Anonymous
2026-09-22 10:06:41
(4 hours ago)
[Drupal AbuseIPDB module] Request path is blacklisted. /wp-admin/phpinfo.php
Web App Attack
๐จ๐ญ
leo1305
2026-09-22 06:14:31
(8 hours ago)
CrowdSec detection | scenario: http-sensitive-files
Web App Attack
Exploited Host
๐บ๐ธ
TPI-Abuse
2026-09-22 01:37:31
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.153.165.164 (164.165.153.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.153.165.164 (164.165.153.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 21:37:25.064052 2026] [security2:error] [pid 28918:tid 28918] [client 34.153.165.164:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "backend.grainavi.com"] [uri "/.git/config"] [unique_id "arHb1TVPE26cGGdYdfnlsgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-21 19:48:43
(18 hours ago)
Backdrop CMS module - malicious activity detected
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 01:35:33
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.153.165.164 (164.165.153.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.153.165.164 (164.165.153.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 21:35:26.142368 2026] [security2:error] [pid 29939:tid 29939] [client 34.153.165.164:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.empoweruamerica.org"] [uri "/.git/config"] [unique_id "arCJ3mxYMo7Fmi8bONGuxgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ณ
evicky2002
2026-09-21 00:02:56
(1 day ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ญ๐ณ
unph
2026-09-20 23:10:52
(1 day ago)
Intento de acceso sospechoso bloqueado por AbuseIPDB Blocker Plugin
Brute-Force
๐ซ๐ท
phoenix1jl96
2026-09-20 18:21:36
(1 day ago)
2026/09/20 20:21:35 [error] 901664#901664: *123811 open() "/home/user-data/www/default/mailer/.env" ...
show more
2026/09/20 20:21:35 [error] 901664#901664: *123811 open() "/home/user-data/www/default/mailer/.env" failed (2: No such file or directory), client: 34.153.165.164, server: autodiscover.dsatec.fr, request: "GET /mailer/.env HTTP/1.1", host: "autodiscover.dsatec.fr"
2026/09/20 20:21:35 [error] 901664#901664: *123811 open() "/usr/local/lib/roundcubemail/.env" failed (2: No such file or directory), client: 34.153.165.164, server: autodiscover.dsatec.fr, request: "GET /mail/.env HTTP/1.1", host: "autodiscover.dsatec.fr"
...
show less
DNS Compromise
DNS Poisoning
DDoS Attack
Ping of Death
Web Spam
Email Spam
Blog Spam
Port Scan
Hacking
Brute-Force
Bad Web Bot
SSH
Web App Attack
๐ฎ๐น
VHosting
2026-09-20 14:35:03
(2 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 14:18:30
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.153.165.164 (164.165.153.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.153.165.164 (164.165.153.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 10:18:26.813916 2026] [security2:error] [pid 15990:tid 15990] [client 34.153.165.164:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.distro.media"] [uri "/.git/config"] [unique_id "aq_rMn6e-vQlE-JWiA4NSQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Lacrimosa99
2026-09-20 12:08:09
(2 days ago)
34.153.165.164 - - [20/Sep/2026:14:08:07 +0200] "GET /admin/.env HTTP/1.1" 404 418 "-" "Mozilla/5.0 ...
show more
34.153.165.164 - - [20/Sep/2026:14:08:07 +0200] "GET /admin/.env HTTP/1.1" 404 418 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.153.165.164 - - [20/Sep/2026:14:08:07 +0200] "GET /database/.env HTTP/1.1" 404 418 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.153.165.164 - - [20/Sep/2026:14:08:08 +0200] "GET /admin-panel/.env HTTP/1.1" 404 418 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Web Spam
๐บ๐ฆ
URAN Publishing Service
2026-09-19 11:37:53
(3 days ago)
[19/Sep/2026:14:37:52 +0300] -- 34.153.165.164 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.gi ...
show more
[19/Sep/2026:14:37:52 +0300] -- 34.153.165.164 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/config HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-19 11:30:02
(3 days ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-19 11:14:46
(3 days ago)
Excessive multi-domain requests
Brute-Force
Anonymous
2026-09-19 08:07:20
(3 days ago)
Trying to access config files
Web App Attack