🇩🇪
ghostwarriors
2026-09-08 04:20:06
(7 hours ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
🇩🇪
yitzhaq
2026-09-08 04:00:13
(8 hours ago)
34.155.215.10 - - [08/Sep/2026:06:00:06 +0200] "GET /shopify/.env HTTP/1.1" 404 520 "-" "Mozilla/5.0 ...
show more
34.155.215.10 - - [08/Sep/2026:06:00:06 +0200] "GET /shopify/.env HTTP/1.1" 404 520 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.155.215.10 - - [08/Sep/2026:06:00:06 +0200] "GET /prestashop/.env HTTP/1.1" 404 520 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.155.215.10 - - [08/Sep/2026:06:00:06 +0200] "GET /codeigniter/.env HTTP/1.1" 404 520 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.155.215.10 - - [08/Sep/2026:06:00:06 +0200] "GET /cakephp/.env HTTP/1.1" 404 520 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.155.215.10 - - [08/Sep/2026:06:00:06 +0200] "GET /zend/.env HTTP/1.1" 404 520 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.155.215.10 - - [08/Sep/2026:06:00
show less
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-08 01:00:11
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.155.215.10 (10.215.155.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.155.215.10 (10.215.155.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 21:00:04.804310 2026] [security2:error] [pid 22108:tid 22108] [client 34.155.215.10:51810] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "francisautodetailing.com"] [uri "/.git/config"] [unique_id "ap9eFMAgXVriLQtmfYuCaQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 18:07:04
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.155.215.10 (10.215.155.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.155.215.10 (10.215.155.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 14:06:59.995229 2026] [security2:error] [pid 14982:tid 14982] [client 34.155.215.10:51330] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "calvianet.com"] [uri "/.git/config"] [unique_id "ap79Q-NicK9i8HuGj59Z1AAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-07 08:35:36
(1 day ago)
Excessive 404/403 errors
Brute-Force
🇬🇧
consul.to
2026-09-07 07:03:22
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
🇩🇪
ger-stg-sifi1
2026-09-07 05:51:20
(1 day ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
🇫🇷
Octopuce
2026-09-07 04:14:25
(1 day ago)
Aggressive web search of vulnerable pages: / /.env /.env.local /app/.env /apps/.env ...
Web App Attack
🇩🇪
crypto i trust, hold i must
2026-09-07 03:34:19
(1 day ago)
Web scanner path: /actuator/env
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 03:26:13
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.155.215.10 (10.215.155.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.155.215.10 (10.215.155.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 23:26:05.235705 2026] [security2:error] [pid 32671:tid 32671] [client 34.155.215.10:50674] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "frenosilent.ar.misterflores.com"] [uri "/.git/config"] [unique_id "ap4uzXYDcEStLtnz-zJEKAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-07 03:16:51
(1 day ago)
Multiple WAF Violations
Web App Attack
🇩🇪
FeG Deutschland
2026-09-07 03:11:02
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 27
Exploited Host
Web App Attack
🇩🇪
Gwyneth Llewelyn
2026-09-07 02:50:27
(1 day ago)
2026/09/07 03:50:25 [error] 380594#380594: *3368622 access forbidden by rule, client: 34.155.215.10, ...
show more
2026/09/07 03:50:25 [error] 380594#380594: *3368622 access forbidden by rule, client: 34.155.215.10, server: betatechnologies.info, request: "GET /.env HTTP/1.1", host: "freeswitch.betatechnologies.info"
34.155.215.10 - - [07/Sep/2026:03:50:25 +0100] "GET /.env HTTP/1.1" 403 1178 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
2026/09/07 03:50:25 [error] 380594#380594: *3368630 access forbidden by rule, client: 34.155.215.10, server: betatechnologies.info, request: "GET /app/.env HTTP/1.1", host: "freeswitch.betatechnologies.info"
show less
Brute-Force
Web App Attack
🇩🇪
Philister11
2026-09-07 01:49:32
(1 day ago)
CrowdSec: crowdsecurity/http-admin-interface-probing (FR/AS396982)
Web App Attack
Hacking
🇩🇪
Philister11
2026-09-07 01:08:30
(1 day ago)
CrowdSec: crowdsecurity/http-sensitive-files (FR/AS396982)
Web App Attack
Hacking