🇬🇧
gurnip
2026-09-07 10:13:41
(10 hours ago)
Vulnerability probe of page /backup.sql, not found on server.
Brute-Force
Web App Attack
🇩🇪
Skyrider
2026-09-07 07:14:35
(13 hours ago)
crowdsecurity/http-sensitive-files
Web App Attack
🇺🇸
zcampbell
2026-09-06 14:27:57
(1 day ago)
Web vulnerability scanning: probing for exposed sensitive files (secrets.yml). Detected and blocked ...
show more
Web vulnerability scanning: probing for exposed sensitive files (secrets.yml). Detected and blocked automatically.
show less
Web App Attack
Bad Web Bot
🇩🇪
ghostwarriors
2026-09-06 06:50:04
(1 day ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 04:14:16
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.173.11.32 (32.11.173.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.173.11.32 (32.11.173.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 00:14:10.799388 2026] [security2:error] [pid 11934:tid 11951] [client 34.173.11.32:52978] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||californiaplasticsurgeon.com.aafm.us|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "californiaplasticsurgeon.com.aafm.us"] [uri "/database.sql"] [unique_id "apzokikz-efFYVN710PuuwAAAI8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:53:16
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.173.11.32 (32.11.173.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.173.11.32 (32.11.173.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:53:10.338057 2026] [security2:error] [pid 31414:tid 31414] [client 34.173.11.32:42340] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.consorciolegal.com"] [uri "/.env.bak"] [unique_id "apzjptlAdbCOnMRor4iiCwAAAHM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:26:58
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.173.11.32 (32.11.173.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.173.11.32 (32.11.173.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:26:51.819607 2026] [security2:error] [pid 11498:tid 11513] [client 34.173.11.32:39810] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cas.bestofthis.com"] [uri "/wp-config.php.swp"] [unique_id "apzdez1yipf3j8T44v8hdQAAAIQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:57:51
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.173.11.32 (32.11.173.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.173.11.32 (32.11.173.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:57:43.898999 2026] [security2:error] [pid 30339:tid 30339] [client 34.173.11.32:48242] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.itony.com"] [uri "/wp-config.php.bak"] [unique_id "apzWpxSCausGG76ZlzT_PwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
BlueWire Hosting
2026-09-06 02:27:58
(1 day ago)
Probing websites for vulnerabilities
Web App Attack
Anonymous
2026-09-06 02:27:49
(1 day ago)
[da.kdns.gr] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/.env.production | /.env.sav ...
show more
[da.kdns.gr] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/.env.production | /.env.save | /actuator/env
show less
Hacking
Web App Attack
Anonymous
2026-09-06 01:16:19
(1 day ago)
Multiple web server 400 error codes from same source ip
Web App Attack
🇩🇪
bluematrix
2026-09-06 00:52:27
(1 day ago)
crowdsecurity/http-sensitive-files - Ip 34.173.11.32 performed 'crowdsecurity/http-sensitive-files' ...
show more
crowdsecurity/http-sensitive-files - Ip 34.173.11.32 performed 'crowdsecurity/http-sensitive-files' (5 events over 7.816676ms) at 2026-09-06 00:52:27.573897185 +0000 UTC
show less
Port Scan
Hacking
Brute-Force
Web App Attack
🇷🇺
DZBOT
2026-09-06 00:33:25
(1 day ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
🇬🇧
consul.to
2026-09-06 00:28:03
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
Anonymous
2026-09-06 00:20:53
(1 day ago)
34.173.11.32 - - [06/Sep/2026:02:20:52 +0200] "GET /storage/logs/laravel.log HTTP/1.1" 404 146 "-" " ...
show more
34.173.11.32 - - [06/Sep/2026:02:20:52 +0200] "GET /storage/logs/laravel.log HTTP/1.1" 404 146 "-" "crusader-worker/1.0" "-"
34.173.11.32 - - [06/Sep/2026:02:20:52 +0200] "GET /.env.backup HTTP/1.1" 404 146 "-" "crusader-worker/1.0" "-"
34.173.11.32 - - [06/Sep/2026:02:20:52 +0200] "GET /.env.old HTTP/1.1" 404 146 "-" "crusader-worker/1.0" "-"
...
show less
Bad Web Bot
Web App Attack