|
๐บ๐ธ
mnsf
|
|
Scanning/Probing (20)
|
Brute-Force
Web App Attack
|
|
|
๐ฉ๐ช
raph
|
|
[DOT FILES] crawler *.env*, .git*, .config*, etc.
|
Bad Web Bot
Web App Attack
|
|
|
๐ณ๐ฑ
BlueWire Hosting
|
|
Probing websites for vulnerabilities
|
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 34.24.95.237 (237.95.24.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.24.95.237 (237.95.24.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:31:10.437381 2026] [security2:error] [pid 22570:tid 22570] [client 34.24.95.237:46744] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "smog-test.smogsandiego.com"] [uri "/.env"] [unique_id "apzQblicfTq5YxvBAnF2JwAAAEw"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐ฉ๐ช
IVski.com
|
|
IVski WAF | Sensitive file probe - looking for exposed .env and .git config
|
DDoS Attack
Bad Web Bot
|
|
|
๐ฉ๐ช
FD-IX
|
|
Fail2Ban: ModSecurity detected a web application attack.
|
Bad Web Bot
Web App Attack
|
|
|
๐ณ๐ฑ
WeCloudit-Anti-Abuse
|
|
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
|
Web App Attack
Hacking
|
|
|
๐ฉ๐ช
paissangroup
|
|
Multiple WAF Violations
|
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 34.24.95.237 (237.95.24.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.24.95.237 (237.95.24.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:47:52.522447 2026] [security2:error] [pid 21450:tid 21450] [client 34.24.95.237:57128] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "avrknives.com"] [uri "/.env"] [unique_id "apzGSJ9Eh7Io3uNvw75rLwAAAE0"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 34.24.95.237 (237.95.24.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.24.95.237 (237.95.24.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:48:02.439729 2026] [security2:error] [pid 18599:tid 18616] [client 34.24.95.237:52270] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.guitarprimer.com"] [uri "/.env.local"] [unique_id "apy4QrxU7PCtzj-QeSb1lgAAAI4"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐ณ๐ฑ
debestelapp
|
|
|
Web App Attack
|
|
|
๐จ๐ฆ
Bots.go.to.hell
|
|
This IP was detected by CrowdSec triggering crowdsecurity/vpatch-env-access
|
Web App Attack
Hacking
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 34.24.95.237 (237.95.24.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.24.95.237 (237.95.24.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:28:22.513193 2026] [security2:error] [pid 3505780:tid 3505916] [client 34.24.95.237:50718] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "m3sxa.com"] [uri "/wp-config.php.bak"] [unique_id "apyllqeVUu6W99IeSwEI4gAAAg8"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
wteiken
|
|
2026-09-05T19:03:26.722347-04:00 rocinante.teiken.net kernel: [542047.773653] syn_limit:IN=ens5 OUT= ...
show more
2026-09-05T19:03:26.722347-04:00 rocinante.teiken.net kernel: [542047.773653] syn_limit:IN=ens5 OUT= MAC=0a:ff:cf:a1:a5:bb:0a:f3:ae:05:2f:b7:08:00 SRC=34.24.95.237 DST=192.168.16.119 LEN=60 TOS=0x00 PREC=0x00 TTL=57 ID=18858 DF PROTO=TCP SPT=37906 DPT=443 WINDOW=65320 RES=0x00 SYN URGP=0
2026-09-05T19:03:26.728222-04:00 rocinante.teiken.net kernel: [542047.776834] syn_limit:IN=ens5 OUT= MAC=0a:ff:cf:a1:a5:bb:0a:f3:ae:05:2f:b7:08:00 SRC=34.24.95.237 DST=192.168.16.119 LEN=60 TOS=0x00 PREC=0x00 TTL=57 ID=11386 DF PROTO=TCP SPT=37936 DPT=443 WINDOW=65320 RES=0x00 SYN URGP=0
2026-09-05T19:03:26.728328-04:00 rocinante.teiken.net kernel: [542047.777011] syn_limit:IN=ens5 OUT= MAC=0a:ff:cf:a1:a5:bb:0a:f3:ae:05:2f:b7:08:00 SRC=34.24.95.237 DST=192.168.16.119 LEN=60 TOS=0x00 PREC=0x60 TTL=58 ID=63534 DF PROTO=TCP SPT=37922 DPT=443 WINDOW=65320 RES=0x00 SYN URGP=0
2026-09-05T19:03:26.728359-04:00 rocinante.teiken.net kernel: [542047.779480] syn_limit:IN=ens5 OUT= MAC=0a:ff:cf:a1:a5:bb:0a:f3:a
...
show less
|
Port Scan
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 34.24.95.237 (237.95.24.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.24.95.237 (237.95.24.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:57:53.056699 2026] [security2:error] [pid 13765:tid 13765] [client 34.24.95.237:56432] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.ozkanturker.com"] [uri "/.env.local"] [unique_id "apyecf12Kh78D9YXuctvAgAAAEM"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|