๐จ๐ฆ
polycoda
2026-08-29 03:11:15
(1 hour ago)
AutoBlock: ๐ฏ Vulnerability Scanner (Non Decay-Based) - โ๏ธ Configuration File Access (Non Decay-Based ...
show more
AutoBlock: ๐ฏ Vulnerability Scanner (Non Decay-Based) - โ๏ธ Configuration File Access (Non Decay-Based) - โช๏ธ Excessive 30X Errors (Decay-Based)
show less
Hacking
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-08-29 01:47:40
(3 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐ฉ๐ช
Hazzard
2026-08-29 01:31:39
(3 hours ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
๐ฉ๐ช
maxpower
2026-08-29 01:26:07
(3 hours ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.67.24.114 (US/United States/114.24.67 ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.67.24.114 (US/United States/114.24.67.34.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.67.24.114 - - [29/Aug/2026:03:26:02 +0200] "GET /wp-config.php.bak HTTP/1.1" 200 11851 "-" "crusader-worker/1.0" "-" host=ramsesconsulting.com
show less
Port Scan
๐ซ๐ท
โจ
2026-08-29 00:53:09
(4 hours ago)
Domain : sql.hermanwald.com
Rule : env
2026-08-29 00:52:00 ***hidden-privacy*** GET /.env.bak - 443 ...
show more
Domain : sql.hermanwald.com
Rule : env
2026-08-29 00:52:00 ***hidden-privacy*** GET /.env.bak - 443 - 34.67.24.114 HTTP/1.1 crusader-worker/1.0 - sql.hermanwald.com 404 0 0 360 98 147 - -
show less
Hacking
SQL Injection
๐ฉ๐ช
maxpower
2026-08-29 00:43:41
(4 hours ago)
(nginx_hardened) REGOLA 3 - Nginx Hardening Triggered 34.67.24.114 (US/United States/114.24.67.34.bc ...
show more
(nginx_hardened) REGOLA 3 - Nginx Hardening Triggered 34.67.24.114 (US/United States/114.24.67.34.bc.googleusercontent.com): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 2026/08/29 02:43:38 [error] 1884171#1884171: *874096 access forbidden by rule, client: 34.67.24.114, server: lasfiziosapizzeria.it, request: "GET /wp-config.php.bak HTTP/1.1", host: "mail.lasfiziosapizzeria.it"
2026/08/29 02:43:38 [error] 1884170#1884170: *874098 access forbidden by rule, client: 34.67.24.114, server: lasfiziosapizzeria.it, request: "GET /wp-config.php.swp HTTP/1.1", host: "mail.lasfiziosapizzeria.it"
2026/08/29 02:43:38 [error] 1884168#1884168: *874100 access forbidden by rule, client: 34.67.24.114, server: lasfiziosapizzeria.it, request: "GET /wp-config.php~ HTTP/1.1", host: "mail.lasfiziosapizzeria.it"
show less
Port Scan
๐ซ๐ฎ
Kimmo Rieskaniemi
2026-08-29 00:31:06
(4 hours ago)
CrowdSec triggered crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ซ๐ท
masterguru
2026-08-28 23:59:52
(4 hours ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.67.24.114 (US/United States/114.24 ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.67.24.114 (US/United States/114.24.67.34.bc.googleusercontent.com): 2 in the last 3600 secs (0-196)
show less
Hacking
๐บ๐ธ
factor1
2026-08-28 23:53:11
(5 hours ago)
CrowdSec at sherman Reports Abuse
Web App Attack
๐ฌ๐ง
Apache
2026-08-28 23:14:35
(5 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.67.24.114 (US/United States/114.24.67.34.bc. ...
show more
(mod_security) mod_security (id:210730) triggered by 34.67.24.114 (US/United States/114.24.67.34.bc.googleusercontent.com): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
๐ฎ๐ฉ
Burayot
2026-08-28 23:01:17
(5 hours ago)
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 34.67.24.114 (US/United States/114.2 ...
show more
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 34.67.24.114 (US/United States/114.24.67.34.bc.googleusercontent.com): 1 in the last 3600 secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 22:42:04
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.67.24.114 (114.24.67.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.67.24.114 (114.24.67.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 18:41:57.129898 2026] [security2:error] [pid 7413:tid 7433] [client 34.67.24.114:57728] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "chris.abney.info"] [uri "/.env.prod"] [unique_id "apIOtVN5b_pcN29AT0mLCQAAAJQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-28 22:25:53
(6 hours ago)
Scan for .env Files at 2026-08-28T22:25:53+00:00
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 20:14:57
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.67.24.114 (114.24.67.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.67.24.114 (114.24.67.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 16:14:49.453484 2026] [security2:error] [pid 28561:tid 28561] [client 34.67.24.114:50712] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.pleasanthillfarms.com"] [uri "/.env.production"] [unique_id "apHsOW9aCzQCZs1jIq3adwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
XICTRON
2026-08-28 20:10:04
(8 hours ago)
ModSecurity rule violation detected by Fail2Ban
Web App Attack