🇫🇷
Allolatr
2026-09-04 12:22:19
(2 minutes ago)
Sep 4 14:22:18 ns332071 nginx: 2026/09/04 14:22:18 [crit] 63884#101138: *4954 SSL_do_handshake() fa ...
show more
Sep 4 14:22:18 ns332071 nginx: 2026/09/04 14:22:18 [crit] 63884#101138: *4954 SSL_do_handshake() failed (13: Permission denied) while SSL handshaking, client: ::ffff:34.94.250.90, server: [::]:443
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-04 11:45:37
(39 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.94.250.90 (90.250.94.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.94.250.90 (90.250.94.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:45:30.951902 2026] [security2:error] [pid 22282:tid 22404] [client 34.94.250.90:57950] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.cookmanufacturinggroup.com"] [uri "/.env.example"] [unique_id "apqvWuWFLdcH77Kdc5AH2AAAAkg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:16:08
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.94.250.90 (90.250.94.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.94.250.90 (90.250.94.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:16:03.997029 2026] [security2:error] [pid 8284:tid 8284] [client 34.94.250.90:41200] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.dividivipartners.com"] [uri "/wp-config.php.bak"] [unique_id "apqocyUbivd8AjCoHwGwSgAAACw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇴
jad-abuse
2026-09-04 10:35:30
(1 hour ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: scanner_u ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: scanner_ua, env_probe, source_backup, actuator, ignition_debug, config_backup. Observed by 1 sensor(s); 19 hits.
show less
Hacking
Web App Attack
🇿🇦
conure.sh
2026-09-04 10:03:21
(2 hours ago)
csagent: score 20.0: secrets grab x2; 1 domain(s) in 0s
Web App Attack
🇸🇪
vaia.cloud
2026-09-04 10:00:05
(2 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
🇬🇧
Aetherweb Ark
2026-09-04 09:57:31
(2 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.94.250.90 (US/United States/90.250.94.34.bc. ...
show more
(mod_security) mod_security (id:949110) triggered by 34.94.250.90 (US/United States/90.250.94.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
🇺🇸
mnsf
2026-09-04 09:05:44
(3 hours ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 08:31:12
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.94.250.90 (90.250.94.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.94.250.90 (90.250.94.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 04:31:06.286837 2026] [security2:error] [pid 5812:tid 5812] [client 34.94.250.90:39770] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.oualierealty.com"] [uri "/.env.prod"] [unique_id "apqBypTM3BsXq_tqDqLBYQAAADM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-04 08:19:41
(4 hours ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 08:02:38
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.94.250.90 (90.250.94.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.94.250.90 (90.250.94.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 04:02:32.060398 2026] [security2:error] [pid 28975:tid 28975] [client 34.94.250.90:41884] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vanemby.com"] [uri "/wp-config.php.bak"] [unique_id "app7GKvJ8XhrsfsJ7A20yAAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-04 07:51:00
(4 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇧🇷
noconex
2026-09-04 07:38:06
(4 hours ago)
Wazuh Alert | Rule ID: 110100 | Desc: Suricata: Exploit (ET WEB_SERVER Tilde in URI - potential .php ...
show more
Wazuh Alert | Rule ID: 110100 | Desc: Suricata: Exploit (ET WEB_SERVER Tilde in URI - potential .php~ source disclosure vulnerability) 34.94.250.90
show less
Port Scan
Brute-Force
SSH
🇺🇸
TPI-Abuse
2026-09-04 07:22:33
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.94.250.90 (90.250.94.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.94.250.90 (90.250.94.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 03:22:28.420380 2026] [security2:error] [pid 26672:tid 26672] [client 34.94.250.90:37218] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "notify.ev.alitcogroup.com"] [uri "/.env.prod"] [unique_id "appxtKPMspfnfoulj3BHDgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
yvoictra
2026-09-04 06:36:35
(5 hours ago)
Bloqueado automáticamente por CrowdSec. Escenario: crowdsecurity/http-probing
Web App Attack