🇩🇪
raph
2026-09-05 23:06:53
(1 minute ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 22:59:11
(8 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.159.255.4 (4.255.159.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.159.255.4 (4.255.159.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:59:05.686652 2026] [security2:error] [pid 23698:tid 23698] [client 34.159.255.4:34888] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.hills-tax.com"] [uri "/.env.local"] [unique_id "apyeuRJ9zsJboVO592ScrgAAAHY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
pscriptos
2026-09-05 22:41:57
(26 minutes ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
ISPLtd
2026-09-05 21:42:20
(1 hour ago)
Sep 5 15:42:19 34.159.255.4 TCP SPT=48274 DPT=80 SYN
Sep 5 15:42:19 34.159.255.4 TCP SPT=48258 DPT ...
show more
Sep 5 15:42:19 34.159.255.4 TCP SPT=48274 DPT=80 SYN
Sep 5 15:42:19 34.159.255.4 TCP SPT=48258 DPT=80 SYN
Sep 5 15:42:19 34.159.255.4 TCP SPT=48276 DPT=80 SYN
...
show less
DDoS Attack
🇺🇸
TPI-Abuse
2026-09-05 21:28:55
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.159.255.4 (4.255.159.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.159.255.4 (4.255.159.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 17:28:48.836337 2026] [security2:error] [pid 15873:tid 15873] [client 34.159.255.4:34918] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "shop.aguasolar.com"] [uri "/.env.save"] [unique_id "apyJkIwdlMZhKa6eFjfaKQAAADE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
debestelapp
2026-09-05 20:40:11
(2 hours ago)
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 20:35:12
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.159.255.4 (4.255.159.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.159.255.4 (4.255.159.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 16:35:04.034192 2026] [security2:error] [pid 2919:tid 2936] [client 34.159.255.4:45262] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "velatorioslugo.soluciona.biz"] [uri "/.env.dev"] [unique_id "apx8-GfyfRzPytDxxPZzywAAAE8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-05 20:24:16
(2 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
🇳🇱
Savvii
2026-09-05 15:10:05
(7 hours ago)
20 attempts against mh-misbehave-ban on argon
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-05 07:41:11
(15 hours ago)
Multiple WAF Violations
Web App Attack
🇮🇹
VHosting
2026-09-02 23:40:03
(2 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇳🇱
homeshowdomain.nl
2026-09-02 22:02:29
(3 days ago)
Auto-ban: 512 malicious requests on 2026-09-01 (e.g., env/backup probes, brute-force, or error burst ...
show more
Auto-ban: 512 malicious requests on 2026-09-01 (e.g., env/backup probes, brute-force, or error bursts).
show less
Web App Attack
SSH
Hacking
🇺🇸
TPI-Abuse
2026-09-02 18:34:18
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 34.159.255.4 (4.255.159.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.159.255.4 (4.255.159.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 14:34:12.861068 2026] [security2:error] [pid 15687:tid 15687] [client 34.159.255.4:54304] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||alextra.org|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "alextra.org"] [uri "/access.log"] [unique_id "aphsJENd4xX3UbxJQLH5iwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-02 05:32:08
(3 days ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack