๐ซ๐ท
phoenix1jl96
2026-09-29 13:29:10
(3 hours ago)
2026/09/29 15:29:10 [error] 3302796#3302796: *351847 open() "/home/user-data/www/default/mailer/.env ...
show more
2026/09/29 15:29:10 [error] 3302796#3302796: *351847 open() "/home/user-data/www/default/mailer/.env" failed (2: No such file or directory), client: 34.24.88.238, server: mta-sts.lucasmaths.fr, request: "GET /mailer/.env HTTP/1.1", host: "mta-sts.lucasmaths.fr"
2026/09/29 15:29:10 [error] 3302796#3302796: *351847 open() "/usr/local/lib/roundcubemail/.env" failed (2: No such file or directory), client: 34.24.88.238, server: mta-sts.lucasmaths.fr, request: "GET /mail/.env HTTP/1.1", host: "mta-sts.lucasmaths.fr"
...
show less
DNS Compromise
DNS Poisoning
DDoS Attack
Ping of Death
Web Spam
Email Spam
Blog Spam
Port Scan
Hacking
Brute-Force
Bad Web Bot
SSH
Web App Attack
๐ฆ๐บ
Klaverstyn
2026-09-29 13:11:02
(4 hours ago)
Excessive HTTP request rate
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 00:42:18
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.24.88.238 (238.88.24.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.24.88.238 (238.88.24.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 20:42:12.322646 2026] [security2:error] [pid 19071:tid 19071] [client 34.24.88.238:35436] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.kelleysbridge.com"] [uri "/.git/config"] [unique_id "arsJZGdmvFdn_HX-wmQXZwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 00:14:08
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.24.88.238 (238.88.24.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.24.88.238 (238.88.24.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 20:14:03.572456 2026] [security2:error] [pid 20466:tid 20488] [client 34.24.88.238:36274] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.kellenlee.com"] [uri "/.git/config"] [unique_id "arsCy7HUxPNpJTn4foulpgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-28 03:06:14
(1 day ago)
Requested unexistent endpoint (Wordpress login, etc.)
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-27 05:28:30
(2 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ง๐ช
cmbplf
2026-09-27 05:00:55
(2 days ago)
9.373 4xx requests in 1 hour (3d17h41m)
Brute-Force
Bad Web Bot
Anonymous
2026-09-27 04:34:03
(2 days ago)
Bot / scanning and/or hacking attempts: GET / HTTP/1.1, GET /live/.env HTTP/1.1, GET /.env_copy HTTP ...
show more
Bot / scanning and/or hacking attempts: GET / HTTP/1.1, GET /live/.env HTTP/1.1, GET /.env_copy HTTP/1.1, GET /.env.json HTTP/1.1, GET /.env.yaml HTTP/1.1
show less
Hacking
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-26 21:52:15
(2 days ago)
[ti-01sc] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-01sc] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.24.88.238 - - [26/Sep/2026:23:52:02 +0200] "GET /.git/config HTTP/1.1" 301 560 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-26 09:46:01
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.24.88.238 (238.88.24.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.24.88.238 (238.88.24.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 05:45:53.913755 2026] [security2:error] [pid 14917:tid 14917] [client 34.24.88.238:49404] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "morleysales.com"] [uri "/.git/config"] [unique_id "areUUTqM7QUWGMtcjSN7OAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
konseptit
2026-09-26 07:33:05
(3 days ago)
(mod_security) mod_security triggered on hostname [redacted] 34.24.88.238 (US/United States/238.88.2 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.24.88.238 (US/United States/238.88.24.34.bc.googleusercontent.com)
show less
SQL Injection
๐ฉ๐ช
Gwyneth Llewelyn
2026-09-25 05:14:12
(4 days ago)
2026/09/25 06:14:04 [error] 325888#325888: *2045068 access forbidden by rule, client: 34.24.88.238, ...
show more
2026/09/25 06:14:04 [error] 325888#325888: *2045068 access forbidden by rule, client: 34.24.88.238, server: [redacted], request: "GET /.env HTTP/1.1", host: "mta-sts.[redacted]"
34.24.88.238 - - [25/Sep/2026:06:14:04 +0100] "GET /.env HTTP/1.1" 403 1178 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
2026/09/25 06:14:11 [error] 325888#325888: *2045068 access forbidden by rule, client: 34.24.88.238, server: [redacted], request: "GET /app/.env HTTP/1.1", host: "mta-sts.[redacted]"
show less
Brute-Force
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-09-25 04:50:04
(4 days ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐บ๐ธ
kosada.com
2026-09-25 04:49:39
(4 days ago)
Repeated exploit attempts, for example: /.env.staging /.env (HTTP/1.1 port 443, user agent: "Mozilla ...
show more
Repeated exploit attempts, for example: /.env.staging /.env (HTTP/1.1 port 443, user agent: "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36")
show less
Web App Attack
๐ฉ๐ช
yitzhaq
2026-09-25 04:31:40
(4 days ago)
34.24.88.238 - - [25/Sep/2026:06:31:37 +0200] "GET /.env.staging HTTP/1.1" 404 519 "-" "Mozilla/5.0 ...
show more
34.24.88.238 - - [25/Sep/2026:06:31:37 +0200] "GET /.env.staging HTTP/1.1" 404 519 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.24.88.238 - - [25/Sep/2026:06:31:37 +0200] "GET /.env.development HTTP/1.1" 404 519 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.24.88.238 - - [25/Sep/2026:06:31:37 +0200] "GET /.env.test HTTP/1.1" 404 519 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.24.88.238 - - [25/Sep/2026:06:31:37 +0200] "GET /.env.remote HTTP/1.1" 404 519 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.24.88.238 - - [25/Sep/2026:06:31:37 +0200] "GET /.env.bak HTTP/1.1" 404 519 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) C
show less
Web App Attack
Hacking