๐ฉ๐ช
iNetWorker
2026-09-16 15:08:09
(6 hours ago)
trolling for resource vulnerabilities
Web App Attack
๐ณ๐ฑ
ConsulHosting
2026-09-16 14:54:04
(6 hours ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
๐ฉ๐ช
LRob
2026-09-16 14:51:52
(6 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.git/config | 2026-09-16 14:51 UTC
show less
Hacking
Web App Attack
๐ฆ๐บ
2000cn.com.au
2026-09-16 14:43:14
(7 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-16 14:43:08
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.158.238.120 (120.238.158.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.158.238.120 (120.238.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 10:43:03.518421 2026] [security2:error] [pid 20910:tid 20910] [client 34.158.238.120:49314] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ballast-capital.com"] [uri "/.git/config"] [unique_id "aqqq932Dh9MuQK9t5wL3vgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 14:21:32
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.158.238.120 (120.238.158.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.158.238.120 (120.238.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 10:21:27.858843 2026] [security2:error] [pid 11201:tid 11201] [client 34.158.238.120:50142] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "balivisaservice.com"] [uri "/.git/config"] [unique_id "aqql5wcQSXF2tiRrI8mXlwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
todix
2026-09-16 13:41:26
(8 hours ago)
Web App Attack Exploid from 34.158.238.120
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 13:37:37
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.158.238.120 (120.238.158.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.158.238.120 (120.238.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 09:37:34.171285 2026] [security2:error] [pid 21173:tid 21173] [client 34.158.238.120:56278] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "baldventure.com.tomthomasplumbing.com"] [uri "/.git/config"] [unique_id "aqqbnoC1BbJh6DMWY4UAsAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-09-16 13:30:04
(8 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-09-16 13:25:54
(8 hours ago)
[Wed Sep 16 23:25:53.389967 2026] [security2:error] [pid 389169] [client 34.158.238.120:38798] [clie ...
show more
[Wed Sep 16 23:25:53.389967 2026] [security2:error] [pid 389169] [client 34.158.238.120:38798] [client 34.158.238.120] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "balcomberetreat.com.au"] [uri "/"] [unique_id "aqqY4W0AUqFfLGLcyYQhxwAAAAk"]
...
show less
Web App Attack
๐ง๐ท
dominioz
2026-09-16 13:21:37
(8 hours ago)
2026-09-16 13:20:40 GET /.env - - 34.158.238.120 HTTP/1.1 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKi ...
show more
2026-09-16 13:20:40 GET /.env - - 34.158.238.120 HTTP/1.1 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/131.0.0.0+Safari/537.36 - 404 5124
2026-09-16 13:20:41 GET /.env.local - - 34.158.238.120 HTTP/1.1 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/131.0.0.0+Safari/537.36 - 404 5136
2026-09-16 13:20:41 GET /.env.production - - 34.158.238.120 HTTP/1.1 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/131.0.0.0+Safari/537.36 - 404 5146
2026-09-16 13:20:43 GET /.env.staging - - 34.158.238.120 HTTP/1.1 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/131.0.0.0+Safari/537.36 - 404 5140
2026-09-16 13:20:43 GET /.env.development - - 34.158.238.120 HTTP/1.1 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/131.0.0.0+Safari/537.36 - 404 5148
2026-09-16 13:20:45 GET /.env.test - - 34.158.238.120 HTTP/1.1 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/5
...
show less
Web App Attack
Anonymous
2026-09-16 12:38:54
(9 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐ซ๐ท
largo-it.net
2026-09-09 08:55:44
(1 week ago)
[09/Sep/2026:10:55:43.500] HTTP 404 - GET /.env.local
[09/Sep/2026:10:55:43.542] HTTP 404 - GET /.en ...
show more
[09/Sep/2026:10:55:43.500] HTTP 404 - GET /.env.local
[09/Sep/2026:10:55:43.542] HTTP 404 - GET /.env.production
[09/Sep/2026:10:55:43.569] HTTP 404 - GET /.env.staging
[09/Sep/2026:10:55:43.595] HTTP 404 - GET /.env.development
[09/Sep/2026:10:55:43.621] HTTP 404 - GET /.env.test
[09/Sep/2026:10:55:43.648] HTTP 404 - GET /.env.remote
[09/Sep/2026:10:55:43.678] HTTP 404 - GET /.env.bak
[09/Sep/2026:10:55:43.705] HTTP 404 - GET /.env.backup
show less
Hacking
Bad Web Bot
Web App Attack