๐บ๐ธ
TPI-Abuse
2026-10-02 15:06:29
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.87.25.211 (211.25.87.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.25.211 (211.25.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 11:06:25.170675 2026] [security2:error] [pid 10679:tid 10679] [client 34.87.25.211:33428] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.zaaniebowen.dev"] [uri "/.htpasswd"] [unique_id "ar_IcXq1JZnRVQLFfwRPjgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
lolyay
2026-10-02 12:22:43
(2 days ago)
34.87.25.211 - - [02/Oct/2026:12:22:42 +0000] "GET /wp-config.php.old HTTP/1.1" 200 4 "-" "Mozilla/5 ...
show more
34.87.25.211 - - [02/Oct/2026:12:22:42 +0000] "GET /wp-config.php.old HTTP/1.1" 200 4 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] )"
34.87.25.211 - - [02/Oct/2026:12:22:42 +0000] "GET /laravel/.env HTTP/1.1" 200 4 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)"
...
show less
Web App Attack
Bad Web Bot
๐บ๐ธ
Aurealize
2026-10-02 12:17:03
(2 days ago)
Automated Sensitive File discovery attempt detected by a Cloudflare WAF custom rule. Path: /env.json ...
show more
Automated Sensitive File discovery attempt detected by a Cloudflare WAF custom rule. Path: /env.json.
show less
Web App Attack
Hacking
๐บ๐ธ
interbiznw.com
2026-10-02 12:09:09
(2 days ago)
malicious-web-requests-vulnerability-scanning
Hacking
Brute-Force
Exploited Host
Web App Attack
๐ธ๐ฌ
leithzz
2026-10-02 12:06:55
(2 days ago)
7x HTTP 403 to krynox.dev:8080 from SG, method GET, path /credentials.json. Blocked by Cloudflare ac ...
show more
7x HTTP 403 to krynox.dev:8080 from SG, method GET, path /credentials.json. Blocked by Cloudflare action block (firewallCustom). Repeated L7 flood traffic.
show less
DDoS Attack
Web App Attack
๐จ๐ญ
leo1305
2026-10-02 11:36:25
(2 days ago)
CrowdSec detection | scenario: http-path-traversal-probing
Web App Attack
Exploited Host
๐ง๐ช
cmbplf
2026-10-02 11:34:13
(2 days ago)
662 requests with url.path *.env
169 requests with url.path */@fs/*
Brute-Force
Bad Web Bot
๐ฎ๐น
VHosting
2026-10-02 10:25:03
(2 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐จ๐ฟ
akac
2026-10-02 10:02:25
(2 days ago)
Web vulnerability scanning: HTTP/2 GET /@fs/var/run/secrets/kubernetes.io/serviceaccount/...
Hacking
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 08:53:43
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.87.25.211 (211.25.87.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.25.211 (211.25.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 04:53:37.775090 2026] [security2:error] [pid 9499:tid 9499] [client 34.87.25.211:38478] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.headcount.dev"] [uri "/.env.js"] [unique_id "ar9xEaDzfGcNFSBUFBXV_gAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 08:33:40
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.87.25.211 (211.25.87.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.25.211 (211.25.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 04:33:33.127656 2026] [security2:error] [pid 340:tid 340] [client 34.87.25.211:52418] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "matteozacchino.dev"] [uri "/.htpasswd"] [unique_id "ar9sXZ-7YsblqIPxlOyraAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 07:58:33
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.87.25.211 (211.25.87.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.25.211 (211.25.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 03:58:26.897163 2026] [security2:error] [pid 25511:tid 25511] [client 34.87.25.211:48482] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bwill.dev"] [uri "/.htpasswd"] [unique_id "ar9kIu8urInLh_AahjvidgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
john doe
2026-10-02 07:19:54
(3 days ago)
SentinelBot: Secret-path hunting (5 distinct paths): Env File Hunting (score: 68)
Bad Web Bot
๐ฉ๐ช
Manuel Braeuer
2026-10-02 07:17:56
(3 days ago)
34.87.25.211 - - [02/Oct/2026:09:17:55 +0200] "GET /.ssh/config HTTP/1.1" 403 6256 "-" "Mozilla/5.0 ...
show more
34.87.25.211 - - [02/Oct/2026:09:17:55 +0200] "GET /.ssh/config HTTP/1.1" 403 6256 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)"
34.87.25.211 - - [02/Oct/2026:09:17:55 +0200] "GET /.ssh/id_ed25519 HTTP/1.1" 403 6256 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
34.87.25.211 - - [02/Oct/2026:09:17:56 +0200] "GET /.bashrc HTTP/1.1" 403 6256 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)"
34.87.25.211 - - [02/Oct/2026:09:17:56 +0200] "GET /.zshrc HTTP/1.1" 403 6256 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)"
34.87.25.211 - - [02/Oct/2026:09:17:56 +0200] "GET /@fs/../.env?raw?? HTTP/1.1" 403 6256 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )"
...
show less
Web App Attack
๐ฌ๐ง
gws-hostmaster
2026-10-02 07:16:51
(3 days ago)
ModSecurity OWASP CRS (Anomaly Score: 45): HTTP header is restricted by policy (/x-middleware-subreq ...
show more
ModSecurity OWASP CRS (Anomaly Score: 45): HTTP header is restricted by policy (/x-middleware-subrequest/);JavaScript Prototype Pollution;JSON-Based SQL Injection;Node.js Injection Attack 1/2;OS File Access Attempt;Remote Command Execution: Unix Shell Code Found;Restricted File Access Attempt;
show less
Web App Attack