🇫🇷
dynamix
2026-09-06 01:35:28
(9 hours ago)
Multiple WAF Violations
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-06 00:46:38
(10 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
🇳🇱
MyGlobalFlowers
2026-09-06 00:35:33
(10 hours ago)
Multiple WAF Violations
Web App Attack
🇳🇱
e.fierstra
2026-09-06 00:28:46
(11 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-06 00:16:06
(11 hours ago)
Web attack/malicious scanning detected
Web App Attack
Anonymous
2026-09-05 23:00:06
(12 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.88.253.132 (FI/Finland/132.253.88.34 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.88.253.132 (FI/Finland/132.253.88.34.bc.googleusercontent.com)
show less
SQL Injection
🇩🇪
Stefan Dreher
2026-09-05 22:55:00
(12 hours ago)
34.88.253.132 - - [04/Sep/2026:07:00:56 +0200] "GET /app/config/parameters.yaml HTTP/1.1" 404 555 "- ...
show more
34.88.253.132 - - [04/Sep/2026:07:00:56 +0200] "GET /app/config/parameters.yaml HTTP/1.1" 404 555 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36"
34.88.253.132 - - [04/Sep/2026:07:00:56 +0200] "GET /app/config.php HTTP/1.1" 404 555 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36"
34.88.253.132 - - [04/Sep/2026:07:00:56 +0200] "GET /app/config.yml HTTP/1.1" 404 555 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36"
34.88.253.132 - - [04/Sep/2026:07:00:56 +0200] "GET /app/credentials.json HTTP/1.1" 404 555 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36"
34.88.253.132 - - [04/Sep/2026:07:00:56 +0200] "GET /app/database.php HTTP/1.1" 404 555 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36"
...
show less
Hacking
Brute-Force
🇺🇸
TPI-Abuse
2026-09-05 22:44:24
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.88.253.132 (132.253.88.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.253.132 (132.253.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:44:19.358830 2026] [security2:error] [pid 8750:tid 8750] [client 34.88.253.132:39558] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "itecsis.com"] [uri "/.env"] [unique_id "apybQ2piSSY4FfcOJieUEQAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
agenciahypelab.com.br
2026-09-05 22:20:22
(13 hours ago)
WordPress login brute-force detectado e bloqueado pelo CSF/LFD. Trigger: LF_TRIGGER
Brute-Force
SSH
🇺🇸
kosada.com
2026-09-05 22:16:39
(13 hours ago)
Repeated exploit attempts, for example: /.env.save /.env (HTTP/1.1 port 443)
Web App Attack
🇺🇸
LotPhantom
2026-09-05 21:08:16
(14 hours ago)
34.88.253.132 - - [05/Sep/2026:21:07:58 +0000] "GET /_ignition/health-check HTTP/1.1" 404 683 "-" "c ...
show more
34.88.253.132 - - [05/Sep/2026:21:07:58 +0000] "GET /_ignition/health-check HTTP/1.1" 404 683 "-" "crusader-worker/1.0" "0"
...
show less
Web App Attack
🇺🇦
URAN Publishing Service
2026-09-05 20:51:00
(14 hours ago)
[05/Sep/2026:23:51:00 +0300] -- 34.88.253.132 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env ...
show more
[05/Sep/2026:23:51:00 +0300] -- 34.88.253.132 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env.backup HTTP/1.1
show less
Bad Web Bot
Web App Attack
🇩🇪
raph
2026-09-05 20:49:48
(14 hours ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 20:49:45
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.88.253.132 (132.253.88.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.253.132 (132.253.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 16:49:41.189596 2026] [security2:error] [pid 30630:tid 30651] [client 34.88.253.132:50296] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ingeconsultcr.com"] [uri "/.env.local"] [unique_id "apyAZdgZFhsQ-Ns5gJL-UwAAAJM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 20:29:30
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.88.253.132 (132.253.88.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.253.132 (132.253.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 16:29:25.338681 2026] [security2:error] [pid 28067:tid 28067] [client 34.88.253.132:51346] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "crushmycrave.ficklepassionproductions.com"] [uri "/wp-config.php.bak"] [unique_id "apx7pdmtq-Pi5ysCtSYVJQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack