๐ฉ๐ช
Philister11
2026-09-22 01:27:36
(2 hours ago)
CrowdSec: crowdsecurity/http-crawl-non_statics (US/AS396982)
Bad Web Bot
Web App Attack
๐ฌ๐ง
andypiper
2026-09-22 01:01:01
(2 hours ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
๐ซ๐ท
masterguru
2026-09-22 00:38:53
(3 hours ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.169.40.215 (US/United States/215.4 ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.169.40.215 (US/United States/215.40.169.34.bc.googleusercontent.com): 1 in the last 3600 secs (0-195)
show less
Hacking
๐ช๐ธ
el-brujo
2026-09-22 00:24:16
(3 hours ago)
22/Sep/2026:02:24:15.715184 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
22/Sep/2026:02:24:15.715184 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 34.169.40.215] ModSecurity: Warning. Matched phrase "proc/self/environ" at ARGS:0. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "98"] [id "930120"] [msg "OS File Access Attempt"] [data "Matched Data: proc/self/environ found within ARGS:0: {\\\\x22then\\\\x22:\\\\x22$1:__proto__:then\\\\x22,\\\\x22status\\\\x22:\\\\x22resolved_model\\\\x22,\\\\x22reason\\\\x22:-1,\\\\x22value\\\\x22:\\\\x22{/\\\\x22then/\\\\x22:/\\\\x22$b1337/\\\\x22}\\\\x22,\\\\x22_response\\\\x22:{\\\\x22_prefix\\\\x22:\\\\x22process.mainmodule.require('child_process').execsync('env 2>/dev/null || cat /proc/self/environ 2>/dev/null');\\\\x22,\\\\x22_formdata\\\\x22:{\\\\x22get\\\\x22:\\\\x22$1:constructor:constructor\\\\x22}}}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 00:14:56
(3 hours ago)
(mod_security) mod_security (id:210580) triggered by 34.169.40.215 (215.40.169.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210580) triggered by 34.169.40.215 (215.40.169.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 20:14:48.441323 2026] [security2:error] [pid 11631:tid 11631] [client 34.169.40.215:48588] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at ARGS:vars[1][]. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||karenbernsteinlaw.net|F|2"] [data "Matched Data: proc/self/environ found within ARGS:vars[1][]: /proc/self/environ"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "karenbernsteinlaw.net"] [uri "/index.php"] [unique_id "arHIeMMnuK8uNdM7WiAp3AAAAFI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
sefinek.net
2026-09-21 23:58:44
(3 hours ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action: BLOCK | Protocol: HTTP/2 (GET) | Endpoint ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action: BLOCK | Protocol: HTTP/2 (GET) | Endpoint: /laravel/.env | UA: Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/) โข Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-21 22:18:30
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.169.40.215 (215.40.169.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.169.40.215 (215.40.169.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 18:18:26.494459 2026] [security2:error] [pid 29704:tid 29704] [client 34.169.40.215:57736] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "personalizedholidaycards.net"] [uri "/.git/config"] [unique_id "arGtMjpq-HRSumz2QJBwMwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 20:38:04
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.169.40.215 (215.40.169.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.169.40.215 (215.40.169.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 16:37:58.433687 2026] [security2:error] [pid 19497:tid 19497] [client 34.169.40.215:51422] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "peradotto.net"] [uri "/admin/.env"] [unique_id "arGVpq3zt3a6knmmSlrlKgAAAGY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
noise.agency
2026-09-21 20:06:07
(7 hours ago)
34.169.40.215 (US/United States/215.40.169.34.bc.googleusercontent.com), more than 10 Apache 403 hit ...
show more
34.169.40.215 (US/United States/215.40.169.34.bc.googleusercontent.com), more than 10 Apache 403 hits
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-21 19:57:19
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.169.40.215 (215.40.169.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.169.40.215 (215.40.169.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 15:57:12.433273 2026] [security2:error] [pid 16208:tid 16208] [client 34.169.40.215:47556] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.vccemail.net"] [uri "/.github/.env"] [unique_id "arGMGJJFlNvCMrQKJES9mAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
NotCool
2026-09-21 18:44:32
(9 hours ago)
(CRAWLDELAY) Generic Bot Crawl-delay Violation 34.169.40.215 (US/United States/215.40.169.34.bc.goog ...
show more
(CRAWLDELAY) Generic Bot Crawl-delay Violation 34.169.40.215 (US/United States/215.40.169.34.bc.googleusercontent.com): 50 in the last 3600 secs
show less
Bad Web Bot
๐ฉ๐ช
pscriptos
2026-09-21 18:24:52
(9 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ช๐ธ
el-brujo
2026-09-21 18:06:21
(9 hours ago)
21/Sep/2026:20:06:20.438982 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
21/Sep/2026:20:06:20.438982 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 34.169.40.215] ModSecurity: Warning. Pattern match "(?i)(?:\\\\\\\\x5c|(?:%(?:c(?:0%(?:[2aq]f|5c|9v)|1%(?:[19p]c|8s|af))|2(?:5(?:c(?:0%25af|1%259c)|2f|5c)|%46|f)|(?:(?:f(?:8%8)?0%8|e)0%80%a|bg%q)f|%3(?:2(?:%(?:%6|4)6|F)|5%%63)|u(?:221[56]|002f|EFC8|F025)|1u|5c)|0x(?:2f|5c)|\\\\\\\\/))(?:%(?:(?:f(?:(?:c%80|8)%8)?0%8 ..." at REQUEST_URI_RAW. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "48"] [id "930100"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /../ found within REQUEST_URI_RAW: /api/w/admins/jobs_u/get_log_file/../../../../proc/self/environ"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [hostname "grafana.elhacker.net"] [uri "/api/proc/self/environ"] [unique
...
show less
Hacking
Web App Attack
๐ฉ๐ช
Hagen Schoebel
2026-09-21 17:42:08
(10 hours ago)
Blocked by CrowdSec - crowdsecurity/http-sensitive-files (US)
Port Scan
Brute-Force
Web App Attack
SSH
๐ฆ๐บ
clapper
2026-09-21 16:39:23
(11 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.169.40.215 (US/United States/215.40.169.34.b ...
show more
(mod_security) mod_security (id:949110) triggered by 34.169.40.215 (US/United States/215.40.169.34.bc.googleusercontent.com): 3 in the last 3600 secs; ID: LUC
show less
Brute-Force
Bad Web Bot