Anonymous
2026-09-03 16:11:48
(1 hour ago)
Aggressive web scan
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-03 13:28:50
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.165.183.171 (171.183.165.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.165.183.171 (171.183.165.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 09:28:42.431504 2026] [security2:error] [pid 17480:tid 17480] [client 34.165.183.171:53574] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "coyotebytes.net"] [uri "/.git/config"] [unique_id "apl2ChZcdGVCW5zUqPaiCAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-03 12:25:01
(5 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐บ๐ธ
paulo.apoloni
2026-09-03 11:59:48
(5 hours ago)
34.165.183.171 - - [03/Sep/2026:08:59:47 -0300] "GET /.env.local HTTP/1.1" 404 22 "-" "Mozilla/5.0 ( ...
show more
34.165.183.171 - - [03/Sep/2026:08:59:47 -0300] "GET /.env.local HTTP/1.1" 404 22 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.165.183.171 - - [03/Sep/2026:08:59:47 -0300] "GET /.env.production HTTP/1.1" 404 22 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.165.183.171 - - [03/Sep/2026:08:59:47 -0300] "GET /.env.staging HTTP/1.1" 404 22 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.165.183.171 - - [03/Sep/2026:08:59:47 -0300] "GET /.env.development HTTP/1.1" 404 22 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.165.183.171 - - [03/Sep/2026:08:59:47 -0300] "GET /.env.test HTTP/1.1" 404 22 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Web App Attack
Anonymous
2026-09-03 08:42:12
(9 hours ago)
Bot / seems abusive / Apache connections: 21
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-03 08:36:28
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.165.183.171 (171.183.165.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.165.183.171 (171.183.165.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 04:36:20.411342 2026] [security2:error] [pid 31977:tid 31977] [client 34.165.183.171:48676] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.feaverslane.com"] [uri "/.git/config"] [unique_id "apkxhI9H7nLDV6ikSXYKfAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
WellSpring
2026-09-03 06:40:35
(11 hours ago)
env leak on covenantcaptcha.org/admin/.env โ WellSpr.ing/NetSentinel civic-AI security layer
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-03 06:23:08
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.165.183.171 (171.183.165.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.165.183.171 (171.183.165.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 02:23:04.577438 2026] [security2:error] [pid 21833:tid 21833] [client 34.165.183.171:48354] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.fairfieldfarms.net"] [uri "/.git/config"] [unique_id "apkSSFxe1gZiM8yUhGwUEAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-03 04:24:38
(13 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐ฉ๐ช
LRob
2026-09-03 02:39:00
(15 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.git/config (+1 more) | 2026-09-03 02:39 UTC
show less
Hacking
Web App Attack
๐ฌ๐ง
[email protected]
2026-09-03 00:03:31
(17 hours ago)
34.165.183.171 - - [03/Sep/2026:00:03:30 +0000] "GET /.git/config HTTP/1.1" 403 335 "-" "Mozilla/5.0 ...
show more
34.165.183.171 - - [03/Sep/2026:00:03:30 +0000] "GET /.git/config HTTP/1.1" 403 335 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.165.183.171 - - [03/Sep/2026:00:03:30 +0000] "GET /.env HTTP/1.1" 404 332 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.165.183.171 - - [03/Sep/2026:00:03:31 +0000] "GET /.env.local HTTP/1.1" 404 332 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Web App Attack
Anonymous
2026-09-02 22:30:24
(19 hours ago)
2026/09/02 22:30:24 [error] 148875#148875: *915 open() "/var/www/monitor.bitfleet.com/mailer/.env" f ...
show more
2026/09/02 22:30:24 [error] 148875#148875: *915 open() "/var/www/monitor.bitfleet.com/mailer/.env" failed (2: No such file or directory), client: 34.165.183.171, server: monitor.bitfleet.com, request: "GET /mailer/.env HTTP/1.1", host: "course.kelasezaban.com"
2026/09/02 22:30:24 [error] 148875#148875: *915 open() "/var/www/monitor.bitfleet.com/mail/.env" failed (2: No such file or directory), client: 34.165.183.171, server: monitor.bitfleet.com, request: "GET /mail/.env HTTP/1.1", host: "course.kelasezaban.com"
2026/09/02 22:30:24 [error] 148875#148875: *915 open() "/var/www/monitor.bitfleet.com/mailing/.env" failed (2: No such file or directory), client: 34.165.183.171, server: monitor.bitfleet.com, request: "GET /mailing/.env HTTP/1.1", host: "course.kelasezaban.com"
...
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-02 22:15:20
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.165.183.171 (171.183.165.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.165.183.171 (171.183.165.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 18:15:14.594940 2026] [security2:error] [pid 16388:tid 16388] [client 34.165.183.171:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.empoweruamerica.org"] [uri "/.git/config"] [unique_id "apif8kymnhGYO9HqCHhiSAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-02 22:08:48
(19 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ณ๐ฑ
Site.eu
2026-09-02 21:42:59
(20 hours ago)
Excessive multi-domain requests
Brute-Force