๐ซ๐ท
Octopuce
2026-08-31 05:48:17
(1 day ago)
Aggressive web search of vulnerable pages: /.env /.env.local /app/.env /apps/.env /api/.env ...
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 05:44:37
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.50.93.154 (154.93.50.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.50.93.154 (154.93.50.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 01:44:31.605145 2026] [security2:error] [pid 6696:tid 6696] [client 34.50.93.154:51966] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "photonmatrix.com"] [uri "/.git/config"] [unique_id "apUUvx3f4PTr_TAvQYZlwwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 05:28:13
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.50.93.154 (154.93.50.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.50.93.154 (154.93.50.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 01:28:09.020268 2026] [security2:error] [pid 28978:tid 28978] [client 34.50.93.154:58762] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "photokarine.com"] [uri "/.git/config"] [unique_id "apUQ6VrEcJe1RGg6VWx2EgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
PHAM
2026-08-31 04:58:11
(1 day ago)
Shield Guard: RFI/LFI dans 'POST:0' | Command Injection dans 'POST:0'
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-08-31 04:33:33
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.50.93.154 (154.93.50.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.50.93.154 (154.93.50.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 00:33:26.829932 2026] [security2:error] [pid 5823:tid 5823] [client 34.50.93.154:46572] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "photoboothtogo.com"] [uri "/.git/config"] [unique_id "apUEFq7CI68pM0ght7uZmQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-08-31 04:29:42
(1 day ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.git/config (+1 more) | 2026-08-31 04:29 UTC
show less
Hacking
Web App Attack
Anonymous
2026-08-30 21:09:31
(1 day ago)
Apache vulnerability scan
Brute-Force
Web App Attack
๐บ๐ธ
Rocky Mountain Bioengineering Symposium
2026-08-30 19:21:23
(1 day ago)
[Sun Aug 30 13:21:18.014516 2026] [authz_core:error] [pid 38907:tid 140669054064192] [client 34.50.9 ...
show more
[Sun Aug 30 13:21:18.014516 2026] [authz_core:error] [pid 38907:tid 140669054064192] [client 34.50.93.154:40756] AH01630: client denied by server configuration: /var/www/horde/.env.bak
[Sun Aug 30 13:21:22.887865 2026] [authz_core:error] [pid 38907:tid 140668475262528] [client 34.50.93.154:40756] AH01630: client denied by server configuration: /var/www/horde/.env.dist
[Sun Aug 30 13:21:23.115277 2026] [authz_core:error] [pid 38907:tid 140670135408192] [client 34.50.93.154:40756] AH01630: client denied by server configuration: /var/www/horde/.env.swp
...
show less
Bad Web Bot
๐ซ๐ท
Zundapper
2026-08-30 17:24:33
(1 day ago)
34.50.93.154 - - [30/Aug/2026:19:23:54 +0200] "GET /config/.env HTTP/1.1" 404 548 "-" "Mozilla/5.0 ( ...
show more
34.50.93.154 - - [30/Aug/2026:19:23:54 +0200] "GET /config/.env HTTP/1.1" 404 548 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.50.93.154 - - [30/Aug/2026:19:24:12 +0200] "GET /vendor/.env HTTP/1.1" 404 548 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.50.93.154 - - [30/Aug/2026:19:24:14 +0200] "GET /bin/.env HTTP/1.1" 404 548 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.50.93.154 - - [30/Aug/2026:19:24:24 +0200] "GET /temp/.env HTTP/1.1" 404 548 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.50.93.154 - - [30/Aug/2026:19:24:32 +0200] "GET /logs/.env HTTP/1.1" 404 548 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/13
...
show less
Web App Attack
Port Scan
๐ณ๐ฑ
e.fierstra
2026-08-30 14:52:38
(2 days ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ฉ๐ช
Blexyel
2026-08-30 09:02:15
(2 days ago)
34.50.93.154 - - [30/Aug/2026:11:02:15 +0200] "GET /.git/config HTTP/1.1" 404 120 "-" "Mozilla/5.0 ( ...
show more
34.50.93.154 - - [30/Aug/2026:11:02:15 +0200] "GET /.git/config HTTP/1.1" 404 120 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Brute-Force
Web App Attack
๐ช๐ธ
alferez
2026-08-30 08:32:50
(2 days ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack
๐ณ๐ฑ
ConsulHosting
2026-08-30 07:29:27
(2 days ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
๐จ๐ญ
ca
2026-08-30 07:23:47
(2 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐ฎ๐น
VHosting
2026-08-30 06:45:04
(2 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack