Anonymous
2026-09-13 17:34:11
(5 days ago)
Multiple pen test attempts.
Web App Attack
Anonymous
2026-09-13 17:30:02
(5 days ago)
CrowdSec decision: crowdsecurity/http-admin-interface-probing (origin: crowdsec)
Web App Attack
๐ฉ๐ช
XICTRON
2026-09-13 17:00:09
(5 days ago)
ModSecurity rule violation detected by Fail2Ban
Web App Attack
๐บ๐ธ
Sling
2026-09-13 15:52:32
(5 days ago)
Automated detection: IP accessed 5 sensitive endpoints within 30s on slingexe.com. Paths: /.env.loca ...
show more
Automated detection: IP accessed 5 sensitive endpoints within 30s on slingexe.com. Paths: /.env.local, /.env.production, /_astro/pages/index.astro.mjs.map, /pages/api/index.astro.mjs.map, /application.properties. UA: Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/).
show less
Web App Attack
Bad Web Bot
Hacking
๐ฎ๐น
CoreTech srl
2026-09-13 15:23:57
(5 days ago)
cloudlinux2 fail2ban: 2026-09-13 17:20:11,050 fail2ban.actions [1591]: NOTICE [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-13 17:20:11,050 fail2ban.actions [1591]: NOTICE [plesk-modsecurity] Unban 34.97.6.148cloudlinux2 fail2ban: 2026-09-13 17:20:49,113 fail2ban.actions [1591]: NOTICE [plesk-modsecurity] Ban 34.77.168.167cloudlinux2 fail2ban: 2026-09-13 17:20:48,608 fail2ban.filter [1591]: INFO [plesk-modsecurity] Found 34.77.168.167 - 2026-09-13 17:20:48cloudlinux2 fail2ban: 2026-09-13 17:20:46,485 fail2ban.filter [1591]: INFO [plesk-modsecurity] Found 34.77.168.167 - 2026-09-13 17:20:46cloudlinux2 fail2ban: 2026-09-13 17:20:49,096 fail2ban.filter [1591]: INFO [plesk-modsecurity] Found 34.77.168.167 - 2026-09-13 17:20:49cloudlinux2 fail2ban: 2026-09-13 17:20:49,119 fail2ban.filter [1591]: INFO [recidive] Found 34.77.168.167 - 2026-09-13 17:20:49cloudlinux2 fail2ban: 2026-09-13 17:20:48,596 fail2ban.filter [1591]: INFO [plesk-modsecurity] Found 34.77.168.167 - 2026-09-13 17:20:48cloudlinux2 fail2ban: 2026-09-13 17:20:48,620 fail2b
show less
Brute-Force
๐บ๐ธ
interbiznw.com
2026-09-13 14:24:26
(5 days ago)
malicious-web-requests-vulnerability-scanning
Hacking
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-13 14:13:17
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.77.168.167 (167.168.77.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.77.168.167 (167.168.77.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 10:13:12.595902 2026] [security2:error] [pid 24903:tid 24903] [client 34.77.168.167:50766] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hendersonhomes.com"] [uri "/.svn/entries"] [unique_id "aqaveE2p0B6ki8n9ykfWLAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
demomodule
2026-09-13 13:35:23
(5 days ago)
PrestaShop Security Module: suspicious probe path detected (/.env)
Web App Attack
๐ช๐ธ
pepitogrillo
2026-09-13 13:23:14
(5 days ago)
34.77.168.167 - - [13/Sep/2026:13:23:13 +0000] "GET /_nuxt/../.env HTTP/1.1" 404 99458 "-" "Mozilla/ ...
show more
34.77.168.167 - - [13/Sep/2026:13:23:13 +0000] "GET /_nuxt/../.env HTTP/1.1" 404 99458 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
...
show less
DNS Compromise
DNS Poisoning
Fraud Orders
DDoS Attack
Ping of Death
Phishing
Fraud VoIP
Open Proxy
Web Spam
Email Spam
Port Scan
Hacking
SQL Injection
Bad Web Bot
Exploited Host
Web App Attack
IoT Targeted
๐บ๐ธ
TPI-Abuse
2026-09-13 13:19:49
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.77.168.167 (167.168.77.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.77.168.167 (167.168.77.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 09:19:43.568326 2026] [security2:error] [pid 18843:tid 18843] [client 34.77.168.167:60912] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "christinepeat.com"] [uri "/%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env"] [unique_id "aqai70hliwa2JsPaJrAq3wAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-13 13:00:05
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.77.168.167 (167.168.77.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.77.168.167 (167.168.77.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 08:59:55.044607 2026] [security2:error] [pid 23939:tid 23939] [client 34.77.168.167:46278] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "chrismoratz.com"] [uri "/css../.env"] [unique_id "aqaeSxMHqn_zDsaRUlsqnAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-13 12:42:10
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 34.77.168.167 (167.168.77.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.77.168.167 (167.168.77.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 08:42:04.036406 2026] [security2:error] [pid 1727:tid 1727] [client 34.77.168.167:41910] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||chooseyourowntrail.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "chooseyourowntrail.com"] [uri "/z9x8c7v6b5-debug-trigger-chooseyourowntrail.com"] [unique_id "aqaaHNaCBO4kt9WvZkcYdQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
IRISIO
2026-09-13 12:40:38
(5 days ago)
scans/SQL injection/spam posts : 76 queries
Web App Attack
SQL Injection
๐ฉ๐ช
tentwentyfour
2026-09-13 12:19:51
(5 days ago)
Blocked for probing for sensitive web application components
Brute-Force
Web App Attack
Anonymous
2026-09-13 12:12:01
(5 days ago)
34.77.168.167 - - [13/Sep/2026:07:12:00 -0500] "GET /.env?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (co ...
show more
34.77.168.167 - - [13/Sep/2026:07:12:00 -0500] "GET /.env?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)" 34.77.168.167
34.77.168.167 - - [13/Sep/2026:07:12:00 -0500] "GET /.env?import&url&inline HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/)" 34.77.168.167
34.77.168.167 - - [13/Sep/2026:07:12:00 -0500] "GET /.env?import&raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)" 34.77.168.167
34.77.168.167 - - [13/Sep/2026:07:12:00 -0500] "GET /.env.local?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)" 34.77.168.167
34.77.168.167 - - [13/Sep/2026:07:12:00 -0500] "GET /.env.local?import&raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)" 34.77.168.167
34.77.168.167 - - [13/Sep/2026:07:12:00 -0500] "GET /.env.production?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.
...
show less
Brute-Force
Bad Web Bot
Web App Attack