🇧🇪
cmbplf
2026-09-13 13:47:35
(33 minutes ago)
17.267 requests with url.path *.env
2.232 requests with url.path *phpinfo.php
378 requests with u ...
show more
17.267 requests with url.path *.env
2.232 requests with url.path *phpinfo.php
378 requests with url.path *credentials.json
show less
Brute-Force
Bad Web Bot
🇳🇱
WeCloudit-Anti-Abuse
2026-09-13 13:10:30
(1 hour ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-13 00:16:18
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.165.47.131 (131.47.165.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.165.47.131 (131.47.165.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 20:16:13.140964 2026] [security2:error] [pid 3267:tid 3267] [client 34.165.47.131:44268] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.iconbizpromo.com"] [uri "/.git/config"] [unique_id "aqXrTb0gZG-XbON9EU_iQAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 22:02:35
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.165.47.131 (131.47.165.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.165.47.131 (131.47.165.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 18:02:29.115849 2026] [security2:error] [pid 3382:tid 3382] [client 34.165.47.131:53266] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.hvacs-aircon.com"] [uri "/.git/config"] [unique_id "aqXL9fnlZGype86yut-z5wAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 21:34:32
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.165.47.131 (131.47.165.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.165.47.131 (131.47.165.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 17:34:26.246354 2026] [security2:error] [pid 21096:tid 21113] [client 34.165.47.131:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.humanet.io"] [uri "/.git/config"] [unique_id "aqXFYhtqJ3n1K60M-QtW7QAAAE0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-09-12 10:15:03
(1 day ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇹🇷
ayayntr
2026-09-11 18:07:31
(1 day ago)
[Fri Sep 11 21:07:29.196629 2026] [proxy_fcgi:error] [pid 1573:tid 1743] [client 34.165.47.131:36122 ...
show more
[Fri Sep 11 21:07:29.196629 2026] [proxy_fcgi:error] [pid 1573:tid 1743] [client 34.165.47.131:36122] AH01071: Got error 'Primary script unknown'
[Fri Sep 11 21:07:29.295538 2026] [proxy_fcgi:error] [pid 1573:tid 1742] [client 34.165.47.131:36122] AH01071: Got error 'Primary script unknown'
[Fri Sep 11 21:07:29.414571 2026] [proxy_fcgi:error] [pid 1573:tid 1746] [client 34.165.47.131:36122] AH01071: Got error 'Primary script unknown'
[Fri Sep 11 21:07:29.508903 2026] [proxy_fcgi:error] [pid 1573:tid 1747] [client 34.165.47.131:36122] AH01071: Got error 'Primary script unknown'
[Fri Sep 11 21:07:29.604025 2026] [proxy_fcgi:error] [pid 1573:tid 1744] [client 34.165.47.131:36122] AH01071: Got error 'Primary script unknown'
...
show less
Brute-Force
SSH
🇺🇸
alecj.com
2026-09-11 17:35:23
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/appsec-vpatch
Web App Attack
🇩🇪
BlueWire Hosting
2026-09-11 17:31:55
(1 day ago)
High-confidence malicious configuration/VCS probe
Web App Attack
Anonymous
2026-09-11 17:07:54
(1 day ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
🇩🇪
FeG Deutschland
2026-09-11 17:00:00
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
🇮🇹
VHosting
2026-09-11 08:30:03
(2 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇦🇺
screwlooseit.com.au
2026-09-11 06:51:50
(2 days ago)
Blocked by CSF 13 firewall - Rule: config-dotfile
US/United States/131.47.165.34.bc.googleuserconten ...
show more
Blocked by CSF 13 firewall - Rule: config-dotfile
US/United States/131.47.165.34.bc.googleusercontent.com
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 05:25:11
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.165.47.131 (131.47.165.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.165.47.131 (131.47.165.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 01:25:07.331063 2026] [security2:error] [pid 2691:tid 2691] [client 34.165.47.131:35728] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.asiancommoditiescorporation.com"] [uri "/.git/config"] [unique_id "aqOQszCbiOVIjLYWlhEr9AAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 05:08:23
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.165.47.131 (131.47.165.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.165.47.131 (131.47.165.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 01:08:16.964312 2026] [security2:error] [pid 26989:tid 26989] [client 34.165.47.131:34442] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.asfmglobal.com"] [uri "/.git/config"] [unique_id "aqOMwOEhS61NoJ2uia6MiwAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack