๐น๐ผ
tye
2026-08-27 22:22:39
(6 hours ago)
Wazuh Alert Evidence: 34.63.23.240 (34.63.23.240) - - [28/Aug/2026:06:22:36 +0800] "GET /actuator/en ...
show more
Wazuh Alert Evidence: 34.63.23.240 (34.63.23.240) - - [28/Aug/2026:06:22:36 +0800] "GET /actuator/env HTTP/1.1" 404 5224 "-" "crusader-worker/1.0"
show less
Web App Attack
๐ง๐ช
sid3windr
2026-08-27 22:20:41
(6 hours ago)
GET /.env (Tarpitted for 4m20s, wasted 15.35kB)
Web App Attack
๐ฎ๐ช
AutosOnShow
2026-08-27 21:59:05
(7 hours ago)
blocked for webapp attack | path requested: / | seen at 2026-08-27 21:58:42.901 |
Web App Attack
๐ซ๐ท
dynamix
2026-08-27 19:56:24
(9 hours ago)
Multiple WAF Violations
Web App Attack
๐จ๐ณ
my meibu
2026-08-27 19:52:03
(9 hours ago)
[T-0084] Banned honeypot visitor: 34.63.23.240 path=/actuator/env
Web App Attack
Hacking
๐ซ๐ท
mail.avx.gr
2026-08-27 19:19:12
(9 hours ago)
(nginxENVSCAN) nginx environment-file scanner detected from 34.63.23.240 (US/United States/Iowa/Coun ...
show more
(nginxENVSCAN) nginx environment-file scanner detected from 34.63.23.240 (US/United States/Iowa/Council Bluffs/240.23.63.34.bc.googleusercontent.com)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-27 19:16:06
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.63.23.240 (240.23.63.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.63.23.240 (240.23.63.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 15:16:01.570515 2026] [security2:error] [pid 28734:tid 28734] [client 34.63.23.240:53904] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ruralroutes.ca"] [uri "/.env.dev"] [unique_id "apCM8bIIGIbeyJpTEAKA-QAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-08-27 19:05:02
(9 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 18:54:41
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.63.23.240 (240.23.63.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.63.23.240 (240.23.63.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 14:54:33.734683 2026] [security2:error] [pid 10452:tid 10452] [client 34.63.23.240:43540] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "maleein.com"] [uri "/.env.dev"] [unique_id "apCH6YiBsmf3jhR7Ol_TOAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
Anytech
2026-08-27 18:45:52
(10 hours ago)
Blocked by ConnMonitor
Web App Attack
๐ฉ๐ช
gadix
2026-08-27 18:32:09
(10 hours ago)
[27/Aug/2026:20:32:07.523453 +0200] apCCoj0uOXIrZQMvSXANOQAAAAI 34.63.23.240 38866 127.0.0.1 7081
[2 ...
show more
[27/Aug/2026:20:32:07.523453 +0200] apCCoj0uOXIrZQMvSXANOQAAAAI 34.63.23.240 38866 127.0.0.1 7081
[27/Aug/2026:20:32:07.742406 +0200] apCCoj0uOXIrZQMvSXANOgAAABE 34.63.23.240 38898 127.0.0.1 7081
[27/Aug/2026:20:32:07.928978 +0200] apCCoj0uOXIrZQMvSXANNgAAAA0 34.63.23.240 38832 127.0.0.1 7081
...
show less
Web App Attack
๐จ๐ญ
Ribeye375
2026-08-27 18:11:38
(10 hours ago)
HIPS web-exfiltration - Block tcp/0:65535
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 17:17:55
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.63.23.240 (240.23.63.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.63.23.240 (240.23.63.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 13:17:51.006773 2026] [security2:error] [pid 5103:tid 5103] [client 34.63.23.240:36340] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.clipper1970.com.jimgrenier.com"] [uri "/.env"] [unique_id "apBxPwUo7h60WcMNt-eCxQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-08-27 17:05:54
(11 hours ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 16:57:15
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.63.23.240 (240.23.63.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.63.23.240 (240.23.63.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 12:57:08.617082 2026] [security2:error] [pid 1621:tid 1621] [client 34.63.23.240:36388] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "duermaseaprisa.com"] [uri "/.env.dev"] [unique_id "apBsZEAxb91gDG_aro2gBAAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack