๐ฉ๐ช
pscriptos
2026-09-16 03:58:50
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/appsec-vpatch
Web App Attack
๐ซ๐ท
Stara
2026-09-16 01:19:45
(1 day ago)
ModSecurity detected web attack - .env/config probing or SQLi/Code injection (Rule 949110)
Brute-Force
Hacking
Web App Attack
๐ฒ๐พ
Rizzy
2026-09-16 00:25:58
(1 day ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ณ๐ฟ
Tripwire
2026-09-15 22:40:49
(1 day ago)
Scanning for exploits - /.env
Web App Attack
๐ซ๐ท
dynamix
2026-09-15 22:27:33
(1 day ago)
Automated web vulnerability and path enumeration scan with excessive 404 requests
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-15 19:37:48
(1 day ago)
[cb-05al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[cb-05al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.88.131.176 - - [15/Sep/2026:21:37:48 +0200] "GET /.git/config HTTP/1.1" 404 6850 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐ซ๐ท
LoneRider
2026-09-15 19:34:40
(1 day ago)
[15/Sep/2026:21:34:39.253983 +0200] aqmdz4oV1L8hCgfnDJvlMQAAAAo 34.88.131.176 52022 127.0.0.1 7081
[ ...
show more
[15/Sep/2026:21:34:39.253983 +0200] aqmdz4oV1L8hCgfnDJvlMQAAAAo 34.88.131.176 52022 127.0.0.1 7081
[15/Sep/2026:21:34:39.417725 +0200] aqmdzwZlv3rtdymvPB8ZsAAAAAg 34.88.131.176 52040 127.0.0.1 7081
[15/Sep/2026:21:34:39.469944 +0200] aqmdzz3UgT7OouGcdnwluQAAAAw 34.88.131.176 52052 127.0.0.1 7081
...
show less
Hacking
Anonymous
2026-09-15 17:38:51
(1 day ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
Anonymous
2026-09-15 17:23:21
(1 day ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 16:11:34
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.88.131.176 (176.131.88.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.88.131.176 (176.131.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 12:11:15.286901 2026] [security2:error] [pid 8679:tid 8679] [client 34.88.131.176:35550] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||jresm.com|F|2"] [data ".env.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "jresm.com"] [uri "/.env.bak"] [unique_id "aqluI3sZk8rqgZSXAXVpXwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-15 12:51:54
(1 day ago)
20 attempts against mh_ha-misbehave-ban on boron
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-15 11:46:41
(1 day ago)
20 attempts against mh-misbehave-ban on eris
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 10:31:06
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.88.131.176 (176.131.88.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.131.176 (176.131.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 06:30:59.777121 2026] [security2:error] [pid 13746:tid 13789] [client 34.88.131.176:48744] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jrc3.com"] [uri "/.git/config"] [unique_id "aqkeYyY6xJ6FGWiUAagPMwAAAYU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 09:48:06
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.88.131.176 (176.131.88.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.131.176 (176.131.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 05:47:59.688476 2026] [security2:error] [pid 25102:tid 25150] [client 34.88.131.176:42818] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jrbllc.com"] [uri "/.git/config"] [unique_id "aqkUT9wQ3R5yeqgOtFX1BQAAAMw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 09:27:21
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.88.131.176 (176.131.88.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.131.176 (176.131.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 05:27:18.486370 2026] [security2:error] [pid 14548:tid 14548] [client 34.88.131.176:55826] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jrbentley.com"] [uri "/.git/config"] [unique_id "aqkPdrmm0vJBBrzx2VXjdgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack