Anonymous
2026-09-03 10:30:24
(28 minutes ago)
Fail2Ban: repeated malicious HTTP requests (path probing / exploit attempts) against a public web se ...
show more
Fail2Ban: repeated malicious HTTP requests (path probing / exploit attempts) against a public web server.
show less
Web App Attack
Bad Web Bot
🇺🇸
mnsf
2026-09-01 22:05:13
(1 day ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
🇳🇱
homeshowdomain.nl
2026-09-01 22:00:21
(1 day ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-08-31.
show less
Web App Attack
SSH
Hacking
🇮🇪
AutosOnShow
2026-09-01 13:27:04
(1 day ago)
blocked for webapp attack | path requested: / | seen at 2026-09-01 13:26:38.452 |
Web App Attack
🇺🇸
TPI-Abuse
2026-09-01 12:33:15
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.106.104.218 (218.104.106.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.104.218 (218.104.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 08:33:09.490001 2026] [security2:error] [pid 22238:tid 22268] [client 34.106.104.218:55256] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "chanyin.org"] [uri "/.env.old"] [unique_id "apbGBRMcZO0zCjph-eG0ewAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-01 12:05:27
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.106.104.218 (218.104.106.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.106.104.218 (218.104.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 08:05:24.446838 2026] [security2:error] [pid 16854:tid 16854] [client 34.106.104.218:47532] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||dental.veneerdent.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "dental.veneerdent.com"] [uri "/storage/logs/laravel.log"] [unique_id "apa_hPavzZ-OqIN3UDYyVAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Marc
2026-09-01 11:21:59
(1 day ago)
34.106.104.218 - - [01/Sep/2026:13:21:58 +0200] "GET /wp-config.php~ HTTP/1.1" 404 4618 "-" "crusade ...
show more
34.106.104.218 - - [01/Sep/2026:13:21:58 +0200] "GET /wp-config.php~ HTTP/1.1" 404 4618 "-" "crusader-worker/1.0" 34.106.104.218 - - [01/Sep/2026:13:21:58 +0200] "GET /crusader-404-probe HTTP/1.1" 404 4617 "-" "crusader-worker/1.0" 34.106.104.218 - - [01/Sep/2026:13:21:58 +0200] "GET /.env.local HTTP/1.1" 404 4617 "-" "crusader-worker/1.0"
show less
Brute-Force
🇺🇸
TPI-Abuse
2026-09-01 10:58:30
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.106.104.218 (218.104.106.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.104.218 (218.104.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 06:58:21.703672 2026] [security2:error] [pid 15182:tid 15182] [client 34.106.104.218:40030] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.linhsbridal.com"] [uri "/wp-config.php.swp"] [unique_id "apavzQsrFKx0BTooQ31WgwAAADk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-01 10:19:30
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.106.104.218 (218.104.106.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.104.218 (218.104.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 06:19:25.488166 2026] [security2:error] [pid 6190:tid 6190] [client 34.106.104.218:46060] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "acquivest.net"] [uri "/.env.old"] [unique_id "apamrVs-Fv9dY_QM23lNfwAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-01 09:59:26
(2 days ago)
Web attack/malicious scanning detected
Web App Attack
🇫🇷
Flo Flo
2026-09-01 09:57:39
(2 days ago)
34.106.104.218 - - - [01/Sep/2026:11:57:38 +0200] "flad.xyz" "GET /actuator/configprops HTTP/1.1" 44 ...
show more
34.106.104.218 - - - [01/Sep/2026:11:57:38 +0200] "flad.xyz" "GET /actuator/configprops HTTP/1.1" 444 0 "-" "crusader-worker/1.0" 0.000
...
show less
Web App Attack
🇫🇷
masterguru
2026-09-01 09:43:46
(2 days ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.106.104.218 (US/United States/218. ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.106.104.218 (US/United States/218.104.106.34.bc.googleusercontent.com): 2 in the last 3600 secs (0-196)
show less
Hacking
🇺🇸
TPI-Abuse
2026-09-01 09:23:17
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.106.104.218 (218.104.106.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.104.218 (218.104.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 05:23:11.140812 2026] [security2:error] [pid 21282:tid 21282] [client 34.106.104.218:53700] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "constructionloansfunding.com"] [uri "/.env.local"] [unique_id "apaZf_E9HDo3zlQO3gh4ywAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇭
zynex
2026-09-01 09:17:57
(2 days ago)
URL Probing: /.env
Web App Attack
🇩🇪
FD-IX
2026-09-01 08:27:23
(2 days ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack