π³π±
homeshowdomain.nl
2026-09-01 22:00:18
(1 day ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-08-31.
show less
Web App Attack
SSH
Hacking
πΊπΈ
TPI-Abuse
2026-09-01 14:05:42
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.34.150.99 (99.150.34.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.34.150.99 (99.150.34.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 10:05:37.909189 2026] [security2:error] [pid 21371:tid 21371] [client 34.34.150.99:41028] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.theblindmantylertx.com"] [uri "/.env.backup"] [unique_id "apbbsZ5TSJg56S0HcTOhgwAAAGM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
FeG Deutschland
2026-09-01 13:13:43
(2 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
π΅π±
Niko's Stuff
2026-09-01 13:02:51
(2 days ago)
Triggered crowdsecurity/http-sensitive-files. More information at: https://app.crowdsec.net/cti/34.3 ...
show more
Triggered crowdsecurity/http-sensitive-files. More information at: https://app.crowdsec.net/cti/34.34.150.99
show less
Web App Attack
Hacking
πΊπΈ
TPI-Abuse
2026-09-01 12:56:08
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.34.150.99 (99.150.34.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.34.150.99 (99.150.34.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 08:56:02.403455 2026] [security2:error] [pid 11013:tid 11013] [client 34.34.150.99:45326] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "primacomm.com"] [uri "/wp-config.php~"] [unique_id "apbLYvOahgrGvwdihOe88QAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 12:05:38
(2 days ago)
(mod_security) mod_security (id:949110) triggered by 34.34.150.99 (99.150.34.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:949110) triggered by 34.34.150.99 (99.150.34.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 08:05:30.233912 2026] [security2:error] [pid 21140:tid 21140] [client 34.34.150.99:51212] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "delcano.org"] [uri "/.env.bak"] [unique_id "apa_iiU4EvKMOPNddQ-pVwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΈπͺ
vaia.cloud
2026-09-01 12:00:04
(2 days ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 10:59:49
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.34.150.99 (99.150.34.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.34.150.99 (99.150.34.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 06:59:42.432816 2026] [security2:error] [pid 20922:tid 20922] [client 34.34.150.99:41830] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.derek-stites.com"] [uri "/.env.save"] [unique_id "apawHrJt6UmEx_ybR_TZRAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
todix
2026-09-01 10:57:43
(2 days ago)
WebAttack or semilar from 34.34.150.99
Web App Attack
π©πͺ
pscriptos
2026-09-01 10:56:43
(2 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
π·π΄
iulianh
2026-09-01 10:19:09
(2 days ago)
80,443
Brute-Force
SSH
π©πͺ
Gwyneth Llewelyn
2026-09-01 08:54:56
(2 days ago)
2026/09/01 09:54:42 [error] 380594#380594: *2038985 access forbidden by rule, client: 34.34.150.99, ...
show more
2026/09/01 09:54:42 [error] 380594#380594: *2038985 access forbidden by rule, client: 34.34.150.99, server: silvana-moreira-portfolio.zonadetestes.com, request: "GET /.env HTTP/2.0", host: "silvana-moreira-portfolio.zonadetestes.com"
34.34.150.99 - - [01/Sep/2026:09:54:42 +0100] "GET /.env HTTP/2.0" 403 1045 "-" "crusader-worker/1.0"
2026/09/01 09:54:53 [error] 380595#380595: *2038986 access forbidden by rule, client: 34.34.150.99, server: silvana-moreira-portfolio.zonadetestes.com, request: "GET //.env HTTP/2.0", host: "silvana-moreira-portfolio.zonadetestes.com"
show less
Brute-Force
Web App Attack
π¬π§
Apache
2026-09-01 08:25:02
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.34.150.99 (BE/Belgium/99.150.34.34.bc.google ...
show more
(mod_security) mod_security (id:210492) triggered by 34.34.150.99 (BE/Belgium/99.150.34.34.bc.googleusercontent.com): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
Anonymous
2026-09-01 08:23:27
(2 days ago)
SIEM ALERT AUTO REPORT
Email Spam
π―π΅
Valhalla
2026-09-01 08:15:09
(2 days ago)
/wp-config.php~
Hacking
Web App Attack