π¬π§
relianoid.com
2026-09-01 11:38:37
(5 hours ago)
404 Errors Abuse detected by Relianoid OSS Load Balancer - relianoid.com
Web App Attack
ππΊ
DumaNet
2026-09-01 05:58:00
(11 hours ago)
Web app attack attempts, scanning for vulnerability.
Date: 2026 Aug 31. 06:46:27
Source IP: 34.20. ...
show more
Web app attack attempts, scanning for vulnerability.
Date: 2026 Aug 31. 06:46:27
Source IP: 34.20.204.253
Portion of the log(s):
34.20.204.253 - [31/Aug/2026:06:46:27 +0200] "GET /.env.example HTTP/1.1" 404 555 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.20.204.253 - [31/Aug/2026:06:46:27 +0200] "GET /.env.prod HTTP/1.1" 404 555 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.20.204.253 - [31/Aug/2026:06:46:27 +0200] "GET /.env.sample HTTP/1.1" 404 555 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.20.204.253 - [31/Aug/2026:06:46:26 +0200] "GET /.env.dev HTTP/1.1" 404 555 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.20.204.253 - [31/Aug/2026:06:46:26 +0200] "GET /.env.old HTTP/1.1" 404 555 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537
show less
Web App Attack
π©π°
ScamAware
2026-09-01 04:44:37
(12 hours ago)
Detected by Cloudflare Security Events via WordPress automation. Detection: sensitive_files (Sensiti ...
show more
Detected by Cloudflare Security Events via WordPress automation. Detection: sensitive_files (Sensitive files, source control, config, and backups). Hits from same IP in last 60 minutes: 32. Unique request paths counted internally: 32. Cloudflare action: block. Cloudflare source: firewallCustom.
show less
Web App Attack
π³π±
Site.eu
2026-09-01 04:37:28
(12 hours ago)
Excessive multi-domain requests
Brute-Force
π©πͺ
jocurionline
2026-09-01 01:30:07
(15 hours ago)
Auto-blocked by WAF: AUTO-BAN: Honeypot 1 h
Web App Attack
Port Scan
Anonymous
2026-09-01 01:07:55
(15 hours ago)
Trying to access config files
Web App Attack
π³π±
homeshowdomain.nl
2026-08-31 22:02:04
(18 hours ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-08-30.
show less
Web App Attack
SSH
Hacking
π³πΏ
Antinson
2026-08-31 12:21:33
(1 day ago)
Scraping with a high error ratio and request rate
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-08-31 09:37:51
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.20.204.253 (253.204.20.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.20.204.253 (253.204.20.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 05:37:47.353412 2026] [security2:error] [pid 22923:tid 22923] [client 34.20.204.253:33658] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "johnsshoehospital.com"] [uri "/.git/config"] [unique_id "apVLa1kZdg2QCe6HV7yzeAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πͺπΈ
masterguru
2026-08-31 09:16:26
(1 day ago)
Inbound Anomaly Score Exceeded (Total Score: 5). Operator GE matched 5 at TX:anomaly_score. (949110- ...
show more
Inbound Anomaly Score Exceeded (Total Score: 5). Operator GE matched 5 at TX:anomaly_score. (949110-122)
show less
Hacking
πΊπΈ
TPI-Abuse
2026-08-31 09:07:43
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.20.204.253 (253.204.20.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.20.204.253 (253.204.20.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 05:07:40.368058 2026] [security2:error] [pid 3316:tid 3316] [client 34.20.204.253:57806] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "johnrobinsonconsulting.com"] [uri "/.git/config"] [unique_id "apVEXP5Oveu1VsEg3hPFKwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
netclix.gr
2026-08-31 08:39:17
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted] 34.20.204.253 (US/United States/253.204 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.20.204.253 (US/United States/253.204.20.34.bc.googleusercontent.com): (CF_ENABLE)
show less
SQL Injection
πΊπΈ
TPI-Abuse
2026-08-31 08:39:10
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.20.204.253 (253.204.20.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.20.204.253 (253.204.20.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 04:39:05.566543 2026] [security2:error] [pid 25879:tid 25879] [client 34.20.204.253:33380] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "johnmorogiello.com"] [uri "/.git/config"] [unique_id "apU9qfcVR0BX3cNUP7fCCgAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-31 08:04:40
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.20.204.253 (253.204.20.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.20.204.253 (253.204.20.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 04:04:32.517564 2026] [security2:error] [pid 25526:tid 25526] [client 34.20.204.253:43776] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "johndidier.com"] [uri "/.git/config"] [unique_id "apU1kNcYgNYkPfkJOtE71AAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
WeCloudit-Anti-Abuse
2026-08-31 08:03:31
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking