🇸🇪
vaia.cloud
2026-09-11 09:45:01
(22 minutes ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
🇫🇷
dwmp
2026-09-11 08:08:05
(1 hour ago)
[11/Sep/2026:10:08:04.039893 +0200] aqO25Ms9jitvFb5EKEmizAAAAFA 34.151.215.13 51808 38.242.227.117 7 ...
show more
[11/Sep/2026:10:08:04.039893 +0200] aqO25Ms9jitvFb5EKEmizAAAAFA 34.151.215.13 51808 38.242.227.117 7081
[11/Sep/2026:10:08:04.508440 +0200] aqO25Ms9jitvFb5EKEmizQAAAEs 34.151.215.13 51816 38.242.227.117 7081
[11/Sep/2026:10:08:04.746327 +0200] aqO25Ms9jitvFb5EKEmizgAAAEI 34.151.215.13 51824 38.242.227.117 7081
...
show less
Brute-Force
SSH
🇩🇪
ghostwarriors
2026-09-11 06:50:09
(3 hours ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
🇩🇪
yitzhaq
2026-09-11 06:39:37
(3 hours ago)
34.151.215.13 - - [11/Sep/2026:08:39:31 +0200] "POST / HTTP/1.1" 200 1093 "-" "Mozilla/5.0 (Macintos ...
show more
34.151.215.13 - - [11/Sep/2026:08:39:31 +0200] "POST / HTTP/1.1" 200 1093 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.151.215.13 - - [11/Sep/2026:08:39:32 +0200] "POST / HTTP/1.1" 200 1093 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.151.215.13 - - [11/Sep/2026:08:39:32 +0200] "GET /.git/config HTTP/1.1" 403 528 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.151.215.13 - - [11/Sep/2026:08:39:32 +0200] "GET /.env HTTP/1.1" 404 525 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.151.215.13 - - [11/Sep/2026:08:39:33 +0200] "GET /.env.local HTTP/1.1" 404 525 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari
show less
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-11 04:52:57
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.151.215.13 (13.215.151.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.151.215.13 (13.215.151.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 00:52:50.093112 2026] [security2:error] [pid 12788:tid 12788] [client 34.151.215.13:60662] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ace.jmnr.net"] [uri "/.git/config"] [unique_id "aqOJIlBLlSlUPn4ZTzLVtwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
debestelapp
2026-09-11 03:20:15
(6 hours ago)
Web App Attack
🇩🇪
big-cloud.nl
2026-09-11 02:37:18
(7 hours ago)
Try to access /.git/config
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 02:16:46
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.151.215.13 (13.215.151.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.151.215.13 (13.215.151.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 22:16:42.347455 2026] [security2:error] [pid 14363:tid 14363] [client 34.151.215.13:41672] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "acctusa.net"] [uri "/.git/config"] [unique_id "aqNkioXOdP-aKYdmvkp_1QAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-10 07:10:41
(1 day ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇧🇪
cmbplf
2026-09-10 06:04:11
(1 day ago)
15.297 requests in 1 hour (1w6h59m)
Brute-Force
Bad Web Bot
🇫🇷
masterguru
2026-09-10 05:43:11
(1 day ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-196)
Hacking
Web App Attack
🇮🇹
VHosting
2026-09-10 05:25:02
(1 day ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇫🇮
mnazibo
2026-09-10 05:00:05
(1 day ago)
Date: 10/Sep/2026 07:57:10 | Reported IP: 34.151.215.13 mod_security | id: 930130 932130 932235 9322 ...
show more
Date: 10/Sep/2026 07:57:10 | Reported IP: 34.151.215.13 mod_security | id: 930130 932130 932235 932260 933135 934100 934130 942151 942550 | BR/group.my_domain/- | Connections: 258 | Blocked: Permanent Block: [LF_MODSEC] | URIs: /; /actions/.env; /admin/.env; /administrator/.env; /administrator/phpinfo.php; /admin-panel/.env; /admin/phpinfo.php; /angular/.env; /ansible/.env; /api/dev/.env; /api/.env; /api/staging/.env; /api/v1/.env; /api/v2/.env; /api/v3/.env; /app/.env; /application_default_credentials.json; /application/.env; /apps/.env; /aws/.env; /azure/.env; /backend/.env; /backup/.env; /backups/.env; /beta/.env; /beta/phpinfo.php; /bin/.env; /bootstrap/.env; /brevo/.env; /build/.env; /buildkite/.env; /bulk/.env; /cache/.env; /cakephp/.env; /campaign/.env; /cd/.env; /ci/.env; /circleci/.env; /client/.env; /cloud/.env; /cms/.env; /codeigniter/.env; /config/app/.env; /config/.env; /.config/gcloud/application_default_credentials.json;
show less
SQL Injection
Brute-Force
Bad Web Bot
🇳🇱
WeCloudit-Anti-Abuse
2026-09-10 04:06:59
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇫🇷
Octopuce
2026-09-10 04:04:44
(1 day ago)
Aggressive web search of vulnerable pages: /.env /.env.local /app/.env /apps/.env /api/.env ...
Web App Attack