🇦🇺
2000cn.com.au
2026-09-06 06:36:37
(10 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
Anonymous
2026-09-06 06:30:03
(10 hours ago)
| Suspicious URL access.
Web App Attack
Hacking
SQL Injection
🇺🇸
TPI-Abuse
2026-09-06 03:51:06
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.83.19.15 (15.19.83.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.83.19.15 (15.19.83.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:50:58.970633 2026] [security2:error] [pid 11165:tid 11183] [client 34.83.19.15:51874] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.cookmanufacturinggroup.com"] [uri "/wp-config.php.swp"] [unique_id "apzjIv1pRt8N7QnZBIknLwAAAE8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇷🇴
clauss
2026-09-06 03:01:44
(13 hours ago)
34.83.19.15 - - [06/Sep/2026:06:01:43 +0300] "GET /.env.old HTTP/1.1" 403 146 "-" "crusader-worker/1 ...
show more
34.83.19.15 - - [06/Sep/2026:06:01:43 +0300] "GET /.env.old HTTP/1.1" 403 146 "-" "crusader-worker/1.0"
34.83.19.15 - - [06/Sep/2026:06:01:43 +0300] "GET /wp-config.php.swp HTTP/1.1" 403 146 "-" "crusader-worker/1.0"
...
show less
Web App Attack
🇩🇪
YF
2026-09-06 03:00:18
(13 hours ago)
WordPress config file probe
Web App Attack
🇩🇪
netclix.gr
2026-09-06 02:58:34
(14 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.83.19.15 (US/United States/15.19.83. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.83.19.15 (US/United States/15.19.83.34.bc.googleusercontent.com): (CF_ENABLE)
show less
SQL Injection
🇺🇸
TPI-Abuse
2026-09-06 02:46:42
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.83.19.15 (15.19.83.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.83.19.15 (15.19.83.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:46:37.427823 2026] [security2:error] [pid 11740:tid 11740] [client 34.83.19.15:42722] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "agrisea.net"] [uri "/.env.bak"] [unique_id "apzUDax4UP2T55IMRJroyAAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Petros Stefanakis
2026-09-06 02:45:15
(14 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.83.19.15 (US/United States/15.19.83. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.83.19.15 (US/United States/15.19.83.34.bc.googleusercontent.com)
show less
SQL Injection
🇳🇱
e.fierstra
2026-09-06 02:31:03
(14 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
wteiken
2026-09-06 02:24:48
(14 hours ago)
2026-09-05T22:24:48.313846-04:00 rocinante.teiken.net kernel: [554129.063289] syn_limit:IN=ens5 OUT= ...
show more
2026-09-05T22:24:48.313846-04:00 rocinante.teiken.net kernel: [554129.063289] syn_limit:IN=ens5 OUT= MAC=0a:ff:cf:a1:a5:bb:0a:f3:ae:05:2f:b7:08:00 SRC=34.83.19.15 DST=192.168.16.119 LEN=60 TOS=0x00 PREC=0x00 TTL=57 ID=7249 DF PROTO=TCP SPT=52462 DPT=443 WINDOW=65320 RES=0x00 SYN URGP=0
2026-09-05T22:24:48.314037-04:00 rocinante.teiken.net kernel: [554129.063418] syn_limit:IN=ens5 OUT= MAC=0a:ff:cf:a1:a5:bb:0a:f3:ae:05:2f:b7:08:00 SRC=34.83.19.15 DST=192.168.16.119 LEN=60 TOS=0x00 PREC=0x00 TTL=57 ID=60692 DF PROTO=TCP SPT=52536 DPT=443 WINDOW=65320 RES=0x00 SYN URGP=0
2026-09-05T22:24:48.314081-04:00 rocinante.teiken.net kernel: [554129.065937] syn_limit:IN=ens5 OUT= MAC=0a:ff:cf:a1:a5:bb:0a:f3:ae:05:2f:b7:08:00 SRC=34.83.19.15 DST=192.168.16.119 LEN=60 TOS=0x00 PREC=0x60 TTL=58 ID=31598 DF PROTO=TCP SPT=52624 DPT=443 WINDOW=65320 RES=0x00 SYN URGP=0
2026-09-05T22:24:48.314116-04:00 rocinante.teiken.net kernel: [554129.068595] syn_limit:IN=ens5 OUT= MAC=0a:ff:cf:a1:a5:bb:0a:f3:ae:05
...
show less
Port Scan
Anonymous
2026-09-06 01:35:11
(15 hours ago)
Bot / seems abusive / Apache connections: 43
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
🇲🇾
Rizzy
2026-09-06 00:40:59
(16 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
🇬🇧
[email protected]
2026-09-05 23:59:45
(16 hours ago)
34.83.19.15 - - [05/Sep/2026:23:59:44 +0000] "GET /.env.save HTTP/1.1" 404 327 "-" "crusader-worker/ ...
show more
34.83.19.15 - - [05/Sep/2026:23:59:44 +0000] "GET /.env.save HTTP/1.1" 404 327 "-" "crusader-worker/1.0"
34.83.19.15 - - [05/Sep/2026:23:59:44 +0000] "GET /.env.bak HTTP/1.1" 404 327 "-" "crusader-worker/1.0"
34.83.19.15 - - [05/Sep/2026:23:59:44 +0000] "GET /.env.dev HTTP/1.1" 404 327 "-" "crusader-worker/1.0"
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 23:54:39
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.83.19.15 (15.19.83.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.83.19.15 (15.19.83.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:54:33.315395 2026] [security2:error] [pid 3505780:tid 3505914] [client 34.83.19.15:32926] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bacchus.productions"] [uri "/.env"] [unique_id "apyruaeVUu6W99IeSwEQDAAAAg4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-09-05 23:40:03
(17 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack