17:15:59 +0200] "GET /wp-config.php.bak HTTP/1.1" 403 4472 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 15:07:31
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.10.53.48 (48.53.10.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.10.53.48 (48.53.10.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 11:07:23.640059 2026] [security2:error] [pid 27998:tid 27998] [client 34.10.53.48:50998] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "medioskreativos.com"] [uri "/.env.production"] [unique_id "arKZq-egSV-N9BPuWkhf0wAAADU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 14:35:05
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.10.53.48 (48.53.10.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.10.53.48 (48.53.10.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 10:34:58.184282 2026] [security2:error] [pid 825221:tid 825221] [client 34.10.53.48:51296] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lloydprins.com"] [uri "/.env.production"] [unique_id "arKSEsubxc_Y2yEkzZ5OoQAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
debestelapp
2026-09-22 14:25:11
(14 hours ago)
Web App Attack
๐บ๐ธ
mnsf
2026-09-22 14:06:34
(14 hours ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
๐ฉ๐ช
webanyone
2026-09-22 13:48:09
(14 hours ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
๐บ๐ธ
Lea
2026-09-22 13:41:33
(14 hours ago)
Malicious web probe detected on bearstool.com: 34.10.53.48 - - [22/Sep/2026:09:41:32 -0400] "GET /.e ...
show more
Malicious web probe detected on bearstool.com: 34.10.53.48 - - [22/Sep/2026:09:41:32 -0400] "GET /.env.old HTTP/1.1" 444 0 "" "crusader-worker/1.0"
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
FD-IX
2026-09-22 12:34:04
(16 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack