๐ซ๐ท
Tilellit.PRO
2026-09-16 05:01:16
(1 day ago)
Malicious web traffic detected by CrowdSec
Hacking
๐ซ๐ท
phoenix1jl96
2026-09-16 03:40:15
(1 day ago)
2026/09/16 05:40:14 [error] 1507858#1507858: *21130 open() "/home/user-data/www/lucasmaths.fr/mailer ...
show more
2026/09/16 05:40:14 [error] 1507858#1507858: *21130 open() "/home/user-data/www/lucasmaths.fr/mailer/.env" failed (2: No such file or directory), client: 34.130.49.42, server: lucasmaths.fr, request: "GET /mailer/.env HTTP/1.1", host: "lucasmaths.fr"
2026/09/16 05:40:14 [error] 1507858#1507858: *21130 open() "/usr/local/lib/roundcubemail/.env" failed (2: No such file or directory), client: 34.130.49.42, server: lucasmaths.fr, request: "GET /mail/.env HTTP/1.1", host: "lucasmaths.fr"
...
show less
DNS Compromise
DNS Poisoning
DDoS Attack
Ping of Death
Web Spam
Email Spam
Blog Spam
Port Scan
Hacking
Brute-Force
Bad Web Bot
SSH
Web App Attack
๐ฎ๐น
VHosting
2026-09-16 03:25:03
(1 day ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ฆ๐บ
clapper
2026-09-16 03:00:16
(1 day ago)
(mod_security) mod_security (id:949110) triggered by 34.130.49.42 (CA/Canada/42.49.130.34.bc.googleu ...
show more
(mod_security) mod_security (id:949110) triggered by 34.130.49.42 (CA/Canada/42.49.130.34.bc.googleusercontent.com): 3 in the last 3600 secs; ID: LUC
show less
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-15 21:53:58
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.130.49.42 (42.49.130.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.130.49.42 (42.49.130.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 17:53:51.516957 2026] [security2:error] [pid 27504:tid 27504] [client 34.130.49.42:49060] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sloaviation.com"] [uri "/.git/config"] [unique_id "aqm-bwXxdVQq8yck4bNjYgAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 19:06:58
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.130.49.42 (42.49.130.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.130.49.42 (42.49.130.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 15:06:52.364921 2026] [security2:error] [pid 10143:tid 10151] [client 34.130.49.42:56806] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "slingshotpro.com"] [uri "/.git/config"] [unique_id "aqmXTMV4yunqWwklqDpQ5gAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Sling
2026-09-15 19:02:07
(1 day ago)
Automated detection: IP accessed 13 sensitive endpoints within 30s on slingexe.me. Paths: /.env, /.e ...
show more
Automated detection: IP accessed 13 sensitive endpoints within 30s on slingexe.me. Paths: /.env, /.env.production, /.env.local, /.env.bak, /.env.backup, /.env.sample, /.env.example, /.env.dev, /.env.stage, /app/.env. UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36.
show less
Web App Attack
Bad Web Bot
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-15 18:07:08
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.130.49.42 (42.49.130.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.130.49.42 (42.49.130.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 14:07:04.140672 2026] [security2:error] [pid 32211:tid 32211] [client 34.130.49.42:46546] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "slimlaw.com"] [uri "/.git/config"] [unique_id "aqmJSJRFOJHDAUPTavZidAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-15 08:47:30
(2 days ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack