Anonymous
2026-09-14 21:15:39
(1 week ago)
34.131.165.228 - - [14/Sep/2026:23:15:20 +0200] "GET /.git/config HTTP/1.1" 403 614 "-" "Mozilla/5.0 ...
show more
34.131.165.228 - - [14/Sep/2026:23:15:20 +0200] "GET /.git/config HTTP/1.1" 403 614 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.131.165.228 - - [14/Sep/2026:23:15:21 +0200] "GET /.env HTTP/1.1" 403 614 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.131.165.228 - - [14/Sep/2026:23:15:21 +0200] "GET /.env.local HTTP/1.1" 403 614 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.131.165.228 - - [14/Sep/2026:23:15:21 +0200] "GET /.env.production HTTP/1.1" 403 614 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.131.165.228 - - [14/Sep/2026:23:15:21 +0200] "GET /.env.staging HTTP/1.1" 403 614 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.131.165.228 - - [14/Sep/2026:23:15:21 +0
...
show less
DDoS Attack
๐ณ๐ฑ
ipoac.nl
2026-09-14 15:39:39
(1 week ago)
-:443 34.131.165.228 - - [14/Sep/2026:17:39:33 +0200] - "GET /.git/config HTTP/1.1" 404 48360 "-" "M ...
show more
-:443 34.131.165.228 - - [14/Sep/2026:17:39:33 +0200] - "GET /.git/config HTTP/1.1" 404 48360 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-14 01:00:46
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.131.165.228 (228.165.131.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.131.165.228 (228.165.131.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 21:00:41.493785 2026] [security2:error] [pid 5322:tid 5322] [client 34.131.165.228:60458] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "3wf.com"] [uri "/.git/config"] [unique_id "aqdHOc3L_U-Eu1pextUB-gAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-13 22:38:29
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.131.165.228 (228.165.131.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.131.165.228 (228.165.131.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 18:38:22.087532 2026] [security2:error] [pid 27770:tid 27878] [client 34.131.165.228:41570] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "3stepreviewforyou.com"] [uri "/.git/config"] [unique_id "aqcl3u537WWztl5d8xZ4BAAAApM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-13 20:43:06
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.131.165.228 (228.165.131.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.131.165.228 (228.165.131.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 16:43:02.520537 2026] [security2:error] [pid 15875:tid 15875] [client 34.131.165.228:36412] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "3rddprints.bridgital.com"] [uri "/.git/config"] [unique_id "aqcK1oqDqm27S5YIS-vLOwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-13 19:23:45
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.131.165.228 (228.165.131.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.131.165.228 (228.165.131.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 15:23:40.770454 2026] [security2:error] [pid 4744:tid 4744] [client 34.131.165.228:45936] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "3pl.com"] [uri "/.git/config"] [unique_id "aqb4PNwion3N29j5YyMPagAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-09-13 18:42:18
(1 week ago)
5.572 requests with url.path *.env
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-13 17:27:07
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.131.165.228 (228.165.131.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.131.165.228 (228.165.131.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 13:27:02.392000 2026] [security2:error] [pid 17331:tid 17331] [client 34.131.165.228:37320] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "3n1ent.com"] [uri "/.git/config"] [unique_id "aqbc5u7nAopNQRJi9iNKuwAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
poundawebsiteltd
2026-09-13 17:06:05
(1 week ago)
Malicious activity in general-malicious. Evidence: (apache_probe) Failed Access (403/404) 34.131.165 ...
show more
Malicious activity in general-malicious. Evidence: (apache_probe) Failed Access (403/404) 34.131.165.228 (IN/India/[REDACTED_DOMAIN]): 20 in the last 3600 secs | UA: (apache_probe) Failed Access (403/404) 34.131.165.228 (IN/India/228.165.131.34.bc.googleusercontent.com): 20 in the last 3600 secs
show less
Brute-Force
Web App Attack
๐บ๐ธ
alecj.com
2026-09-13 16:08:07
(1 week ago)
This IP was detected by CrowdSec triggering crowdsecurity/appsec-vpatch
Web App Attack
Anonymous
2026-09-13 16:07:11
(1 week ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-13 16:00:01
(1 week ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-09-12 22:00:42
(1 week ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-11.
show less
Web App Attack
SSH
Hacking
๐จ๐ฟ
Countryman
2026-09-11 18:39:01
(2 weeks ago)
IPS detection: React.Server.Components.react-flight.Remote.Code.Execution
Hacking
๐ฎ๐น
VHosting
2026-09-11 17:15:04
(2 weeks ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack