🇮🇹
Inartis
2026-09-07 01:31:28
(6 hours ago)
34.156.154.64 - - [07/Sep/2026:03:31:24 +0200] "GET /.env HTTP/1.1" 302 435 "-" "Mozilla/5.0 (compat ...
show more
34.156.154.64 - - [07/Sep/2026:03:31:24 +0200] "GET /.env HTTP/1.1" 302 435 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36"
34.156.154.64 - - [07/Sep/2026:03:31:25 +0200] "GET /.env HTTP/1.1" 302 435 "-" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)"
34.156.154.64 - - [07/Sep/2026:03:31:25 +0200] "GET /.env HTTP/1.1" 403 5422 "http://www.abanogolf.it/.env" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
infra-monitor
2026-09-07 01:00:06
(7 hours ago)
Automated ban via infra-monitor: crowdsecurity/http-probing, suspicious-probe
Port Scan
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 00:44:07
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.156.154.64 (64.154.156.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.156.154.64 (64.154.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 20:44:00.965182 2026] [security2:error] [pid 8249:tid 8249] [client 34.156.154.64:51284] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "virtualvideo.org"] [uri "/.git/config"] [unique_id "ap4I0H3AGgPf_vdaHMa0uwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
screwlooseit.com.au
2026-09-06 22:41:07
(9 hours ago)
Blocked by CSF 13 firewall - Rule: config-dotfile
US/United States/64.154.156.34.bc.googleuserconten ...
show more
Blocked by CSF 13 firewall - Rule: config-dotfile
US/United States/64.154.156.34.bc.googleusercontent.com
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 22:31:58
(9 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.156.154.64 (64.154.156.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.156.154.64 (64.154.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 18:31:52.028042 2026] [security2:error] [pid 1298770:tid 1298865] [client 34.156.154.64:44362] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.adambarnard.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.adambarnard.com"] [uri "/rclone.conf"] [unique_id "ap3p2JUjPXe-IK_tUmCtjgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇭
zynex
2026-09-06 20:52:46
(11 hours ago)
URL Probing: /.env
Web App Attack
🇧🇪
cmbplf
2026-09-06 20:42:16
(11 hours ago)
386 requests with url.path */@fs/*
Brute-Force
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-06 19:42:15
(12 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.156.154.64 (64.154.156.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.156.154.64 (64.154.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 15:42:11.092814 2026] [security2:error] [pid 21394:tid 21394] [client 34.156.154.64:44092] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||goatedlottosecrets.com|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "goatedlottosecrets.com"] [uri "/ssl/localhost.key"] [unique_id "ap3CE0k5gbeNCeebZHhzCQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
big-cloud.nl
2026-09-06 19:41:21
(12 hours ago)
Try to access /@fs/src/.env?raw??
Web App Attack
🇳🇱
Site.eu
2026-09-06 19:23:57
(12 hours ago)
Excessive multi-domain requests
Brute-Force
Anonymous
2026-09-06 19:01:37
(13 hours ago)
Multiple web server 400 error codes from same source ip
Web App Attack
🇺🇸
dot.mg
2026-09-06 18:32:05
(13 hours ago)
Scan of vulnerable files
Web App Attack
🇳🇱
Savvii
2026-09-06 18:27:08
(13 hours ago)
20 attempts against mh-misbehave-ban on eris
Brute-Force
Bad Web Bot
Web App Attack
🇨🇦
polycoda
2026-09-06 18:05:15
(14 hours ago)
AutoBlock: 📡 Port Scan (Non Decay-Based) - ⚙️ Configuration File Access (Non Decay-Based) - ↪️ Exces ...
show more
AutoBlock: 📡 Port Scan (Non Decay-Based) - ⚙️ Configuration File Access (Non Decay-Based) - ↪️ Excessive 30X Errors (Decay-Based)
show less
Port Scan
Hacking
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-06 16:43:29
(15 hours ago)
Multiple WAF Violations
Web App Attack