๐ธ๐ฌ
nayumi
2026-08-27 20:34:49
(2 hours ago)
CrowdSec detection: crowdsecurity/http-sensitive-files | Service: http, http, http, http, http
Web App Attack
๐ณ๐ฑ
MM-bot
2026-08-27 19:13:50
(4 hours ago)
URL-probe: HTTP/1.1 GET request on /.env.dev (2026-08-27 21:13:50 UTC+2)
Web App Attack
Hacking
๐บ๐ธ
mnsf
2026-08-27 19:05:15
(4 hours ago)
Abuse Detected (9)
Brute-Force
Web App Attack
๐ง๐พ
shopmax
2026-08-27 18:55:43
(4 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-27 18:33:45
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.72.17.237 (237.17.72.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.72.17.237 (237.17.72.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 14:33:38.854136 2026] [security2:error] [pid 29217:tid 29217] [client 34.72.17.237:37518] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "eclipsesoftware.biz"] [uri "/wp-config.php.bak"] [unique_id "apCDAo-fBHvBRxPTBkKmJgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
sigurg
2026-08-27 18:27:21
(4 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ท๐บ
DZBOT
2026-08-27 18:25:09
(5 hours ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐ช๐ธ
alferez
2026-08-27 18:02:51
(5 hours ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 18:02:30
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.72.17.237 (237.17.72.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.72.17.237 (237.17.72.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 14:02:25.435803 2026] [security2:error] [pid 28790:tid 28790] [client 34.72.17.237:40036] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mahoninginn.com"] [uri "/.env.dev"] [unique_id "apB7sYsO6WQEVKJVRkb20gAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-27 17:37:23
(5 hours ago)
CrowdSec blocked IP for crowdsecurity/http-sensitive-files on vps_agent
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 17:07:39
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.72.17.237 (237.17.72.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.72.17.237 (237.17.72.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 13:07:33.149261 2026] [security2:error] [pid 26675:tid 26675] [client 34.72.17.237:46118] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.wow-tx.com.srtmanagementservices.com"] [uri "/wp-config.php.bak"] [unique_id "apBu1f6eRK7L6DgA_zozCAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 16:35:32
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.72.17.237 (237.17.72.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.72.17.237 (237.17.72.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 12:35:26.869395 2026] [security2:error] [pid 28652:tid 28652] [client 34.72.17.237:49376] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kugbe.com"] [uri "/.env.production"] [unique_id "apBnTiOYa7JpkWW1666J3QAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
polycoda
2026-08-27 15:54:18
(7 hours ago)
AutoBlock: ๐ฏ Vulnerability Scanner (Non Decay-Based)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 15:52:15
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.72.17.237 (237.17.72.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.72.17.237 (237.17.72.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 11:52:07.090836 2026] [security2:error] [pid 10735:tid 10735] [client 34.72.17.237:36004] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.talleyappraisalservices.taltonfamily.com"] [uri "/.env.old"] [unique_id "apBdJyQuvQyqt5MzKSq1qAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐น๐ท
eryilmaz
2026-08-27 15:44:05
(7 hours ago)
Automated attack blocked by eryilmaz WAF/defense engine (level 1, source: auto, path: /_ignition/hea ...
show more
Automated attack blocked by eryilmaz WAF/defense engine (level 1, source: auto, path: /_ignition/health-check)
show less
Web App Attack
Hacking