Anonymous
2026-09-08 13:11:31
(9 hours ago)
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: DE, Attack patterns: Word ...
show more
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: DE, Attack patterns: WordPress scanning, Backup file probing, Cloud secrets probing
show less
Bad Web Bot
Web App Attack
🇩🇪
Roper123
2026-09-08 13:02:55
(9 hours ago)
Web exploits
Web App Attack
Anonymous
2026-09-08 10:59:36
(11 hours ago)
Scan for .env Files at 2026-09-08T10:59:36+00:00
Web App Attack
🇫🇷
Douglin
2026-09-08 10:38:06
(11 hours ago)
Detectado pelo CrowdSec: crowdsecurity/http-sensitive-files. Servidor de producao.
Brute-Force
SSH
🇩🇪
edena
2026-09-08 09:53:57
(12 hours ago)
34.179.172.235 - - [08/Sep/2026:11:53:56 +0200] "GET /.git/config HTTP/1.1" 403 380 "-" "Mozilla/5.0 ...
show more
34.179.172.235 - - [08/Sep/2026:11:53:56 +0200] "GET /.git/config HTTP/1.1" 403 380 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.179.172.235 - - [08/Sep/2026:11:53:56 +0200] "GET /.env HTTP/1.1" 403 380 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.179.172.235 - - [08/Sep/2026:11:53:56 +0200] "GET /.env.local HTTP/1.1" 403 380 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Web App Attack
Bad Web Bot
🇩🇪
MSC IT for Business GmbH
2026-09-08 08:40:04
(13 hours ago)
GASTO/CrowdSec: gasto/modsec-critical triggered (via crowdsec-agent, categories 15,21)
Hacking
Web App Attack
🇪🇸
Francisco Vallejo
2026-09-08 08:31:44
(13 hours ago)
[Tue Sep 08 10:31:43.533885 2026] [authz_core:error] [pid 2887595:tid 125406401263296] [client 34.17 ...
show more
[Tue Sep 08 10:31:43.533885 2026] [authz_core:error] [pid 2887595:tid 125406401263296] [client 34.179.172.235:39368] AH01630: client denied by server configuration: proxy:https://localhost:3000/
[Tue Sep 08 10:31:43.636077 2026] [authz_core:error] [pid 2887595:tid 125407047177920] [client 34.179.172.235:39368] AH01630: client denied by server configuration: proxy:https://localhost:3000/
[Tue Sep 08 10:31:43.687633 2026] [authz_core:error] [pid 2887595:tid 125405839214272] [client 34.179.172.235:39368] AH01630: client denied by server configuration: proxy:https://localhost:3000/
[Tue Sep 08 10:31:43.860516 2026] [authz_core:error] [pid 2887595:tid 125407030392512] [client 34.179.172.235:39368] AH01630: client denied by server configuration: proxy:https://localhost:3000/
[Tue Sep 08 10:31:44.148935 2026] [authz_core:error] [pid 2887595:tid 125405822428864] [client 34.179.172.235:39368] AH01630: client denied by server configuration: proxy:https://localhost:3000/.git/config
...
show less
Brute-Force
SSH
🇫🇮
mnazibo
2026-09-08 08:00:34
(14 hours ago)
Date: Sep 08 10:54:58 2026 EAT | Reported IP: 34.179.172.235 mod_security | id: 932130 932235 932260 ...
show more
Date: Sep 08 10:54:58 2026 EAT | Reported IP: 34.179.172.235 mod_security | id: 932130 932235 932260 933135 934100 934130 942151 942550 949110 930130 920440 920500 | DE/usernameab.my_domain/- | Connections: 1 | Blocked: Permanent Block: [LF_MODSEC] | Logs: ; Remote Command Execution: Unix Shell Expression Found; Remote Command Execution: Unix Command Injection (command without evasion); Remote Command Execution: Direct Unix Command Execution; PHP Injection Attack: Variable Access Found; Node.js Injection Attack 1/2; Node.js Injection Attack 1/2; Node.js Injection Attack 1/2; JavaScript Prototype Pollution; JavaScript Prototype Pollution; SQL Injection Attack: SQL function name detected; JSON-Based SQL Injection; Inbound Anomaly Score Exceeded (Total Score: 55); Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Ac
show less
SQL Injection
Brute-Force
Bad Web Bot
🇩🇪
dave
2026-09-08 07:11:35
(15 hours ago)
threat-feed-sync observed repeated abuse from this IP after local filtering. scenarios=crowdsecurity ...
show more
threat-feed-sync observed repeated abuse from this IP after local filtering. scenarios=crowdsecurity/appsec-vpatch,crowdsecurity/vpatch-CVE-2025-55182,crowdsecurity/vpatch-env-access,crowdsecurity/vpatch-git-config observed_by=1_hosts hit_count=83 first_seen=2026-09-08T07:11:19Z last_seen=2026-09-08T07:11:35Z
show less
Web App Attack
🇩🇪
Dominik Lysiak
2026-09-08 06:29:01
(16 hours ago)
34.179.172.235 - - [08/Sep/2026:08:29:00 +0200] "GET /.git/config HTTP/1.1" 302 57 "-" "Mozilla/5.0 ...
show more
34.179.172.235 - - [08/Sep/2026:08:29:00 +0200] "GET /.git/config HTTP/1.1" 302 57 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.179.172.235 - - [08/Sep/2026:08:29:00 +0200] "GET /.env HTTP/1.1" 302 48 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.179.172.235 - - [08/Sep/2026:08:29:00 +0200] "GET /.env.local HTTP/1.1" 302 54 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Web App Attack
🇨🇦
arsonist
2026-09-08 06:26:22
(16 hours ago)
This IP accessed the path /.git/config, which is banned. Powered by ListenCaddy
Bad Web Bot
Web App Attack
🇩🇪
Blexyel
2026-09-08 06:15:54
(16 hours ago)
34.179.172.235 - - [08/Sep/2026:08:15:53 +0200] "GET /.git/config HTTP/1.1" 302 57 "-" "Mozilla/5.0 ...
show more
34.179.172.235 - - [08/Sep/2026:08:15:53 +0200] "GET /.git/config HTTP/1.1" 302 57 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Brute-Force
Web App Attack
🇵🇱
Budyn
2026-09-08 05:52:56
(16 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: grafana.astropot.online | URI: /.git/config | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 05:50:46
(16 hours ago)
apache-auth
Brute-Force
Web App Attack
🇺🇸
[email protected]
2026-09-08 05:38:11
(16 hours ago)
CrowdSec ban: crowdsecurity/appsec-vpatch on unknown-host (duration 4h)
Web App Attack