๐บ๐ธ
kosada.com
2026-09-01 10:16:39
(5 hours ago)
Repeated requests for suspicious nonexistent URLs, for example: /.env.staging (HTTP port 443)
Web App Attack
๐ฉ๐ช
JLKnoch Software GmbH
2026-09-01 06:30:17
(9 hours ago)
CrowdSec crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
Anonymous
2026-09-01 02:42:22
(12 hours ago)
CrowdSec ban: crowdsecurity/http-sensitive-files
Port Scan
๐ฉ๐ช
Balthasar Morpheus Jรถrmundur (JKweb Service)
2026-09-01 02:20:15
(13 hours ago)
JKweb Security: Severe and dangerous web attack detected. Vulnerability Wordpress Scanning, Director ...
show more
JKweb Security: Severe and dangerous web attack detected. Vulnerability Wordpress Scanning, Directory Brute-Forcing / Content Discovery, Predictable Resource Location / Forced Browsing, Scan for administration and debugging interfaces of modern frameworks, Scan for Spring Boot Actuator Leaks, Scan for Cloud & Infrastructure Credentials, Scan for Database & Backup Dumps, Scan for IDE- und Editor-Configurations, Scan for CI/CD Pipelines & GitHub Workflows etc. The Attacker is permanently banned by Fail2Ban, configurate by JKweb Security a brand of JKweb Service.
show less
Port Scan
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-01 01:25:06
(14 hours ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
Anonymous
2026-09-01 01:07:03
(14 hours ago)
[da.kdns.gr] httpd-config-scan: sites=www.jkmedica.gr; logs=/var/log/httpd/domains/jkmedica.gr.log; ...
show more
[da.kdns.gr] httpd-config-scan: sites=www.jkmedica.gr; logs=/var/log/httpd/domains/jkmedica.gr.log; samples=/.git/config | /.env | /.env.local
show less
Hacking
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-01 01:05:52
(14 hours ago)
Excessive multi-domain requests
Brute-Force
๐ซ๐ท
Octopuce
2026-08-31 12:56:19
(1 day ago)
Aggressive web search of vulnerable pages: /.env /.env.local /app/.env /apps/.env /api/.env ...
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-08-31 12:50:10
(1 day ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 12:36:37
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.21.141.107 (107.141.21.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.21.141.107 (107.141.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 08:36:30.597493 2026] [security2:error] [pid 25377:tid 25377] [client 34.21.141.107:37888] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kajohn11.org"] [uri "/.git/config"] [unique_id "apV1TljvXmuiF2mrK4MqfQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
yitzhaq
2026-08-31 12:35:09
(1 day ago)
34.21.141.107 - - [31/Aug/2026:14:35:05 +0200] "GET /.env.production HTTP/1.1" 404 508 "-" "Mozilla/ ...
show more
34.21.141.107 - - [31/Aug/2026:14:35:05 +0200] "GET /.env.production HTTP/1.1" 404 508 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.21.141.107 - - [31/Aug/2026:14:35:05 +0200] "GET /.env.staging HTTP/1.1" 404 508 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.21.141.107 - - [31/Aug/2026:14:35:05 +0200] "GET /.env.development HTTP/1.1" 404 508 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.21.141.107 - - [31/Aug/2026:14:35:05 +0200] "GET /.env.test HTTP/1.1" 404 508 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.21.141.107 - - [31/Aug/2026:14:35:05 +0200] "GET /.env.remote HTTP/1.1" 404 508 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Sa
show less
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-31 12:01:46
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.21.141.107 (107.141.21.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.21.141.107 (107.141.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 08:01:38.337693 2026] [security2:error] [pid 17018:tid 17018] [client 34.21.141.107:48528] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kaiyadunn.com"] [uri "/.git/config"] [unique_id "apVtIhas7YYSGmdoLg3uuQAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 11:14:12
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.21.141.107 (107.141.21.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.21.141.107 (107.141.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 07:14:07.991132 2026] [security2:error] [pid 4673:tid 4673] [client 34.21.141.107:50440] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kairoslogammakmur.com"] [uri "/.git/config"] [unique_id "apVh_6NrWD4GxsAWzYRjFgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 09:46:07
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.21.141.107 (107.141.21.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.21.141.107 (107.141.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 05:46:00.374938 2026] [security2:error] [pid 14509:tid 14509] [client 34.21.141.107:54534] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kahnzollbeck.org"] [uri "/.git/config"] [unique_id "apVNWEQT3vf032jgpZMFrAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
bluematrix
2026-08-31 08:30:43
(1 day ago)
crowdsecurity/http-sensitive-files - Ip 34.21.141.107 performed 'crowdsecurity/http-sensitive-files' ...
show more
crowdsecurity/http-sensitive-files - Ip 34.21.141.107 performed 'crowdsecurity/http-sensitive-files' (5 events over 1.292448877s) at 2026-08-31 08:30:45.15810675 +0000 UTC
show less
Port Scan
Hacking
Brute-Force
Web App Attack