๐ซ๐ท
IRISIO
2026-09-07 10:29:32
(2 weeks ago)
scans/SQL injection/spam posts : 64 queries
Web App Attack
SQL Injection
๐ฆ๐บ
2000cn.com.au
2026-09-07 02:51:35
(2 weeks ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
deskpass.com
2026-09-07 01:43:29
(2 weeks ago)
GET /.env.php.bak
Web App Attack
๐ณ๐ฑ
ConsulHosting
2026-09-07 00:23:57
(2 weeks ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
๐ซ๐ท
Baking333
2026-09-06 21:26:42
(2 weeks ago)
[redacted] 34.31.46.52 - - [06/Sep/2026:22:26:39 +0100] "GET /.env HTTP/1.1" 302 1499 0/54529 "-" "M ...
show more
[redacted] 34.31.46.52 - - [06/Sep/2026:22:26:39 +0100] "GET /.env HTTP/1.1" 302 1499 0/54529 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ChatGPT-User/1.0; +https://[redacted]/bot)" [redacted] 34.31.46.52 - - [06/Sep/2026:22:26:40 +0100] "GET /.[redacted] HTTP/1.1" 302 6741 0/72247 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://[redacted]/perplexitybot)"
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-09-06 19:05:11
(2 weeks ago)
Abuse Detected (9)
Brute-Force
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-06 17:00:48
(2 weeks ago)
crowdsecurity/grafana-cve-2021-43798
Brute-Force
Web App Attack
๐ฉ๐ช
mondor.ro
2026-09-06 16:19:51
(2 weeks ago)
Cluster member 148.251.176.225 (DE/Germany/antares.webyouridea.ro) said, DENY 34.31.46.52, Reason:[( ...
show more
Cluster member 148.251.176.225 (DE/Germany/antares.webyouridea.ro) said, DENY 34.31.46.52, Reason:[(mod_security) mod_security (id:210730) triggered by 34.31.46.52 (US/United States/52.46.31.34.bc.googleusercontent.com): 3 in the last 3600 secs]; Ports: *; Direction: inout; Trigger: LF_CLUSTER; Logs:
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-09-06 16:02:28
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 34.31.46.52 (52.46.31.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.31.46.52 (52.46.31.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 12:02:24.039453 2026] [security2:error] [pid 18298:tid 18298] [client 34.31.46.52:48450] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.certifiedfarmersmarkets.org|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.certifiedfarmersmarkets.org"] [uri "/rclone.conf"] [unique_id "ap2OkGEyBr-sT8x3A_3UQwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Apache
2026-09-06 16:01:07
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.31.46.52 (US/United States/52.46.31.34.bc.go ...
show more
(mod_security) mod_security (id:210492) triggered by 34.31.46.52 (US/United States/52.46.31.34.bc.googleusercontent.com): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-09-06 15:00:09
(2 weeks ago)
Active Response: IP 34.31.46.52 Blocked via Firewall Drop. Threat Score: 0/10 (INFORMATIONAL). Repor ...
show more
Active Response: IP 34.31.46.52 Blocked via Firewall Drop. Threat Score: 0/10 (INFORMATIONAL). Reported by TangerangKota-CSIRT
show less
Hacking
Web App Attack
๐ง๐ท
Serra Threat Intelligence
2026-09-06 14:38:00
(2 weeks ago)
* classification: Malicious IPv4 โ Exploitation of Public-Facing Application
* attack_type: Automat ...
show more
* classification: Malicious IPv4 โ Exploitation of Public-Facing Application
* attack_type: Automated multi-vector exploitation
* first_seen: 2026-09-06 06:49:38 UTC
* last_seen: 2026-09-6 07:27:08 UTC
* requests: 658
* abuse_confidence: 100% (28 reports / 24 sources)
* mitigation: 441 WAF blocks + 217 managed challenges
* automation_indicators: High โ consistent timing, payload diversity, spoofed UA, multi-framework targeting:
* Secret & Cloud Credential Harvesting:
Exhaustive .env variations: /.env, /.env.local, /.env.production, /api/.env, /config/.env, /.env.bak
* Cloud & DevOps keys: /.aws/credentials, /.oci/config, /.oci/oci_api_key.pem, gcp-credentials.json, firebase-admin.json, /.docker/config.json
* Infrastructure-as-Code / Configs: docker-compose.yml, terraform.tfstate, serverless.yml, application.yml
* Path Traversal & Local File Inclusion (LFI / Vite SSR):
* Directory navigation: ../, ....//, ..%252f..., /userfiles?path=../../../../proc/self
show less
Bad Web Bot
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-06 14:10:42
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.31.46.52 (52.46.31.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.31.46.52 (52.46.31.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 10:10:39.276988 2026] [security2:error] [pid 11389:tid 11389] [client 34.31.46.52:39782] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rotorservice.com"] [uri "/api/fs/read"] [unique_id "ap10X7BZoKNWlOrWJKRcLwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
polycoda
2026-09-06 11:42:04
(2 weeks ago)
AutoBlock: ๐ก Port Scan (Non Decay-Based)
Port Scan
๐บ๐ธ
TPI-Abuse
2026-09-06 10:39:11
(2 weeks ago)
(mod_security) mod_security (id:210580) triggered by 34.31.46.52 (52.46.31.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210580) triggered by 34.31.46.52 (52.46.31.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 06:39:03.432925 2026] [security2:error] [pid 2377:tid 2377] [client 34.31.46.52:59556] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at ARGS:path. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||anytimesign.com|F|2"] [data "Matched Data: proc/self/environ found within ARGS:path: ../../../../proc/self/environ"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "anytimesign.com"] [uri "/userfiles"] [unique_id "ap1Cxwbc3aecdUfdBTW32wAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack