๐บ๐ธ
aks4226
2026-08-30 03:41:58
(1 day ago)
Bot search, attacking common web applications.
Web App Attack
๐ณ๐ฑ
BlueWire Hosting
2026-08-30 03:03:16
(1 day ago)
High-confidence malicious configuration/VCS probe
Web App Attack
๐ฎ๐ฉ
Burayot
2026-08-30 01:13:25
(1 day ago)
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 34.138.81.27 (US/United States/27.81 ...
show more
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 34.138.81.27 (US/United States/27.81.138.34.bc.googleusercontent.com): 1 in the last 3600 secs
show less
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-08-29 22:00:48
(1 day ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-08-28.
show less
Web App Attack
SSH
Hacking
๐ฟ๐ฆ
conure.sh
2026-08-29 12:01:52
(1 day ago)
csagent: score 21.5: 404 noise floor x6, secrets grab x2; 1 domain(s) in 0s
Web App Attack
Anonymous
2026-08-29 03:04:53
(2 days ago)
Scenarios: http-sensitive-files
Total requests: 19
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 03:03:14
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.138.81.27 (27.81.138.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.138.81.27 (27.81.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 23:03:07.811437 2026] [security2:error] [pid 18612:tid 18612] [client 34.138.81.27:41376] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "amywoodruff.com"] [uri "/.env.prod"] [unique_id "apJL6_m8-he2o49m66yGaQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 02:42:39
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.138.81.27 (27.81.138.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.138.81.27 (27.81.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 22:42:36.008800 2026] [security2:error] [pid 5959:tid 5959] [client 34.138.81.27:50462] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "web50.dnchosting.com"] [uri "/.env.dev"] [unique_id "apJHHLHCAgQw7B0GnF76zwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 01:10:58
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.138.81.27 (27.81.138.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.138.81.27 (27.81.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 21:10:53.921124 2026] [security2:error] [pid 7036:tid 7036] [client 34.138.81.27:49752] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.cdalakefrontcabin.com"] [uri "/.env.production"] [unique_id "apIxneBT3f-aj8Z4DJTTiwAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 00:29:24
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.138.81.27 (27.81.138.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.138.81.27 (27.81.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 20:29:17.765953 2026] [security2:error] [pid 16835:tid 16835] [client 34.138.81.27:52632] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.binfieldresources.keyston.net"] [uri "/.env.example"] [unique_id "apIn3frCe8SpcghFKvaUHAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
BlueWire Hosting
2026-08-29 00:29:12
(2 days ago)
Probing websites for vulnerabilities
Web App Attack
Anonymous
2026-08-29 00:18:34
(2 days ago)
(mod_security) mod_security triggered on hostname [redacted] 34.138.81.27 (US/United States/27.81.13 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.138.81.27 (US/United States/27.81.138.34.bc.googleusercontent.com)
show less
SQL Injection
๐ฉ๐ช
Philister11
2026-08-29 00:17:58
(2 days ago)
CrowdSec: crowdsecurity/http-sensitive-files (US/AS396982)
Web App Attack
Hacking
๐ฉ๐ช
mygcode.de
2026-08-28 23:42:41
(2 days ago)
Scanning for Exploits
Bad Web Bot
๐ฉ๐ช
rollenspiel.network
2026-08-28 22:31:49
(2 days ago)
CrowdSec detection: crowdsecurity/http-sensitive-files
Web App Attack