๐ฌ๐ง
andypiper
2026-09-15 01:01:32
(2 days ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
๐ซ๐ท
Catalin Negru
2026-09-15 00:14:00
(2 days ago)
Recidive ban by fail2ban on server.blackbit.ro
Brute-Force
๐ซ๐ท
Catalin Negru
2026-09-12 05:39:10
(5 days ago)
Recidive ban by fail2ban on server.blackbit.ro
Brute-Force
๐ซ๐ท
Catalin Negru
2026-09-08 19:07:07
(1 week ago)
Recidive ban by fail2ban on server.blackbit.ro
Brute-Force
๐ณ๐ฑ
wlt-blocker
2026-09-06 06:02:29
(1 week ago)
Unauthorized access to webpage admin
Web App Attack
Anonymous
2026-09-06 03:09:01
(1 week ago)
34.141.85.73 - - [06/Sep/2026:03:09:01 +0000] "GET /.env.prod HTTP/1.1" 404 4319 "-" "crusader-worke ...
show more
34.141.85.73 - - [06/Sep/2026:03:09:01 +0000] "GET /.env.prod HTTP/1.1" 404 4319 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-06 02:58:28
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.141.85.73 (73.85.141.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.141.85.73 (73.85.141.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:58:20.788019 2026] [security2:error] [pid 26338:tid 26338] [client 34.141.85.73:34816] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.doubloonswap.com"] [uri "/.env.dev"] [unique_id "apzWzLdoFuLvW2Vz_eOICwAAAGc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-09-06 02:57:29
(1 week ago)
[SunSep0604:57:23.6197812026][security2:error][pid2361300:tid2361342][client34.141.85.73:0]ModSecuri ...
show more
[SunSep0604:57:23.6197812026][security2:error][pid2361300:tid2361342][client34.141.85.73:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"webmail.fidmeyer.ch\"][uri\"/.env.old\"][unique_id\"apzWk3DM18kK-XQm-zZzywAAABc\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-06 01:01:23
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.141.85.73 (73.85.141.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.141.85.73 (73.85.141.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:01:20.171988 2026] [security2:error] [pid 32178:tid 32178] [client 34.141.85.73:53380] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "elizabethkwon.com"] [uri "/.env.prod"] [unique_id "apy7YMZ7oq1UezJQBnNINgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
leo1305
2026-09-06 00:28:43
(1 week ago)
CrowdSec detection | scenario: http-sensitive-files
Web App Attack
Exploited Host
๐บ๐ธ
TPI-Abuse
2026-09-06 00:28:33
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.141.85.73 (73.85.141.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.141.85.73 (73.85.141.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:28:26.918722 2026] [security2:error] [pid 32665:tid 32665] [client 34.141.85.73:56794] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vigants.com"] [uri "/.env.example"] [unique_id "apyzqhpvINmXoR-AY8Y4NgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
raph
2026-09-06 00:02:50
(1 week ago)
[Wordpress] crawler /wp-admin/*, /wp-content/*, etc.
Bad Web Bot
Web App Attack
๐ฎ๐ณ
evicky2002
2026-09-06 00:02:40
(1 week ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ซ๐ท
Stara
2026-09-05 23:36:38
(1 week ago)
ModSecurity detected web attack - .env/config probing or SQLi/Code injection (Rule 949110)
Brute-Force
SSH
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-05 23:08:04
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.141.85.73 (73.85.141.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.141.85.73 (73.85.141.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:07:59.820969 2026] [security2:error] [pid 11731:tid 11803] [client 34.141.85.73:50242] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rusherair.piazza9.com"] [uri "/.env.local"] [unique_id "apygz5sU0UwcvWhlsZpPtgAAAcw"]
show less
Brute-Force
Bad Web Bot
Web App Attack