🇦🇺
2000cn.com.au
2026-09-12 14:56:49
(48 minutes ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇫🇷
regishoussin
2026-09-12 12:48:12
(2 hours ago)
Automated web scanning detected by Wazuh (rule 100241): repeated 400/404 errors from mass probing of ...
show more
Automated web scanning detected by Wazuh (rule 100241): repeated 400/404 errors from mass probing of admin/backdoor paths (e.g. wp-login.php, known CMS shell filenames) on an Apache web server, on 2026-09-12 12:48 UTC.
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 11:59:08
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.154.72.132 (132.72.154.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.154.72.132 (132.72.154.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 07:59:03.588780 2026] [security2:error] [pid 9668:tid 9668] [client 34.154.72.132:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.plaiatech.com"] [uri "/.git/config"] [unique_id "aqU-hyEfTqB3Vw_SZv4E2wAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 11:18:37
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.154.72.132 (132.72.154.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.154.72.132 (132.72.154.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 07:18:31.951791 2026] [security2:error] [pid 15714:tid 15714] [client 34.154.72.132:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.pixacast.com"] [uri "/.git/config"] [unique_id "aqU1B7N4V9XtnNis61U4jgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
TheDjRider
2026-09-12 10:46:12
(4 hours ago)
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban tri ...
show more
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban triggered. Detection time (UTC): 2026-09-12T10:46:09.918411992Z. Context: http_status=200
show less
Web App Attack
🇳🇱
Site.eu
2026-09-12 10:43:59
(5 hours ago)
Excessive multi-domain requests
Brute-Force
🇨🇭
beatsnet.com
2026-09-12 10:32:47
(5 hours ago)
[Sat Sep 12 12:32:45.039000 2026] [proxy_fcgi:error] [pid 57529:tid 15978342219792] [client 34.154.7 ...
show more
[Sat Sep 12 12:32:45.039000 2026] [proxy_fcgi:error] [pid 57529:tid 15978342219792] [client 34.154.72.132:37400] AH01071: Got error 'Primary script unknown'
[Sat Sep 12 12:32:45.633545 2026] [proxy_fcgi:error] [pid 57529:tid 15978342221840] [client 34.154.72.132:37400] AH01071: Got error 'Primary script unknown'
[Sat Sep 12 12:32:45.795373 2026] [proxy_fcgi:error] [pid 57529:tid 15978342221840] [client 34.154.72.132:37400] AH01071: Got error 'Primary script unknown'
[Sat Sep 12 12:32:45.994475 2026] [proxy_fcgi:error] [pid 57529:tid 15978342221840] [client 34.154.72.132:37400] AH01071: Got error 'Primary script unknown'
...
show less
Brute-Force
Web App Attack
🇫🇮
YF
2026-09-12 09:00:40
(6 hours ago)
404 errors Vulnerability scan
Web App Attack
🇫🇷
phoenix1jl96
2026-09-12 05:52:01
(9 hours ago)
2026/09/12 07:52:01 [error] 4744#4744: *58622 open() "/home/user-data/www/default/mailer/.env" faile ...
show more
2026/09/12 07:52:01 [error] 4744#4744: *58622 open() "/home/user-data/www/default/mailer/.env" failed (2: No such file or directory), client: 34.154.72.132, server: autodiscover.pbs.ledemon.us, request: "GET /mailer/.env HTTP/1.1", host: "autodiscover.pbs.ledemon.us"
2026/09/12 07:52:01 [error] 4744#4744: *58622 open() "/usr/local/lib/roundcubemail/.env" failed (2: No such file or directory), client: 34.154.72.132, server: autodiscover.pbs.ledemon.us, request: "GET /mail/.env HTTP/1.1", host: "autodiscover.pbs.ledemon.us"
...
show less
DNS Compromise
DNS Poisoning
DDoS Attack
Ping of Death
Web Spam
Email Spam
Blog Spam
Port Scan
Hacking
Brute-Force
Bad Web Bot
SSH
Web App Attack
🇺🇸
Rocky Mountain Bioengineering Symposium
2026-09-12 05:38:32
(10 hours ago)
[Fri Sep 11 23:38:26.919995 2026] [authz_core:error] [pid 354183:tid 139763780634176] [client 34.154 ...
show more
[Fri Sep 11 23:38:26.919995 2026] [authz_core:error] [pid 354183:tid 139763780634176] [client 34.154.72.132:33210] AH01630: client denied by server configuration: /var/www/horde/.env.bak
[Fri Sep 11 23:38:31.829628 2026] [authz_core:error] [pid 354183:tid 139765600998976] [client 34.154.72.132:33210] AH01630: client denied by server configuration: /var/www/horde/.env.dist
[Fri Sep 11 23:38:31.962207 2026] [authz_core:error] [pid 354183:tid 139763738670656] [client 34.154.72.132:33210] AH01630: client denied by server configuration: /var/www/horde/.env.swp
...
show less
Bad Web Bot
🇸🇪
nekopavel
2026-09-12 05:27:17
(10 hours ago)
34.154.72.132 - - [12/Sep/2026:07:27:14 +0200]"GET /.git/config HTTP/1.1" 404 178"-" autodiscover.pa ...
show more
34.154.72.132 - - [12/Sep/2026:07:27:14 +0200]"GET /.git/config HTTP/1.1" 404 178"-" autodiscover.pavel.gg "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36""0.001" "0.000""Milan" "IT"
34.154.72.132 - - [12/Sep/2026:07:27:14 +0200]"GET /.env HTTP/1.1" 404 178"-" autodiscover.pavel.gg "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36""0.002" "0.001""Milan" "IT"
34.154.72.132 - - [12/Sep/2026:07:27:14 +0200]"GET /.env.local HTTP/1.1" 404 178"-" autodiscover.pavel.gg "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36""0.002" "0.000""Milan" "IT"
...
show less
Hacking
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 04:24:41
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.154.72.132 (132.72.154.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.154.72.132 (132.72.154.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 00:24:36.962564 2026] [security2:error] [pid 12133:tid 12133] [client 34.154.72.132:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "atlascoombs.com"] [uri "/.git/config"] [unique_id "aqTUBEQq-9gNrIzdjfQ3YwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
daveoctober
2026-09-12 03:39:27
(12 hours ago)
October Sentinel: honeypot triggered
Bad Web Bot
Web App Attack
Anonymous
2026-09-12 03:38:25
(12 hours ago)
Banned by Fail2Ban on server
Web App Attack
🇨🇭
m_vlasov
2026-09-12 03:19:45
(12 hours ago)
SSH/Telnet honeypot: 0 login attempts, 0 sessions, 0 shell commands.
Hacking