๐ง๐ช
taivas.nl
2026-09-19 13:02:11
(5 hours ago)
Bad_requests
Bad Web Bot
๐บ๐ธ
kosada.com
2026-09-19 12:54:45
(6 hours ago)
Repeated exploit attempts, for example: /.env.staging /.env (HTTP/1.1 port 443, user agent: "Mozilla ...
show more
Repeated exploit attempts, for example: /.env.staging /.env (HTTP/1.1 port 443, user agent: "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36")
show less
Web App Attack
๐ช๐ธ
robotstxt
2026-09-19 12:34:51
(6 hours ago)
34.97.214.110 - - [19/Sep/2026:12:33:49 +0000] "POST / HTTP/1.1" 403 31 "-" "Mozilla/5.0 (Windows NT ...
show more
34.97.214.110 - - [19/Sep/2026:12:33:49 +0000] "POST / HTTP/1.1" 403 31 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="34.97.214.110"
34.97.214.110 - - [19/Sep/2026:12:33:49 +0000] "POST / HTTP/1.1" 403 31 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="34.97.214.110"
34.97.214.110 - - [19/Sep/2026:12:33:50 +0000] "GET /.git/config HTTP/1.1" 403 31 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="34.97.214.110"
34.97.214.110 - - [19/Sep/2026:12:33:50 +0000] "GET /.env HTTP/1.1" 403 31 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="34.97.214.110"
34.97.214.110 - - [19/Sep/2026:12:33:51 +0000] "GET /.env.local HTTP/1.1" 403 31 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64)
...
show less
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-19 12:05:03
(6 hours ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
๐ซ๐ท
masterguru
2026-09-19 11:50:55
(7 hours ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-196)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-18 09:20:31
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.97.214.110 (110.214.97.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.97.214.110 (110.214.97.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 05:20:25.776136 2026] [security2:error] [pid 11590:tid 11590] [client 34.97.214.110:35628] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ww1.clcmillvale.com"] [uri "/.git/config"] [unique_id "aq0CWWprABoqlotGuUeGFgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-18 03:35:36
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.97.214.110 (110.214.97.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.97.214.110 (110.214.97.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 23:35:32.926389 2026] [security2:error] [pid 26439:tid 26439] [client 34.97.214.110:51690] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.4115.abecasis.com"] [uri "/.git/config"] [unique_id "aqyxhFk3VlVuyaOq4RWwuwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-18 03:15:36
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.97.214.110 (110.214.97.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.97.214.110 (110.214.97.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 23:15:33.051561 2026] [security2:error] [pid 24138:tid 24138] [client 34.97.214.110:56754] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.40svocaltrio.com.flashbackmusicmemories.com"] [uri "/.git/config"] [unique_id "aqys1TlwEpeH768KJxfQpAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-18 03:01:12
(1 day ago)
Bot / seems abusive / Apache connections: 25
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
๐ฌ๐ง
andypiper
2026-09-18 01:01:51
(1 day ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-09-18 00:51:47
(1 day ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ฉ๐ช
EGP Abuse Dept
2026-09-18 00:12:28
(1 day ago)
Scanning for web/db/file exploits on www.4-design.nl
SQL Injection
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-09-18 00:11:48
(1 day ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.git/config (+5 more) | 2026-09-18 00:11 UTC
show less
Hacking
Web App Attack
๐ช๐ธ
pipeline.es
2026-09-17 21:50:32
(1 day ago)
Web scanning / probing for vulnerable paths | URL: /.env.old | Evidence: 3tbooking.com 34.97.214.110 ...
show more
Web scanning / probing for vulnerable paths | URL: /.env.old | Evidence: 3tbooking.com 34.97.214.110 - - [17/Sep/2026:23:49:38 +0200] \"GET /.env.old HTTP/1.1\" 404 27551 \"-\" \"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36\" GEOIP_COUNTRY_CODE=JP | ASN: GOOGLE-CLOUD-PLATFORM | Country: JP
show less
Port Scan
Web App Attack
๐ฌ๐ง
poundawebsiteltd
2026-09-17 19:04:11
(1 day ago)
Malicious activity in general-malicious. Evidence: (apache_probe) Failed Access (403/404) 34.97.214. ...
show more
Malicious activity in general-malicious. Evidence: (apache_probe) Failed Access (403/404) 34.97.214.110 (JP/Japan/[REDACTED_DOMAIN]): 20 in the last 3600 secs | UA: (apache_probe) Failed Access (403/404) 34.97.214.110 (JP/Japan/110.214.97.34.bc.googleusercontent.com): 20 in the last 3600 secs
show less
Brute-Force
Web App Attack