Anonymous
2026-09-21 00:51:03
(3 days ago)
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 34.32.105.42 (DE/Germany/42.105.32.34.bc.goo ...
show more
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 34.32.105.42 (DE/Germany/42.105.32.34.bc.googleusercontent.com): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.32.105.42 - - [21/Sep/2026:02:51:00 +0200] "GET /.env HTTP/1.1" 406 518 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.32.105.42 - - [21/Sep/2026:02:51:00 +0200] "GET /.env.local HTTP/1.1" 406 4886 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.32.105.42 - - [21/Sep/2026:02:51:00 +0200] "GET /.env.production HTTP/1.1" 406 4887 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
show less
Port Scan
๐บ๐ธ
abenage
2026-09-21 00:37:57
(3 days ago)
34.32.105.42 - - [20/Sep/2026:18:37:56 -0600] "GET /phpinfo.php HTTP/1.1" 404 564 "-" "Mozilla/5.0 ( ...
show more
34.32.105.42 - - [20/Sep/2026:18:37:56 -0600] "GET /phpinfo.php HTTP/1.1" 404 564 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-21 00:15:55
(3 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ท๐บ
DZBOT
2026-09-21 00:05:11
(3 days ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-20 23:33:03
(3 days ago)
[mx02al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Examp ...
show more
[mx02al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.32.105.42 - - [21/Sep/2026:01:33:02 +0200] "GET /.git/config HTTP/1.1" 404 1434 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 21:14:15
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.32.105.42 (42.105.32.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.32.105.42 (42.105.32.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 17:14:11.469197 2026] [security2:error] [pid 30639:tid 30639] [client 34.32.105.42:52744] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.bbrd.net"] [uri "/.git/config"] [unique_id "arBMo0vo4P0Ccy2YuZVz4gAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Aetherweb Ark
2026-09-20 20:49:45
(3 days ago)
(mod_security) mod_security (id:949110) triggered by 34.32.105.42 (DE/Germany/42.105.32.34.bc.google ...
show more
(mod_security) mod_security (id:949110) triggered by 34.32.105.42 (DE/Germany/42.105.32.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 20:25:52
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.32.105.42 (42.105.32.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.32.105.42 (42.105.32.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 16:25:45.959382 2026] [security2:error] [pid 6739:tid 6739] [client 34.32.105.42:36070] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.baumannarchitecture.com"] [uri "/.git/config"] [unique_id "arBBSS04J1nxJ4plqfBLcAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Little Iguana
2026-09-20 20:07:49
(3 days ago)
Attempt to hack Wordpress Login, XMLRPC or other login
Hacking
๐บ๐ธ
dot.mg
2026-09-20 19:55:59
(3 days ago)
Scan of vulnerable files
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 19:46:58
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.32.105.42 (42.105.32.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.32.105.42 (42.105.32.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 15:46:52.300746 2026] [security2:error] [pid 26797:tid 26797] [client 34.32.105.42:40990] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.basicsa.com"] [uri "/.git/config"] [unique_id "arA4LMFguzrZZnos6NcUxgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ญ๐บ
bcsaba
2026-09-20 17:31:00
(3 days ago)
Probing for .git:
34.32.105.42 - - - - [20/Sep/2026:19:30:56 +0200] "GET /.git/config HTTP/1.1" 400 ...
show more
Probing for .git:
34.32.105.42 - - - - [20/Sep/2026:19:30:56 +0200] "GET /.git/config HTTP/1.1" 400 632 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-"
show less
Web App Attack
๐ฉ๐ช
iNetWorker
2026-09-20 17:27:46
(3 days ago)
trolling for resource vulnerabilities
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 16:35:51
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.32.105.42 (42.105.32.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.32.105.42 (42.105.32.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 12:35:44.716422 2026] [security2:error] [pid 3066186:tid 3066186] [client 34.32.105.42:53756] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.baileylabovitz.com"] [uri "/.git/config"] [unique_id "arALYPNhjMont3cNQEZDAAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Hazzard
2026-09-20 16:03:04
(3 days ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection