๐ณ๐ฑ
JCB
2026-09-01 22:04:00
(23 hours ago)
8.234.106.104 - - [01/Sep/2026:12:46:46 +0300] "GET /.env.save HTTP/1.1" 403 239 "-" "crusader-worke ...
show more
8.234.106.104 - - [01/Sep/2026:12:46:46 +0300] "GET /.env.save HTTP/1.1" 403 239 "-" "crusader-worker/1.0"
8.234.106.104 - - [01/Sep/2026:12:46:46 +0300] "GET /.env.prod HTTP/1.1" 403 239 "-" "crusader-worker/1.0"
...
show less
Web App Attack
Hacking
๐ณ๐ฑ
homeshowdomain.nl
2026-09-01 22:00:38
(23 hours ago)
Auto-ban: >3000 req/min op 2026-09-01
Web App Attack
SSH
Hacking
Anonymous
2026-09-01 13:53:00
(1 day ago)
Spring.Boot.Actuator.Unauthorized.Access
Hacking
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-01 09:39:14
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐ต๐ฑ
TaKeN
2026-09-01 08:40:44
(1 day ago)
Automated Wazuh local observation. Wazuh rule 31151 lvl=10 detected repeated HTTP web application pr ...
show more
Automated Wazuh local observation. Wazuh rule 31151 lvl=10 detected repeated HTTP web application probing from this source IP. Observed 1 matching blocked event(s) between 2026-09-01T10:40:44+02:00 and 2026-09-01T10:40:44+02:00. Sample requested paths: /actuator/configprops.
show less
Web App Attack
Hacking
๐ฎ๐น
CoreTech srl
2026-09-01 08:38:56
(1 day ago)
cloudlinux2 fail2ban: 2026-09-01 10:33:56,450 fail2ban.filter [1605]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-01 10:33:56,450 fail2ban.filter [1605]: INFO [plesk-modsecurity] Found 8.234.106.104 - 2026-09-01 10:33:56cloudlinux2 fail2ban: 2026-09-01 10:33:56,425 fail2ban.filter [1605]: INFO [plesk-modsecurity] Found 8.234.106.104 - 2026-09-01 10:33:56cloudlinux2 fail2ban: 2026-09-01 10:33:56,442 fail2ban.filter [1605]: INFO [plesk-modsecurity] Found 8.234.106.104 - 2026-09-01 10:33:56cloudlinux2 fail2ban: 2026-09-01 10:33:56,465 fail2ban.filter [1605]: INFO [plesk-modsecurity] Found 8.234.106.104 - 2026-09-01 10:33:56cloudlinux2 fail2ban: 2026-09-01 10:33:56,433 fail2ban.filter [1605]: INFO [plesk-modsecurity] Found 8.234.106.104 - 2026-09-01 10:33:56cloudlinux2 fail2ban: 2026-09-01 10:33:56,497 fail2ban.filter [1605]: INFO [plesk-modsecurity] Found 8.234.106.104 - 2026-09-01 10:33:56cloudlinux2 fail2ban: 2026-09-01 10:33:56,505 fail2ban.filter [1605]: INFO [plesk-modsecurity] Found 8.234.106.104 - 2026-09-01 10:
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-01 06:29:07
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 8.234.106.104 (104.106.234.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.234.106.104 (104.106.234.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 02:29:00.804135 2026] [security2:error] [pid 9152:tid 9152] [client 8.234.106.104:60768] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stellwagenmusic.com"] [uri "/.env.save"] [unique_id "apZwrJZlC_eCn8jaHGLG0AAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 05:07:15
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 8.234.106.104 (104.106.234.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.234.106.104 (104.106.234.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 01:07:09.076474 2026] [security2:error] [pid 31146:tid 31146] [client 8.234.106.104:49248] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.hatfieldborodems.com"] [uri "/wp-config.php.bak"] [unique_id "apZdfTm-2iQWLoN6gdu7AAAAADk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-09-01 05:06:11
(1 day ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-09-01 04:22:05
(1 day ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ฉ๐ฐ
HostingGroup
2026-09-01 03:36:53
(1 day ago)
Automated malicious activity (Honeypot Trap) detected and blocked at the CDN edge by NordicCDN Shiel ...
show more
Automated malicious activity (Honeypot Trap) detected and blocked at the CDN edge by NordicCDN Shield. Offenses: 2. First blocked: 2026-09-01.
show less
Bad Web Bot
Web App Attack
๐จ๐ฟ
ddw
2026-09-01 03:17:00
(1 day ago)
Multiple ModSecurity detections - Rules: 920440(URL file extension is restricted by policy), 930130( ...
show more
Multiple ModSecurity detections - Rules: 920440(URL file extension is restricted by policy), 930130(Restricted File Access Attempt), 930130(Restricted File Access Attempt)
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 03:08:21
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 8.234.106.104 (104.106.234.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.234.106.104 (104.106.234.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 23:08:16.784303 2026] [security2:error] [pid 77434:tid 77454] [client 8.234.106.104:43006] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pacific-medical.com.fevini.com"] [uri "/.env"] [unique_id "apZBoO0wKU5I3u64y8c6xQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-01 02:58:26
(1 day ago)
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .back/ .b ...
show more
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .back/ .backup/ .bak/ .bck/ .bk/ .bkp/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .cnf/ .com/ .compositefont/ .config/ .conf/ .copy/ .crt/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dist/ .dll/ .dos/ .dpkg-dist/ .drv/ .gadget/ .hta/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .inf/ .ini/ .jks/ .jse/ .key/ .licx/ .lnk/ .log/ .mdb/ .msc/ .ocx/ .old/ .pass/ .pdb/ .pfx/ .pif/ .pem/ .pol/ .prf/ .printer/ .pwd/ .rdb/ .rdp/ .reg/ .resources/ .resx/ .sav/ .save/ .scr/ .sct/ .sh/ .shs/ .sql/ .sqlite/ .sqlite3/ .swap/ .swo/ .swp/ .sys/ .temp/ .tfstate/ .tlb/ .tmp/ .vb/ .vbe/ .vbs/ .vbproj/ .vsdisco/ .vxd/ .webinfo/ .ws/ .wsc/ .wsf/ .wsh/ .xsd/ .xsx/" at TX:extension. (920440-201)
show less
Hacking
๐น๐ท
pashait
2026-09-01 02:54:40
(1 day ago)
Auto-blocked by Seczar SecureOps โ IPS Web Attack Signature (1 events in 5min) at 2026-09-01 02:54
Web App Attack
Bad Web Bot