Anonymous
2026-10-11 04:10:37
(1 hour ago)
34.186.39.179 - - [10/Oct/2026:23:10:36 -0500] "GET /.env.example HTTP/1.1" 403 199 "-" "Mozilla/5.0 ...
show more
34.186.39.179 - - [10/Oct/2026:23:10:36 -0500] "GET /.env.example HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)" 104.22.102.56
34.186.39.179 - - [10/Oct/2026:23:10:36 -0500] "GET /.env.bak HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1; +http://www.apple.com/go/applebot)" 104.22.102.55
34.186.39.179 - - [10/Oct/2026:23:10:36 -0500] "GET /.env.local HTTP/1.1" 403 199 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )" 104.22.102.55
34.186.39.179 - - [10/Oct/2026:23:10:36 -0500] "GET /.env.old HTTP/1.1" 403 199 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)" 104.22.102.56
34.186.39.179 - - [10/Oct/2026:23:10:36 -0500] "GET /.env.save HTTP/1.1" 403 199 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)" 104.22.102.56
34.1
...
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-11 03:49:42
(1 hour ago)
Detected by CrowdSec: crowdsecurity/http-sensitive-files
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-11 02:38:41
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.186.39.179 (179.39.186.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.186.39.179 (179.39.186.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 22:38:33.498567 2026] [security2:error] [pid 26100:tid 26100] [client 34.186.39.179:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||backend.grainavi.com|F|2"] [data ".grainavi.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "backend.grainavi.com"] [uri "/z9x8c7v6b5-debug-trigger-backend.grainavi.com"] [unique_id "asr2qQ2Xv7n0R7sCKhg0hQAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-11 00:30:57
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.186.39.179 (179.39.186.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.186.39.179 (179.39.186.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 20:30:48.605706 2026] [security2:error] [pid 9979:tid 9979] [client 34.186.39.179:54414] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "awarriorsprayerbook.kathrynmcbride.com"] [uri "/core/.env"] [unique_id "asrYuA_p5RtCcvxuNrzcwwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
raph
2026-10-11 00:20:56
(4 hours ago)
[LIB DIR] crawler /vendor/*, /node_modules/*, /laravel/*, etc.
Bad Web Bot
Web App Attack
Anonymous
2026-10-10 23:41:01
(5 hours ago)
XSS Attempt
Hacking
Anonymous
2026-10-10 23:17:54
(6 hours ago)
Detected by CrowdSec: crowdsecurity/http-path-traversal-probing
Web App Attack
๐ธ๐ฌ
Cloudkul Cloudkul
2026-10-10 23:00:24
(6 hours ago)
Attempted Brute Force on our application
Brute-Force
Web App Attack
๐บ๐ธ
MakoWish
2026-10-10 22:49:27
(6 hours ago)
Fuzzing for misconfigured web servers.
Hacking
Web App Attack
๐ฉ๐ช
XICTRON
2026-10-10 22:10:11
(7 hours ago)
ModSecurity rule violation detected by Fail2Ban
Web App Attack
Anonymous
2026-10-10 22:07:03
(7 hours ago)
Automated web scanner. Requested suspicious paths: /z9x8c7v6b5-debug-trigger-tigzig.com | /.vite/man ...
show more
Automated web scanner. Requested suspicious paths: /z9x8c7v6b5-debug-trigger-tigzig.com | /.vite/manifest.json | /build/manifest.json | /dist/manifest.json | /dist/.vite/manifest.json. UTC: 2026-10-10 21:32:45.
show less
Web App Attack
๐บ๐ธ
[email protected]
2026-10-10 21:43:48
(7 hours ago)
CrowdSec ban: crowdsecurity/http-crawl-non_statics (duration: 71h59m56s)
Web App Attack
Anonymous
2026-10-10 21:33:28
(7 hours ago)
Detected by CrowdSec: crowdsecurity/http-bad-user-agent
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-10 21:04:14
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.186.39.179 (179.39.186.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.186.39.179 (179.39.186.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 17:04:08.401386 2026] [security2:error] [pid 3319:tid 3329] [client 34.186.39.179:37304] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "oplconnect.com"] [uri "/.htpasswd"] [unique_id "asqoSNby65tWLq4J_4s54gAAAQY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
Origon
2026-10-10 20:46:54
(8 hours ago)
http-sensitive-files - IP: 34.186.39.179 - time="2026-10-10T22:46:53+02:00" level=info msg="(555f66 ...
show more
http-sensitive-files - IP: 34.186.39.179 - time="2026-10-10T22:46:53+02:00" level=info msg="(555f66b4f6a74558bc11e3f93469658es8App0Mcc0TKEeje/crowdsec) crowdsecurity/http-sensitive-files by ip 34.186.39.179 (US/396982) : 4h ban on Ip 34.186.39.179" module=db
show less
Web App Attack