๐ต๐ฑ
lns.bz
2026-07-21 20:23:38
(4 hours ago)
Web app attack [PL.Lu]
Exploited Host
Web App Attack
๐ซ๐ฎ
000rosiu
2026-07-21 19:29:05
(5 hours ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action: BLOCK | Protocol: HTTP/1.1 (HEAD) | Endpo ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action: BLOCK | Protocol: HTTP/1.1 (HEAD) | Endpoint: /.env.production | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.0.0 Safari/537.36 โข Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-07-21 19:28:14
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.139.141.56 (56.141.139.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.139.141.56 (56.141.139.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 15:28:10.672394 2026] [security2:error] [pid 5094:tid 5094] [client 34.139.141.56:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nsfwmanager.com"] [uri "/.env.local"] [unique_id "al_ISlkCymXTEVlJevEclQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-07-21 18:39:13
(6 hours ago)
20 attempts against mh-misbehave-ban on eris
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Webhoster
2026-07-21 18:13:59
(6 hours ago)
{"ClientAddr":"172.71.23.195:9750","ClientHost":"34.139.141.56","ClientPort":"9750","ClientUsername" ...
show more
{"ClientAddr":"172.71.23.195:9750","ClientHost":"34.139.141.56","ClientPort":"9750","ClientUsername":"-","DownstreamContentSize":0,"DownstreamStatus":403,"Duration":20621448,"OriginContentSize":0,"OriginDuration":0,"OriginStatus":0,"Overhead":20621448,"RequestAddr":"sync-in.timvdberg.dev","RequestContentSize":0,"RequestCount":529346,"RequestHost":"sync-in.timvdberg.dev","RequestMethod":"HEAD","RequestPath":"/.dev.vars","RequestPort":"-","RequestProtocol":"HTTP/2.0","RequestScheme":"https","RetryAttempts":0,"RouterName":"sync-in@file","StartLocal":"2026-07-21T18:13:58.655782904Z","StartUTC":"2026-07-21T18:13:58.655782904Z","TLSCipher":"TLS_AES_128_GCM_SHA256","TLSVersion":"1.3","entryPointName":"https","level":"info","msg":"","request_Cf-Connecting-Ip":"34.139.141.56","request_X-Forwarded-For":"34.139.141.56","request_X-Real-Ip":"172.71.23.195","time":"2026-07-21T18:13:58Z"}
{"ClientAddr":"104.22.1.209:12070","ClientHost":"34.139.141.56","ClientPort":"12070","ClientUsername":"-","Downst
...
show less
Port Scan
Hacking
Bad Web Bot
Web App Attack
๐จ๐ญ
Cybercat
2026-07-21 17:47:07
(7 hours ago)
CrowdSec detection: crowdsecurity/http-sensitive-files
Hacking
๐ฉ๐ช
Lino Project
2026-07-21 17:44:18
(7 hours ago)
CrowdSec abuse IP report (host SRV-2) Scenario: crowdsecurity/http-sensitive-files
Hacking
Anonymous
2026-07-21 17:39:35
(7 hours ago)
Web App Attack
Port Scan
๐ฎ๐น
VHosting
2026-07-21 17:35:03
(7 hours ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐ฉ๐ช
macrob
2026-07-21 16:59:39
(8 hours ago)
2026/07/21 16:59:37 [error] 2535539#2535539: *396737911 access forbidden by rule, client: 34.139.141 ...
show more
2026/07/21 16:59:37 [error] 2535539#2535539: *396737911 access forbidden by rule, client: 34.139.141.56, server: fn.binixo.es, request: "HEAD /.env.bak HTTP/2.0", host: "events.luckentra.org", referrer: "https://www.google.com/search?q=events.luckentra.org"
2026/07/21 16:59:37 [error] 2535540#2535540: *396737893 access forbidden by rule, client: 34.139.141.56, server: fn.binixo.es, request: "HEAD /.env.development.local HTTP/2.0", host: "events.luckentra.org", referrer: "https://www.google.com/search?q=events.luckentra.org"
2026/07/21 16:59:37 [error] 2535540#2535540: *396737877 access forbidden by rule, client: 34.139.141.56, server: fn.binixo.es, request: "HEAD /.git/config HTTP/2.0", host: "events.luckentra.org", referrer: "https://www.google.com/search?q=events.luckentra.org"
...
show less
Web App Attack
๐ณ๐ฑ
Lentini
2026-07-21 15:39:25
(9 hours ago)
visuitslagen.nl: malicious request:/.env.test
Web App Attack
๐ซ๐ฎ
xyz.rip
2026-07-21 15:13:13
(9 hours ago)
WAF Violation
...
Hacking
Web App Attack
๐บ๐ธ
paulo.apoloni
2026-07-21 15:07:41
(9 hours ago)
34.139.141.56 - - [21/Jul/2026:12:07:41 -0300] "HEAD /.aws/credentials HTTP/1.1" 444 0 "-" "Mozilla/ ...
show more
34.139.141.56 - - [21/Jul/2026:12:07:41 -0300] "HEAD /.aws/credentials HTTP/1.1" 444 0 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
34.139.141.56 - - [21/Jul/2026:12:07:41 -0300] "HEAD /.env.save HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:137.0) Gecko/20100101 Firefox/137.0"
34.139.141.56 - - [21/Jul/2026:12:07:41 -0300] "HEAD /.git/config HTTP/1.1" 444 0 "https://www.google.com/search?q=cownter.agr.br" "Mozilla/5.0 (Linux; Android 14; Pixel 8) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.6422.113 Mobile Safari/537.36"
34.139.141.56 - - [21/Jul/2026:12:07:41 -0300] "HEAD /.env HTTP/1.1" 444 0 "https://www.google.com/search?q=cownter.agr.br" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.0.0 Safari/537.36"
34.139.141.56 - - [21/Jul/2026:12:07:41 -0300] "HEAD /.env.old HTTP/1.1" 444 0 "https://www.google.com/search?q=cownter.agr.br" "Mozilla/5.0 (Windows NT 10.0; Win64; x
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
maxpower
2026-07-21 14:42:59
(10 hours ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.139.141.56 (US/United States/56.141.1 ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.139.141.56 (US/United States/56.141.139.34.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.139.141.56 - - [21/Jul/2026:16:42:51 +0200] "HEAD /.aws/credentials HTTP/2.0" 404 0 "-" "Mozilla/5.0 (Linux; Android 14; Pixel 8) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.6422.113 Mobile Safari/537.36" "34.139.141.56" host=brokerleader.it
show less
Port Scan
Anonymous
2026-07-21 13:46:16
(11 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack