๐จ๐ญ
Cybercat
2026-09-22 16:26:47
(1 day ago)
CrowdSec detection: crowdsecurity/http-probing
Hacking
๐ฆ๐บ
Klaverstyn
2026-09-22 16:26:43
(1 day ago)
Excessive HTTP request rate
Web App Attack
Anonymous
2026-09-22 16:16:18
(1 day ago)
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 34.58.247.13 (13.247.58.34.bc.googleusercont ...
show more
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 34.58.247.13 (13.247.58.34.bc.googleusercontent.com): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.58.247.13 - - [22/Sep/2026:18:16:17 +0200] "GET /.env.old HTTP/1.1" 406 4830 "-" "crusader-worker/1.0"
34.58.247.13 - - [22/Sep/2026:18:16:17 +0200] "GET /.env.dev HTTP/1.1" 406 4831 "-" "crusader-worker/1.0"
34.58.247.13 - - [22/Sep/2026:18:16:17 +0200] "GET /.env HTTP/1.1" 406 4831 "-" "crusader-worker/1.0"
show less
Port Scan
๐ง๐ท
Peregrine
2026-09-22 16:06:31
(1 day ago)
Fail2Ban Jail: tomcat-honeypot | Evidence: 34.58.247.13 104.22.56.24 - - [22/Sep/2026:13:06:27 -0300 ...
show more
Fail2Ban Jail: tomcat-honeypot | Evidence: 34.58.247.13 104.22.56.24 - - [22/Sep/2026:13:06:27 -0300] "GET /.env.production HTTP/1.1" 404 414
34.58.247.13 172.68.71.141 - - [22/Sep/2026:13:06:27 -0300] "GET /.env.local HTTP/1.1" 404 414
34.58.247.13 104.22.1.168 - - [22/Sep/2026:13:06:27 -0300] "GET /.env.bak HTTP/1.1" 404 414
34.58.247.13 172.71.31.84 - - [22/Sep/2026:13:06:27 -0300] "GET /.env HTTP/1.1" 404 414
34.58.247.13 172.69.68.90 - - [22/Sep/2026:13:06:28 -0300] "GET /.env.old HTTP/1.1" 404 414
34.58.247.13 162.158.102.52 - - [22/Sep/2026:13:06:28 -0300] "GET /.env.save HTTP/1.1" 404 414
34.58.247.13 172.64.200.31 - - [22/Sep/2026:13:06:28 -0300] "GET /.env.backup HTTP/1.1" 404 414
34.58.247.13 172.69.155.62 - - [22/Sep/2026:13:06:28 -0300] "GET /.env.dev HTTP/1.1" 404 414
34.58.247.13 104.23.162.4 - - [22/Sep/2026:13:06:28 -0300] "GET /.env.example HTTP/1.1" 404 414
34.58.247.13 108.162.221.37 - - [22/Sep/2026:13:06:28 -0300] "GET /.env.prod HTTP/1.1" 404 414
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-22 15:43:27
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.58.247.13 (13.247.58.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.58.247.13 (13.247.58.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 11:43:19.365351 2026] [security2:error] [pid 20569:tid 20578] [client 34.58.247.13:59068] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nwnative.us"] [uri "/.env.bak"] [unique_id "arKiF32-urp3z1s4pLe3UAAAAIc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐บ
Albram
2026-09-22 14:58:02
(1 day ago)
Tries find Web server vulnerability
...
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 14:57:49
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.58.247.13 (13.247.58.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.58.247.13 (13.247.58.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 10:57:44.029072 2026] [security2:error] [pid 448:tid 448] [client 34.58.247.13:36142] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.vsecuritysolutions.com"] [uri "/wp-config.php.bak"] [unique_id "arKXaDEUM48nemvhlHRLRwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 14:25:43
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.58.247.13 (13.247.58.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.58.247.13 (13.247.58.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 10:25:39.200521 2026] [security2:error] [pid 9394:tid 9394] [client 34.58.247.13:57564] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lakeviewbewdley.com"] [uri "/.env.save"] [unique_id "arKP45BmPd0MFUdB5Pd_wQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-22 13:52:39
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ณ๐ฑ
Alt255
2026-09-22 13:38:25
(1 day ago)
[ti-17al] Web exploit scanning: 3 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-17al] Web exploit scanning: 3 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.58.247.13 - - [22/Sep/2026:15:38:14 +0200] "GET /.env.prod HTTP/1.1" 301 6291 "-" "crusader-worker/1.0"
34.58.247.13 - - [22/Sep/2026:15:38:14 +0200] "GET /.env.example HTTP/1.1" 301 6291 "-" "crusader-worker/1.0"
34.58.247.13 - - [22/Sep/2026:15:38:14 +0200] "GET /.env.bak HTTP/1.1" 301 6291 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
Web App Attack
๐ณ๐ด
doofy
2026-09-22 13:38:16
(1 day ago)
[Tue Sep 22 15:38:15.483272 2026] [authz_core:error] [pid 1376944:tid 1376988] [client 34.58.247.13: ...
show more
[Tue Sep 22 15:38:15.483272 2026] [authz_core:error] [pid 1376944:tid 1376988] [client 34.58.247.13:37956] AH01630: client denied by server configuration: /www/hekser.net/.env.save
[Tue Sep 22 15:38:15.486222 2026] [authz_core:error] [pid 1376977:tid 1377029] [client 34.58.247.13:37872] AH01630: client denied by server configuration: /www/hekser.net/.env.backup
[Tue Sep 22 15:38:15.483238 2026] [authz_core:error] [pid 1376977:tid 1377043] [client 34.58.247.13:37822] AH01630: client denied by server configuration: /www/hekser.net/.env.prod
[Tue Sep 22 15:38:15.493260 2026] [authz_core:error] [pid 1376977:tid 1377028] [client 34.58.247.13:37902] AH01630: client denied by server configuration: /www/hekser.net/.env.bak
[Tue Sep 22 15:38:15.496373 2026] [authz_core:error] [pid 1376977:tid 1377023] [client 34.58.247.13:37838] AH01630: client denied by server configuration: /www/hekser.net/.env.dev
...
show less
Brute-Force
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-22 13:17:39
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐จ๐ฆ
polycoda
2026-09-22 12:19:38
(1 day ago)
AutoBlock: ๐ฏ Vulnerability Scanner (Non Decay-Based) - โ๏ธ Configuration File Access (Non Decay-Based ...
show more
AutoBlock: ๐ฏ Vulnerability Scanner (Non Decay-Based) - โ๏ธ Configuration File Access (Non Decay-Based)
show less
Hacking
Web App Attack
๐ฉ๐ช
rh24
2026-09-22 12:07:41
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted] 34.58.247.13 (US/United States/13.247.5 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.58.247.13 (US/United States/13.247.58.34.bc.googleusercontent.com): (CF_ENABLE)
show less
SQL Injection
Anonymous
2026-09-22 11:30:02
(1 day ago)
suspicious request in access.log
Web App Attack