๐บ๐ธ
mnsf
2026-09-10 14:05:11
(1 day ago)
Too many Status 40X (11)
Brute-Force
Web App Attack
๐ฉ๐ช
maxpower
2026-09-08 12:23:57
(3 days ago)
(nginx_hardened) REGOLA 3 - Nginx Hardening Triggered 34.106.130.35 (US/United States/35.130.106.34. ...
show more
(nginx_hardened) REGOLA 3 - Nginx Hardening Triggered 34.106.130.35 (US/United States/35.130.106.34.bc.googleusercontent.com): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 2026/09/08 14:23:52 [error] 343746#343746: *179360 access forbidden by rule, client: 34.106.130.35, server: luigivitalipittore.it, request: "GET /wp-config.php.bak HTTP/1.1", host: "www.luigivitalipittore.it"
2026/09/08 14:23:52 [error] 343745#343745: *179367 access forbidden by rule, client: 34.106.130.35, server: luigivitalipittore.it, request: "GET /wp-config.php.bak HTTP/1.1", host: "mail.luigivitalipittore.it"
2026/09/08 14:23:52 [error] 343753#343753: *179368 access forbidden by rule, client: 34.106.130.35, server: luigivitalipittore.it, request: "GET /wp-config.php.swp HTTP/1.1", host: "www.luigivitalipittore.it"
show less
Port Scan
๐ฑ๐ป
garmtech.com
2026-09-08 11:05:04
(3 days ago)
Attempted access to sensitive endpoint (/.env.example) detected. Automated scan or unauthorized prob ...
show more
Attempted access to sensitive endpoint (/.env.example) detected. Automated scan or unauthorized probing.
show less
Web App Attack
๐ณ๐ฑ
Cloud86 B.V.
2026-09-08 06:54:02
(3 days ago)
categories: DDoS Attack
DDoS Attack
๐ธ๐ช
vaia.cloud
2026-09-08 06:15:02
(3 days ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐จ๐ฆ
Roper123
2026-09-08 01:46:34
(3 days ago)
Web exploits
Hacking
Web App Attack
๐บ๐ธ
Starburst SysOp Team
2026-09-07 10:14:01
(4 days ago)
Host header is a numeric IP address. Pattern match "(?:^( (920350-stl2-17)
Hacking
Bad Web Bot
๐บ๐ธ
Gabriel Camargo
2026-09-07 09:41:43
(4 days ago)
34.106.130.35 - - [07/Sep/2026:04:41:42 -0500] "GET /wp-config.php~ HTTP/1.1" 404 162 "-" "crusader- ...
show more
34.106.130.35 - - [07/Sep/2026:04:41:42 -0500] "GET /wp-config.php~ HTTP/1.1" 404 162 "-" "crusader-worker/1.0"
34.106.130.35 - - [07/Sep/2026:04:41:42 -0500] "GET /wp-config.php.swp HTTP/1.1" 404 162 "-" "crusader-worker/1.0"
34.106.130.35 - - [07/Sep/2026:04:41:42 -0500] "GET /env HTTP/1.1" 404 162 "-" "crusader-worker/1.0"
...
show less
Brute-Force
SSH
๐ง๐พ
lns.bz
2026-09-07 09:41:22
(4 days ago)
Too many 404 requests [BY]
Web App Attack
๐ฆ๐บ
2000cn.com.au
2026-09-07 06:03:03
(4 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ธ๐ฐ
Eurofluid
2026-09-06 07:02:29
(5 days ago)
You shall not pass ! Abusive behavior blocked by EF firewall.
Port Scan
Hacking
Brute-Force
๐บ๐ธ
Shouddy Tarano
2026-09-06 06:04:22
(5 days ago)
[Sun Sep 06 00:04:21.465777 2026] [authz_core:error] [pid 2787501:tid 139792369010432] [client 34.10 ...
show more
[Sun Sep 06 00:04:21.465777 2026] [authz_core:error] [pid 2787501:tid 139792369010432] [client 34.106.130.35:51968] AH01630: client denied by server configuration: /var/www/erpcampestremty/public/.env.production
[Sun Sep 06 00:04:21.468542 2026] [authz_core:error] [pid 2572344:tid 139792310261504] [client 34.106.130.35:51980] AH01630: client denied by server configuration: /var/www/erpcampestremty/public/.env.bak
[Sun Sep 06 00:04:21.471451 2026] [authz_core:error] [pid 2787411:tid 139792335439616] [client 34.106.130.35:51976] AH01630: client denied by server configuration: /var/www/erpcampestremty/public/.env.old
[Sun Sep 06 00:04:21.472631 2026] [authz_core:error] [pid 2572273:tid 139792301868800] [client 34.106.130.35:51990] AH01630: client denied by server configuration: /var/www/erpcampestremty/public/.env.prod
[Sun Sep 06 00:04:21.475103 2026] [authz_core:error] [pid 2787411:tid 139792436152064] [client 34.106.130.35:52010] AH01630: client denied by server configuration: /var/www
...
show less
DDoS Attack
Web Spam
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-06 03:52:13
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.106.130.35 (35.130.106.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.130.35 (35.130.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:52:08.716368 2026] [security2:error] [pid 29818:tid 29828] [client 34.106.130.35:52652] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.newleafpro.com"] [uri "/.env.example"] [unique_id "apzjaOoUBvlQaBz6B_yXQQAAAMU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-06 02:58:13
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.106.130.35 (35.130.106.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.130.35 (35.130.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:58:09.486485 2026] [security2:error] [pid 27508:tid 27508] [client 34.106.130.35:57898] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.bradmackenzie.com"] [uri "/.env.local"] [unique_id "apzWwYUKhpIzBNmb36IHJQAAAE4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-09-06 02:57:24
(5 days ago)
[SunSep0604:57:20.6064542026][security2:error][pid2361304:tid2361369][client34.106.130.35:0]ModSecur ...
show more
[SunSep0604:57:20.6064542026][security2:error][pid2361304:tid2361369][client34.106.130.35:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"webdisk.gruppobalu.com\"][uri\"/storage/logs/laravel.log\"][unique_id\"apzWkINbTkAd3Y2YhUl1_QAAAE0\"]
show less
Port Scan
Brute-Force
Web App Attack