πΊπΈ
TPI-Abuse
2026-09-16 05:41:58
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.176.134.66 (66.134.176.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.176.134.66 (66.134.176.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 01:41:52.989723 2026] [security2:error] [pid 15387:tid 15387] [client 34.176.134.66:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nyemdr.org"] [uri "/.git/config"] [unique_id "aqosIFXfAGHuFfVLA1YHHgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
dynamix
2026-09-16 02:04:58
(23 hours ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-09-15 15:39:02
(1 day ago)
Bot / scanning and/or hacking attempts: GET /.env.docker HTTP/1.1, GET /.env.prod HTTP/1.1, GET /.en ...
show more
Bot / scanning and/or hacking attempts: GET /.env.docker HTTP/1.1, GET /.env.prod HTTP/1.1, GET /.env.dev HTTP/1.1, GET /.env.dist HTTP/1.1, GET /.env.old HTTP/1.1, GET /.env.example HTTP/1.1, GET /.git/config HTTP/1.1, GET /.env.live HTTP/1.1, GET /api/.env HTTP/1.1, GET /.env.preprod HTTP/1.1, GET /.env.ci HTTP/1.1, GET /.env.swp HTTP/1.1, GET /apps/.env HTTP/1.1, GET /.env.stage HTTP/1.1, GET /.env.test HTTP/1.1, GET /.env.uat HTTP/1.1, GET /.env~ HTTP/1.1, GET /app/.env HTTP/1.1, GET /.env.sample HTTP/1.1
show less
Hacking
Web App Attack
π³π±
Alt255
2026-09-15 13:44:43
(1 day ago)
[ti-11al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-11al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.176.134.66 - - [15/Sep/2026:15:44:31 +0200] "GET /.git/config HTTP/1.1" 404 6898 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
π©πͺ
LRob
2026-09-15 12:11:41
(1 day ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.git/config | 2026-09-15 12:11 UTC
show less
Hacking
Web App Attack
π³πΏ
Antinson
2026-09-15 09:06:54
(1 day ago)
Scraping with a high error ratio and request rate
Bad Web Bot
Anonymous
2026-09-15 08:59:14
(1 day ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
Anonymous
2026-09-15 07:59:41
(1 day ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
π©πͺ
sigurg
2026-09-15 04:27:01
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
π©πͺ
ghostwarriors
2026-09-15 03:50:09
(1 day ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
πΊπ¦
MakselPr
2026-09-15 03:41:23
(1 day ago)
2026/09/15 06:41:21 [error] 1915790#1915790: *258010 open() "/var/www/virtual/mta-sts.pretcher.dp.ua ...
show more
2026/09/15 06:41:21 [error] 1915790#1915790: *258010 open() "/var/www/virtual/mta-sts.pretcher.dp.ua/mailer/.env" failed (2: No such file or directory), client: 34.176.134.66, server: mta-sts.pretcher.dp.ua, request: "GET /mailer/.env HTTP/1.1", host: "mta-sts.pretcher.dp.ua"
2026/09/15 06:41:22 [error] 1915790#1915790: *258010 open() "/var/www/virtual/mta-sts.pretcher.dp.ua/mail/.env" failed (2: No such file or directory), client: 34.176.134.66, server: mta-sts.pretcher.dp.ua, request: "GET /mail/.env HTTP/1.1", host: "mta-sts.pretcher.dp.ua"
...
show less
Brute-Force
π©πͺ
yitzhaq
2026-09-15 03:34:03
(1 day ago)
34.176.134.66 - - [15/Sep/2026:05:34:00 +0200] "GET /.env.test HTTP/1.1" 303 616 "-" "Mozilla/5.0 (M ...
show more
34.176.134.66 - - [15/Sep/2026:05:34:00 +0200] "GET /.env.test HTTP/1.1" 303 616 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.176.134.66 - - [15/Sep/2026:05:34:01 +0200] "GET /.env.remote HTTP/1.1" 303 620 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.176.134.66 - - [15/Sep/2026:05:33:57 +0200] "GET /.env HTTP/1.1" 301 592 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.176.134.66 - - [15/Sep/2026:05:33:57 +0200] "GET /.env HTTP/1.1" 404 4501 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.176.134.66 - - [15/Sep/2026:05:33:58 +0200] "GET /.env.local HTTP/1.1" 301 603 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.
show less
Web App Attack
Hacking