🇨🇦
SoteriaCovenant
2026-09-07 01:39:07
(1 week ago)
Automated probe: /server-info.php on Soteria Global infrastructure. No vulnerable software present.
Hacking
Anonymous
2026-09-05 13:22:08
(1 week ago)
Bloqueado automaticamente por CrowdSec escenario crowdsecurity/http-sensitive-files
Brute-Force
Anonymous
2026-09-04 03:30:02
(1 week ago)
CrowdSec decision: crowdsecurity/http-probing (origin: crowdsec)
Web App Attack
🇺🇸
brightenfield
2026-09-04 01:43:15
(1 week ago)
Web App Attack
Web App Attack
🇦🇺
aranguren.org
2026-09-04 01:16:32
(1 week ago)
34.50.125.189 - - [04/Sep/2026:11:16:30 +1000] "GET /.env HTTP/1.1" 404 992 "-" "Mozilla/5.0 (Macint ...
show more
34.50.125.189 - - [04/Sep/2026:11:16:30 +1000] "GET /.env HTTP/1.1" 404 992 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.50.125.189 - - [04/Sep/2026:11:16:30 +1000] "GET /.env.local HTTP/1.1" 404 992 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.50.125.189 - - [04/Sep/2026:11:16:30 +1000] "GET /.env.production HTTP/1.1" 404 992 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.50.125.189 - - [04/Sep/2026:11:16:31 +1000] "GET /.env.staging HTTP/1.1" 404 992 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.50.125.189 - - [04/Sep/2026:11:16:31 +1000] "GET /.env.development HTTP/1.1" 404 992 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Ge
...
show less
Bad Web Bot
🇧🇪
cmbplf
2026-09-03 23:02:53
(1 week ago)
3.391 requests from abuseipdb.com blacklisted IP (1yr10mos3w)
Brute-Force
Bad Web Bot
🇳🇱
Site.eu
2026-09-03 19:57:49
(1 week ago)
Excessive multi-domain requests
Brute-Force
🇺🇸
TPI-Abuse
2026-09-03 14:17:30
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.50.125.189 (189.125.50.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.50.125.189 (189.125.50.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 10:17:26.191886 2026] [security2:error] [pid 31127:tid 31127] [client 34.50.125.189:42640] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "photo-craft.org"] [uri "/.git/config"] [unique_id "apmBdt3woffhqxS05PdztwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
AWW-Admin
2026-09-03 12:15:01
(1 week ago)
(mod_security) mod_security triggered on hostname [redacted] 34.50.125.189 (ID/Indonesia/189.125.50. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.50.125.189 (ID/Indonesia/189.125.50.34.bc.googleusercontent.com)
show less
SQL Injection
🇺🇸
TPI-Abuse
2026-09-03 12:12:03
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.50.125.189 (189.125.50.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.50.125.189 (189.125.50.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 08:11:55.686774 2026] [security2:error] [pid 3290:tid 3290] [client 34.50.125.189:54694] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "phoneresponse.com"] [uri "/.git/config"] [unique_id "aplkC5JjYdJgB9XQhJ4IswAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-03 07:52:50
(1 week ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
🇨🇦
SoteriaCovenant
2026-09-03 07:19:18
(1 week ago)
Automated probe: /server-info.php on Soteria Global infrastructure. No vulnerable software present.
Hacking
🇩🇪
Hazzard
2026-09-03 07:05:04
(1 week ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
Anonymous
2026-09-03 06:58:21
(1 week ago)
PSCSERV WPSCAN 34.50.125.189
Bad Web Bot
Web App Attack
🇩🇪
Blexyel
2026-09-03 06:08:38
(1 week ago)
34.50.125.189 - - [03/Sep/2026:08:08:38 +0200] "GET /.git/config HTTP/1.1" 200 265 "-" "Mozilla/5.0 ...
show more
34.50.125.189 - - [03/Sep/2026:08:08:38 +0200] "GET /.git/config HTTP/1.1" 200 265 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "pingusmc.org"
...
show less
Brute-Force
Web App Attack