๐ฉ๐ช
terminal.myselfhosted.online
2026-09-03 18:59:19
(4 hours ago)
...
Hacking
Web App Attack
๐ญ๐บ
miszterx.hu
2026-09-02 05:07:03
(1 day ago)
XORP (haproxy): 3x HTTP 404/403/500 or handshake failure in 24h. Automated report from log_check_ipt ...
show more
XORP (haproxy): 3x HTTP 404/403/500 or handshake failure in 24h. Automated report from log_check_iptables_generator.sh (xorp.hu)
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 11:07:21
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.87.194.214 (214.194.87.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.194.214 (214.194.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 07:07:16.364466 2026] [security2:error] [pid 15915:tid 15915] [client 34.87.194.214:41566] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "w360.elpais.mx"] [uri "/.env.local"] [unique_id "apax5LBJ-TZgLHgrkAXENQAAACs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-01 11:04:39
(2 days ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
Anonymous
2026-09-01 09:47:50
(2 days ago)
Trapped by Fail2Ban: Too many login failures from 34.87.194.214
Brute-Force
Hacking
๐ฆ๐บ
2000cn.com.au
2026-09-01 09:32:22
(2 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐ฌ๐ง
gws-hostmaster
2026-09-01 09:15:56
(2 days ago)
[Tue Sep 01 10:15:55.753491 2026] [authz_core:error] [pid 2592048] [client 34.87.194.214:0] AH01630: ...
show more
[Tue Sep 01 10:15:55.753491 2026] [authz_core:error] [pid 2592048] [client 34.87.194.214:0] AH01630: client denied by server configuration: /var/www/vhosts/iqvisuals.uk/store.iqvisuals.uk/.env.production
[Tue Sep 01 10:15:55.756615 2026] [authz_core:error] [pid 2592046] [client 34.87.194.214:0] AH01630: client denied by server configuration: /var/www/vhosts/iqvisuals.uk/store.iqvisuals.uk/.env.example
[Tue Sep 01 10:15:55.758476 2026] [authz_core:error] [pid 2631449] [client 34.87.194.214:0] AH01630: client denied by server configuration: /var/www/vhosts/iqvisuals.uk/store.iqvisuals.uk/.env.prod
[Tue Sep 01 10:15:55.760089 2026] [authz_core:error] [pid 2592048] [client 34.87.194.214:0] AH01630: client denied by server configuration: /var/www/vhosts/iqvisuals.uk/store.iqvisuals.uk/.env.backup
[Tue Sep 01 10:15:55.826020 2026] [authz_core:error] [pid 2592049] [client 34.87.194.214:0] AH01630: client denied by server configuration: /var/www/vhosts/iqvisuals.uk/store.iqvisuals.uk/.env.loca
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 07:47:57
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.87.194.214 (214.194.87.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.194.214 (214.194.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 03:47:49.168881 2026] [security2:error] [pid 23498:tid 23581] [client 34.87.194.214:52754] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gelatoconsapevole.it"] [uri "/wp-config.php.swp"] [unique_id "apaDJRsgjZgCfYAWBKmFXQAAApY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
nfsec.pl
2026-09-01 06:32:27
(2 days ago)
34.87.194.214 - - [01/Sep/2026:06:32:27 +0000] "GET /.env HTTP/1.1" 403 5379 "-" "crusader-worker/1. ...
show more
34.87.194.214 - - [01/Sep/2026:06:32:27 +0000] "GET /.env HTTP/1.1" 403 5379 "-" "crusader-worker/1.0"
34.87.194.214 - - [01/Sep/2026:06:32:27 +0000] "GET /wp-config.php~ HTTP/1.1" 404 5376 "-" "crusader-worker/1.0"
34.87.194.214 - - [01/Sep/2026:06:32:27 +0000] "GET /.env.production HTTP/1.1" 403 5379 "-" "crusader-worker/1.0"
34.87.194.214 - - [01/Sep/2026:06:32:27 +0000] "GET /.env.example HTTP/1.1" 403 5379 "-" "crusader-worker/1.0"
34.87.194.214 - - [01/Sep/2026:06:32:27 +0000] "GET /wp-config.php.bak HTTP/1.1" 403 5379 "-" "crusader-worker/1.0"
...
show less
Web App Attack
Exploited Host
๐บ๐ธ
factor1
2026-09-01 06:24:21
(2 days ago)
CrowdSec at apollo Reports Abuse
Web App Attack
๐ฌ๐ง
Aetherweb Ark
2026-09-01 06:14:17
(2 days ago)
(mod_security) mod_security (id:949110) triggered by 34.87.194.214 (AU/Australia/214.194.87.34.bc.go ...
show more
(mod_security) mod_security (id:949110) triggered by 34.87.194.214 (AU/Australia/214.194.87.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
Anonymous
2026-09-01 05:07:02
(2 days ago)
Automated web scanner. Requested suspicious paths: /.env.bak | /actuator/env | /.env.local | /.env.b ...
show more
Automated web scanner. Requested suspicious paths: /.env.bak | /actuator/env | /.env.local | /.env.backup | /_ignition/health-check | /.env.dev | /crusader-404-probe | /.env.old | /env | /.env.example | /.env.production | /.env.save | /actuator/configprops | /.env | /storage/logs/laravel.log, /.env.prod | /actuator/env | /.env.local | /.env.backup | /_ignition/health-check | /.env.dev | /crusader-404-probe | /.env.old | /env | /.env.example | /.env.production | /.env.save | /actuator/configprops | /.env | /storage/logs/laravel.log. UTC: 2026-09-01 04:15:11.
show less
Web App Attack
Anonymous
2026-09-01 04:20:03
(2 days ago)
Bot / scanning and/or hacking attempts: GET /.env.dev HTTP/1.1, GET /actuator/env HTTP/1.1, GET /.en ...
show more
Bot / scanning and/or hacking attempts: GET /.env.dev HTTP/1.1, GET /actuator/env HTTP/1.1, GET /.env.bak HTTP/1.1, GET /actuator/configprops HTTP/1.1, GET /.env HTTP/1.1, GET /.env.backup HTTP/1.1, GET /.env.local HTTP/1.1, GET /.env.example HTTP/1.1, GET /storage/logs/laravel.log HTTP/1.1, GET /.env.save HTTP/1.1, GET /.env.prod HTTP/1.1, GET /_ignition/health-check HTTP/1.1, GET /.env.production HTTP/1.1, GET /env HTTP/1.1, GET /wp-config.php.bak HTTP/1.1
show less
Hacking
Web App Attack
๐ซ๐ท
dynamix
2026-09-01 03:48:23
(2 days ago)
Multiple WAF Violations
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-09-01 03:46:31
(2 days ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack