🇮🇳
evicky2002
2026-09-13 06:00:01
(6 hours ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
🇩🇪
Nevermind
2026-09-13 02:55:37
(9 hours ago)
34.65.114.94 - - [13/Sep/2026:04:55:37 +0200] "GET /.git/config HTTP/1.1" 403 6233 "-" "Mozilla/5.0 ...
show more
34.65.114.94 - - [13/Sep/2026:04:55:37 +0200] "GET /.git/config HTTP/1.1" 403 6233 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.65.114.94 - - [13/Sep/2026:04:55:37 +0200] "GET /.env HTTP/1.1" 403 6233 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.65.114.94 - - [13/Sep/2026:04:55:37 +0200] "GET /.env.local HTTP/1.1" 403 6233 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.65.114.94 - - [13/Sep/2026:04:55:37 +0200] "GET /.env.production HTTP/1.1" 403 6233 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 01:33:44
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.65.114.94 (94.114.65.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.114.94 (94.114.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 21:33:38.490114 2026] [security2:error] [pid 29910:tid 29910] [client 34.65.114.94:42022] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "singleslidestrategy.com"] [uri "/.git/config"] [unique_id "aqX9cgXhe34_hqigOvOT6gAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
Sonoflet
2026-09-12 23:44:02
(12 hours ago)
CrowdSec detection | scenario: appsec-vpatch
Web App Attack
🇩🇪
Savvii
2026-09-12 20:38:09
(15 hours ago)
20 attempts against mh-misbehave-ban on train
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
ruusvuu
2026-09-12 20:22:34
(16 hours ago)
Automated abuse report: 15 attack/probe requests from Google LLC / CH.
Targeted paths: /.git/config, ...
show more
Automated abuse report: 15 attack/probe requests from Google LLC / CH.
Targeted paths: /.git/config, /.env, /.env.local, /.env.production, /.env.staging.
Sample log lines:
[signerauthority] 34.65.114.94 - - [12/Sep/2026:13:22:32 -0700] "GET /.env.sample HTTP/1.1" 404 2034 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome…
[signerauthority] 34.65.114.94 - - [12/Sep/2026:13:22:33 -0700] "GET /.env.example HTTP/1.1" 404 2035 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrom…
[signerauthority] 34.65.114.94 - - [12/Sep/2026:13:22:34 -0700] "GET /.env.dev HTTP/1.1" 404 2040 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/13…
Detected by an automated web-server log monitor.
show less
Web App Attack
🇳🇱
Site.eu
2026-09-12 18:45:14
(17 hours ago)
Excessive 404/403 errors
Brute-Force
🇳🇱
ConsulHosting
2026-09-12 18:40:36
(17 hours ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
🇺🇸
dot.mg
2026-09-12 14:46:02
(21 hours ago)
Bad behaviour
Web Spam
🇫🇮
mnazibo
2026-09-12 14:00:31
(22 hours ago)
Date: Sep 12 16:55:42 2026 EAT | Reported IP: 34.65.114.94 mod_security | id: 932130 932235 932260 9 ...
show more
Date: Sep 12 16:55:42 2026 EAT | Reported IP: 34.65.114.94 mod_security | id: 932130 932235 932260 933135 934100 934130 942151 942550 949110 930130 920440 920500 | CH/usernameab.my_domain/- | Connections: 1 | Blocked: Permanent Block: [LF_MODSEC] | Logs: ; Remote Command Execution: Unix Shell Expression Found; Remote Command Execution: Unix Shell Expression Found; Remote Command Execution: Unix Command Injection (command without evasion); Remote Command Execution: Unix Command Injection (command without evasion); Remote Command Execution: Direct Unix Command Execution; Remote Command Execution: Direct Unix Command Execution; PHP Injection Attack: Variable Access Found; PHP Injection Attack: Variable Access Found; Node.js Injection Attack 1/2; Node.js Injection Attack 1/2; Node.js Injection Attack 1/2; Node.js Injection Attack 1/2; Node.js Injection Attack 1/2; Node.js Injection Attack 1/2; Node.js Injection Attack 1/2; Node.js Injection
show less
SQL Injection
Brute-Force
Bad Web Bot
🇫🇷
dynamix
2026-09-12 13:44:30
(22 hours ago)
Multiple WAF Violations
Web App Attack
🇺🇸
CollideTech
2026-09-12 13:23:49
(23 hours ago)
probing for vulnerabilities
Web App Attack
🇮🇩
Burayot
2026-09-12 11:11:08
(1 day ago)
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 34.65.114.94 (CH/Switzerland/94.114. ...
show more
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 34.65.114.94 (CH/Switzerland/94.114.65.34.bc.googleusercontent.com): 2 in the last 3600 secs
show less
Web App Attack
🇬🇧
consul.to
2026-09-12 10:07:33
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
🇲🇾
Rizzy
2026-09-12 09:49:03
(1 day ago)
Multiple WAF Violations
Brute-Force
Web App Attack