๐ซ๐ท
masterguru
2026-09-02 05:35:50
(11 minutes ago)
Remote Command Execution: Unix Command Injection (command without evasion). Pattern match "(?i)(?:b ...
show more
Remote Command Execution: Unix Command Injection (command without evasion). Pattern match "(?i)(?:b (932235-195)
show less
Hacking
Anonymous
2026-09-02 05:06:06
(40 minutes ago)
Bot / scanning and/or hacking attempts: GET /web/.env HTTP/1.1, GET /.env.yaml HTTP/1.1, GET /.env.y ...
show more
Bot / scanning and/or hacking attempts: GET /web/.env HTTP/1.1, GET /.env.yaml HTTP/1.1, GET /.env.yml HTTP/1.1, GET /apps/.env HTTP/1.1, GET /.env.uat HTTP/1.1, GET /.env_copy HTTP/1.1, GET /.env.json HTTP/1.1, GET /server/.env HTTP/1.1, GET /public/.env HTTP/1.1, GET /api/.env HTTP/1.1, GET /site/.env HTTP/1.1, GET /admin/.env HTTP/1.1, GET /app/.env HTTP/1.1, GET /backend/.env HTTP/1.1
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 04:15:31
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.81.46.47 (47.46.81.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.46.47 (47.46.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 00:15:28.021631 2026] [security2:error] [pid 26433:tid 26433] [client 34.81.46.47:56718] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "superlamb.com"] [uri "/.git/config"] [unique_id "apei4GexgqWH2IiigoczhQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Gwyneth Llewelyn
2026-09-02 03:10:48
(2 hours ago)
2026/09/02 04:10:38 [error] 380594#380594: *2212621 access forbidden by rule, client: 34.81.46.47, s ...
show more
2026/09/02 04:10:38 [error] 380594#380594: *2212621 access forbidden by rule, client: 34.81.46.47, server: superiorinnercore.game-host.org, request: "GET /.env HTTP/1.1", host: "superiorinnercore.game-host.org"
34.81.46.47 - - [02/Sep/2026:04:10:38 +0100] "GET /.env HTTP/1.1" 403 1178 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
2026/09/02 04:10:46 [error] 380594#380594: *2212621 access forbidden by rule, client: 34.81.46.47, server: superiorinnercore.game-host.org, request: "GET /app/.env HTTP/1.1", host: "superiorinnercore.game-host.org"
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 03:06:02
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.81.46.47 (47.46.81.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.46.47 (47.46.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 23:05:54.407458 2026] [security2:error] [pid 23571:tid 23571] [client 34.81.46.47:56894] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "superiorhandyman.net"] [uri "/.git/config"] [unique_id "apeSkg-UDECOYtxvAg6noAAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Nevermind
2026-09-01 23:00:03
(6 hours ago)
34.81.46.47 - - [02/Sep/2026:01:00:01 +0200] "GET /.git/config HTTP/1.1" 403 5663 "-" "Mozilla/5.0 ( ...
show more
34.81.46.47 - - [02/Sep/2026:01:00:01 +0200] "GET /.git/config HTTP/1.1" 403 5663 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.81.46.47 - - [02/Sep/2026:01:00:01 +0200] "GET /.env HTTP/1.1" 403 5663 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.81.46.47 - - [02/Sep/2026:01:00:01 +0200] "GET /.env.local HTTP/1.1" 403 5663 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.81.46.47 - - [02/Sep/2026:01:00:01 +0200] "GET /.env.production HTTP/1.1" 403 5663 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 22:56:36
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.81.46.47 (47.46.81.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.46.47 (47.46.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 18:56:32.536242 2026] [security2:error] [pid 24533:tid 24663] [client 34.81.46.47:60872] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "supercyprus.com"] [uri "/.git/config"] [unique_id "apdYIHXF3W7VCily_nEkVQAAAhY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
nyt
2026-09-01 22:01:49
(7 hours ago)
Sensitive File Probe
Web App Attack
๐ท๐ด
clauss
2026-09-01 20:34:12
(9 hours ago)
34.81.46.47 - - [01/Sep/2026:23:34:09 +0300] "GET /.git/config HTTP/1.1" 403 4783 "-" "Mozilla/5.0 ( ...
show more
34.81.46.47 - - [01/Sep/2026:23:34:09 +0300] "GET /.git/config HTTP/1.1" 403 4783 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.81.46.47 - - [01/Sep/2026:23:34:11 +0300] "GET /.env.local HTTP/1.1" 403 4786 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 20:22:01
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.81.46.47 (47.46.81.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.46.47 (47.46.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 16:21:53.869711 2026] [security2:error] [pid 22330:tid 22330] [client 34.81.46.47:57962] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "superbat.info"] [uri "/.git/config"] [unique_id "apcz4XTI9wXiy-r33jrkBAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
2000cn.com.au
2026-09-01 20:16:09
(9 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ฎ๐น
VHosting
2026-09-01 19:40:04
(10 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
Anonymous
2026-09-01 18:10:13
(11 hours ago)
| [Dangerous/Taiwan] Aggressive IP 34.81.46.47 (~30 hits). Type: DoS Defender- Web server 400 error ...
show more
| [Dangerous/Taiwan] Aggressive IP 34.81.46.47 (~30 hits). Type: DoS Defender- Web server 400 error code
show less
Web App Attack
Hacking
SQL Injection
๐ซ๐ท
Octopuce
2026-09-01 18:04:53
(11 hours ago)
Aggressive web search of vulnerable pages: /.env /.env.local /app/.env /apps/.env /api/.env ...
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-01 17:55:37
(11 hours ago)
Excessive 404/403 errors
Brute-Force