🇨🇦
zXero
2026-09-03 12:20:21
(22 minutes ago)
Fail2Ban automatic report - jail: web-exploit
Brute-Force
SSH
DDoS Attack
🇧🇬
Stoyko Stoykov
2026-09-03 04:37:06
(8 hours ago)
34.32.7.234 - - [03/Sep/2026:07:37:06 +0300] "GET /.env HTTP/1.1" 404 0 "-" "Mozilla/5.0 (Macintosh; ...
show more
34.32.7.234 - - [03/Sep/2026:07:37:06 +0300] "GET /.env HTTP/1.1" 404 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Hacking
Web App Attack
🇫🇷
sthoyer.de
2026-09-03 03:07:33
(9 hours ago)
34.32.7.234 - - [03/Sep/2026:05:07:31 +0200] "GET /.git/config HTTP/1.1" 302 495 "-" "Mozilla/5.0 (X ...
show more
34.32.7.234 - - [03/Sep/2026:05:07:31 +0200] "GET /.git/config HTTP/1.1" 302 495 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.32.7.234 - - [03/Sep/2026:05:07:31 +0200] "GET /.env HTTP/1.1" 302 495 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.32.7.234 - - [03/Sep/2026:05:07:31 +0200] "GET /.env.local HTTP/1.1" 302 495 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-03 02:15:31
(10 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇩🇪
Lino Project
2026-09-03 01:59:06
(10 hours ago)
CrowdSec abuse IP report (host SRV-2) Scenario: crowdsecurity/http-sensitive-files
Hacking
🇺🇸
superflea2828
2026-09-03 01:46:22
(10 hours ago)
34.32.7.234 - - [03/Sep/2026:01:46:20 +0000] "GET /.env HTTP/1.1" 404 559 "-" "Mozilla/5.0 (X11; Lin ...
show more
34.32.7.234 - - [03/Sep/2026:01:46:20 +0000] "GET /.env HTTP/1.1" 404 559 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Web App Attack
🇩🇪
FD-IX
2026-09-03 01:02:14
(11 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇺🇸
Starburst SysOp Team
2026-09-03 00:37:37
(12 hours ago)
Malware host detected by rbl.malware.expert. RBL lookup of 234.7.32.34.rbl.malware.expert succeeded ...
show more
Malware host detected by rbl.malware.expert. RBL lookup of 234.7.32.34.rbl.malware.expert succeeded at REMOTE_ADDR. (400010-mnz6-1)
show less
Hacking
🇺🇸
TPI-Abuse
2026-09-03 00:19:38
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.32.7.234 (234.7.32.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.32.7.234 (234.7.32.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 20:19:30.794568 2026] [security2:error] [pid 31779:tid 31779] [client 34.32.7.234:41190] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.stananddana.com"] [uri "/.git/config"] [unique_id "api9EuH_Yk6Bzxb14kdaoAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇵🇱
miriks
2026-09-02 23:59:40
(12 hours ago)
Automated scan detected: GET /.git/config — UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) Appl ...
show more
Automated scan detected: GET /.git/config — UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
show less
Port Scan
Web App Attack
Anonymous
2026-09-02 20:12:25
(16 hours ago)
Trapped by Fail2Ban: Too many login failures from 34.32.7.234
Brute-Force
Hacking
🇺🇸
TPI-Abuse
2026-09-02 17:20:05
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.32.7.234 (234.7.32.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.32.7.234 (234.7.32.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 13:19:58.212259 2026] [security2:error] [pid 24653:tid 24653] [client 34.32.7.234:53268] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.spidersbox.com"] [uri "/.git/config"] [unique_id "aphavm-c2jo77dOexxYELQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-02 15:07:57
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.32.7.234 (234.7.32.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.32.7.234 (234.7.32.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 11:07:52.377206 2026] [security2:error] [pid 8264:tid 8264] [client 34.32.7.234:46776] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.yun-san.com"] [uri "/.git/config"] [unique_id "apg7yPKTdq47Xy5ThGjpyQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-02 13:27:06
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.32.7.234 (234.7.32.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.32.7.234 (234.7.32.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 09:27:02.352961 2026] [security2:error] [pid 12328:tid 12328] [client 34.32.7.234:36740] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.yourpath.help"] [uri "/.git/config"] [unique_id "apgkJoiVX8-bCblrVv9b0QAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Hazzard
2026-09-02 13:15:24
(23 hours ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection