🇮🇳
evicky2002
2026-09-06 00:02:40
(56 minutes ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
🇩🇪
FeG Deutschland
2026-09-05 22:53:16
(2 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
🇦🇺
2000cn.com.au
2026-09-05 22:39:25
(2 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-05 22:12:26
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.186.154.89 (89.154.186.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.186.154.89 (89.154.186.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:12:20.112637 2026] [security2:error] [pid 9512:tid 9512] [client 34.186.154.89:37046] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.kristywernerauthor.com"] [uri "/public/.git/config"] [unique_id "apyTxD-3PVRaBkr6Gh7wZAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
homeshowdomain.nl
2026-09-05 21:59:59
(2 hours ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-04.
show less
Web App Attack
SSH
Hacking
🇫🇷
dynamix
2026-09-05 11:41:01
(13 hours ago)
Multiple WAF Violations
Web App Attack
🇧🇪
sid3windr
2026-09-05 07:07:33
(17 hours ago)
GET /.env (Tarpitted for 4m18s, wasted 15.23kB)
Web App Attack
🇬🇧
openstrike.co.uk
2026-09-05 05:13:57
(19 hours ago)
13 attacks on env grabbing URLs, PHP URLs:
GET /.env.old HTTP/1.1
GET /wp-config.php.swp HTTP/1.1
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 15:17:07
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.186.154.89 (89.154.186.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.186.154.89 (89.154.186.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:17:03.988581 2026] [security2:error] [pid 22289:tid 22392] [client 34.186.154.89:37612] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.aqutar.com"] [uri "/.env"] [unique_id "aprg7y1zfZ2w0ZSLw1wlfgAAAhA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:44:55
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.186.154.89 (89.154.186.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.186.154.89 (89.154.186.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:44:51.032785 2026] [security2:error] [pid 11012:tid 11012] [client 34.186.154.89:39934] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sandersgroundtest.ryanc.net"] [uri "/.env"] [unique_id "aprZY52Jck9BSAC8WsjUKQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-04 14:35:02
(1 day ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:09:03
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.186.154.89 (89.154.186.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.186.154.89 (89.154.186.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:08:59.326176 2026] [security2:error] [pid 3074852:tid 3074963] [client 34.186.154.89:51986] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.layoverlocations.com"] [uri "/.env.old"] [unique_id "aprQ-8EtaesxEZ02xUhDNAAAAM4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
filstal.org
2026-09-04 13:41:31
(1 day ago)
Web exploit or injection attempt blocked by ModSecurity WAF.
SQL Injection
Web App Attack
🇫🇷
Security_Whaller
2026-09-04 13:17:11
(1 day ago)
Malicious activity detected on Honeypot.
Brute-Force
Hacking
Web App Attack
Anonymous
2026-09-04 13:05:26
(1 day ago)
34.186.154.89 detected and blocked by apache-modsecurity after 1 try
Brute-Force