๐ง๐ช
cmbplf
2026-09-27 10:28:28
(1 hour ago)
4.183 requests with url.path *.env
675 requests with url.path *phpinfo.php
Brute-Force
Bad Web Bot
๐ณ๐ฑ
Site.eu
2026-09-27 09:29:51
(2 hours ago)
Excessive multi-domain requests
Brute-Force
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-27 08:49:48
(3 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-26 20:21:51
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.61.106.5 (5.106.61.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.61.106.5 (5.106.61.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 16:21:44.357977 2026] [security2:error] [pid 1679:tid 1679] [client 34.61.106.5:60810] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.ajvaage.com"] [uri "/.git/config"] [unique_id "argpWIg7J7LyMb69btS9lgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-26 14:14:43
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.61.106.5 (5.106.61.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.61.106.5 (5.106.61.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 10:14:38.214969 2026] [security2:error] [pid 29147:tid 29147] [client 34.61.106.5:48936] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "asisecuresystems.com"] [uri "/.git/config"] [unique_id "arfTTsYma2I8IJMGfIoy2AAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
openstrike.co.uk
2026-09-26 05:15:25
(1 day ago)
250 attacks on PHP URLs, env grabbing URLs, VC URLs:
GET /includes/phpinfo.php HTTP/1.1
GET /config/ ...
show more
250 attacks on PHP URLs, env grabbing URLs, VC URLs:
GET /includes/phpinfo.php HTTP/1.1
GET /config/app/.env HTTP/1.1
GET /.git/config HTTP/1.1
show less
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-24 19:07:00
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.61.106.5 (5.106.61.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.61.106.5 (5.106.61.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 15:06:55.547568 2026] [security2:error] [pid 20831:tid 20831] [client 34.61.106.5:36362] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.california6.com.glassicannex.org"] [uri "/.git/config"] [unique_id "arV0z5Cq1fov_Pyr8DxuHQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
robotstxt
2026-09-24 05:25:07
(3 days ago)
34.61.106.5 - - [24/Sep/2026:05:24:12 +0000] "GET /.env HTTP/1.1" 403 15957 "-" "Mozilla/5.0 (Macint ...
show more
34.61.106.5 - - [24/Sep/2026:05:24:12 +0000] "GET /.env HTTP/1.1" 403 15957 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="34.61.106.5"
34.61.106.5 - - [24/Sep/2026:05:24:13 +0000] "GET /.env.local HTTP/1.1" 403 15957 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="34.61.106.5"
34.61.106.5 - - [24/Sep/2026:05:24:13 +0000] "GET /.env.production HTTP/1.1" 403 15957 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="34.61.106.5"
34.61.106.5 - - [24/Sep/2026:05:24:14 +0000] "GET /.env.staging HTTP/1.1" 403 15957 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="34.61.106.5"
34.61.106.5 - - [24/Sep/2026:05:24:15 +0000] "GET /.env.development HTTP/1.1" 403 1
...
show less
Web App Attack
๐ฌ๐ง
consul.to
2026-09-23 09:20:33
(4 days ago)
Web attack/malicious scanning detected
Web App Attack
๐ณ๐ฑ
maxxsense
2026-09-23 08:58:51
(4 days ago)
(mod_security) mod_security triggered on hostname [redacted] 34.61.106.5 (US/United States/5.106.61. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.61.106.5 (US/United States/5.106.61.34.bc.googleusercontent.com)
show less
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-09-22 09:48:43
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.61.106.5 (5.106.61.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.61.106.5 (5.106.61.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 05:48:35.715710 2026] [security2:error] [pid 10248:tid 10248] [client 34.61.106.5:40196] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vip.veneerdent.com"] [uri "/.git/config"] [unique_id "arJO8_1f8CP4V4QE_pgSPgAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-22 01:57:30
(5 days ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 18:55:28
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.61.106.5 (5.106.61.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.61.106.5 (5.106.61.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 14:55:23.720075 2026] [security2:error] [pid 2127:tid 2127] [client 34.61.106.5:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vidacellenlaweb.com"] [uri "/.git/config"] [unique_id "arF9m3y4ZDbmzt5Fg-u2MAAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
middelkoopcc
2026-09-21 18:03:01
(5 days ago)
2026-09-21 19:59:16 GET /.git/config [404] && 2026-09-21 19:59:17 GET /.env [404] && 2026-09-21 19:5 ...
show more
2026-09-21 19:59:16 GET /.git/config [404] && 2026-09-21 19:59:17 GET /.env [404] && 2026-09-21 19:59:25 GET /.env.bak [404] && 119 more within 20 minutes
show less
Web App Attack
Anonymous
2026-09-21 16:51:35
(5 days ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack