🇦🇺
rubixstudios
2026-09-15 04:06:04
(6 days ago)
Excessive HTTP requests consistent with automated attack behaviour detected by Imunify360
DDoS Attack
Brute-Force
Web App Attack
🇩🇪
Blexyel
2026-09-15 02:25:55
(6 days ago)
34.152.11.146 - - [15/Sep/2026:04:25:54 +0200] "GET /.git/config HTTP/1.1" 404 120 "-" "Mozilla/5.0 ...
show more
34.152.11.146 - - [15/Sep/2026:04:25:54 +0200] "GET /.git/config HTTP/1.1" 404 120 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-15 02:06:01
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 34.152.11.146 (146.11.152.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.152.11.146 (146.11.152.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 22:05:54.791219 2026] [security2:error] [pid 27474:tid 27474] [client 34.152.11.146:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.theabstractpress.com"] [uri "/.git/config"] [unique_id "aqioAv6Ef4AV9hicx4hgSgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
phoenix1jl96
2026-09-15 01:16:57
(6 days ago)
2026/09/15 03:16:56 [error] 1444054#1444054: *172104 open() "/home/user-data/www/default/mailer/.env ...
show more
2026/09/15 03:16:56 [error] 1444054#1444054: *172104 open() "/home/user-data/www/default/mailer/.env" failed (2: No such file or directory), client: 34.152.11.146, server: autodiscover.test.ledemon.us, request: "GET /mailer/.env HTTP/1.1", host: "autodiscover.test.ledemon.us"
2026/09/15 03:16:56 [error] 1444054#1444054: *172104 open() "/usr/local/lib/roundcubemail/.env" failed (2: No such file or directory), client: 34.152.11.146, server: autodiscover.test.ledemon.us, request: "GET /mail/.env HTTP/1.1", host: "autodiscover.test.ledemon.us"
...
show less
DNS Compromise
DNS Poisoning
DDoS Attack
Ping of Death
Web Spam
Email Spam
Blog Spam
Port Scan
Hacking
Brute-Force
Bad Web Bot
SSH
Web App Attack
🇫🇷
Catalin Negru
2026-09-14 22:57:46
(6 days ago)
Recidive ban by fail2ban on server.blackbit.ro
Brute-Force
🇺🇸
Rocky Mountain Bioengineering Symposium
2026-09-14 21:36:07
(6 days ago)
[Mon Sep 14 15:36:03.812218 2026] [authz_core:error] [pid 2247:tid 140603597710912] [client 34.152.1 ...
show more
[Mon Sep 14 15:36:03.812218 2026] [authz_core:error] [pid 2247:tid 140603597710912] [client 34.152.11.146:57848] AH01630: client denied by server configuration: /var/www/horde/.env.bak
[Mon Sep 14 15:36:06.394752 2026] [authz_core:error] [pid 2247:tid 140603698423360] [client 34.152.11.146:57848] AH01630: client denied by server configuration: /var/www/horde/.env.dist
[Mon Sep 14 15:36:06.425824 2026] [authz_core:error] [pid 2247:tid 140603438249536] [client 34.152.11.146:57848] AH01630: client denied by server configuration: /var/www/horde/.env.swp
...
show less
Bad Web Bot
🇵🇱
miriks
2026-09-14 16:51:32
(6 days ago)
Automated scan detected: GET /.git/config — UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKi ...
show more
Automated scan detected: GET /.git/config — UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
show less
Port Scan
Web App Attack
🇨🇭
ca
2026-09-14 14:55:27
(6 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
🇫🇷
Lacrimosa99
2026-09-14 14:40:13
(6 days ago)
34.152.11.146 - - [14/Sep/2026:16:40:04 +0200] "GET /admin/.env HTTP/1.1" 404 418 "-" "Mozilla/5.0 ( ...
show more
34.152.11.146 - - [14/Sep/2026:16:40:04 +0200] "GET /admin/.env HTTP/1.1" 404 418 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.152.11.146 - - [14/Sep/2026:16:40:05 +0200] "GET /database/.env HTTP/1.1" 404 418 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.152.11.146 - - [14/Sep/2026:16:40:12 +0200] "GET /admin-panel/.env HTTP/1.1" 404 418 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Web Spam
🇿🇦
conure.sh
2026-09-13 12:08:11
(1 week ago)
csagent: score 21.4: 404 noise floor x6, secrets grab x2; 1 domain(s) in 2s
Web App Attack
🇮🇳
evicky2002
2026-09-13 06:00:01
(1 week ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
Anonymous
2026-09-12 14:54:44
(1 week ago)
Auto-reported by Fail2Ban (NPM-Auth)
Web App Attack
🇮🇹
ciccio diddo
2026-09-12 13:33:56
(1 week ago)
High Burst multiple 40X port:Tcp/80,443
Brute-Force
Web App Attack
🇿🇦
conure.sh
2026-09-12 12:03:51
(1 week ago)
csagent: score 21.4: 404 noise floor x6, secrets grab x2; 1 domain(s) in 2s
Web App Attack
🇨🇦
polycoda
2026-09-12 11:16:10
(1 week ago)
🔥 VERY AGGRESSIVE SCANNER probed over 500 inexistent files and PHP scripts in less than an hour.
Hacking
Web App Attack