Anonymous
2026-10-10 20:28:02
(54 minutes ago)
WEB attack
Brute-Force
๐ฉ๐ช
neckaralb-admin.de
2026-10-10 19:47:23
(1 hour ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐ช๐ธ
robotstxt
2026-10-10 18:34:27
(2 hours ago)
34.12.113.64 - - [10/Oct/2026:18:34:05 +0000] "GET /public../.env HTTP/2.0" 403 189 "-" "Mozilla/5.0 ...
show more
34.12.113.64 - - [10/Oct/2026:18:34:05 +0000] "GET /public../.env HTTP/2.0" 403 189 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)" "-" edge="34.12.113.64"
34.12.113.64 - - [10/Oct/2026:18:34:05 +0000] "GET /static../.env HTTP/2.0" 403 189 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] )" "-" edge="34.12.113.64"
34.12.113.64 - - [10/Oct/2026:18:34:05 +0000] "GET /build../.env HTTP/2.0" 403 189 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)" "-" edge="34.12.113.64"
34.12.113.64 - - [10/Oct/2026:18:34:05 +0000] "GET /images../.env HTTP/2.0" 403 189 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )" "-" edge="34.12.113.64"
34.12.113.64 - - [10/Oct/2026:18:34:05 +0000] "GET /img../.env HTTP/2.0" 403 189 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)" "-" edge="34
...
show less
Web App Attack
Anonymous
2026-10-10 18:20:05
(3 hours ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection
๐ณ๐ฑ
Site.eu
2026-10-10 18:03:38
(3 hours ago)
Excessive multi-domain requests
Brute-Force
๐ณ๐ฑ
Alt255
2026-10-10 17:50:47
(3 hours ago)
[ti-04al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apac ...
show more
[ti-04al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apache-404. Example: 34.12.113.64 - - [10/Oct/2026:19:50:35 +0200] "GET /forgot-password HTTP/2.0" 404 1854 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Mobile Safari/537.36"
34.12.113.64 - - [10/Oct/2026:19:50:35 +0200] "GET /signin HTTP/2.0" 404 1854 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Mobile Safari/537.36"
34.12.113.64 - - [10/Oct/2026:19:50:35 +0200] "GET /secure HTTP/2.0" 404 1854 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Mobile Safari/537.36"
34.12.113.64 - - [10/Oct/2026:19:50:35 +0200] "GET /users/login HTTP/2.0" 404 1854 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-10 17:42:26
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.12.113.64 (64.113.12.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.12.113.64 (64.113.12.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 13:42:21.771109 2026] [security2:error] [pid 4877:tid 4877] [client 34.12.113.64:33838] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||tarekshohaieb.online|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "tarekshohaieb.online"] [uri "/rclone.conf"] [unique_id "asp4_U8UwAalDzcS81osrQAAAHU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Apache
2026-10-10 16:57:22
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.12.113.64 (64.113.12.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.12.113.64 (64.113.12.34.bc.googleusercontent.com): 5 in the last 300 secs
show less
Brute-Force
Web App Attack
๐ฎ๐น
VHosting
2026-10-10 16:55:04
(4 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-10-10 16:52:28
(4 hours ago)
excessive HTTP 404 errors
Bad Web Bot
๐ฌ๐ง
consul.to
2026-10-10 16:50:53
(4 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐ช๐ธ
arturotrenard
2026-10-10 16:38:07
(4 hours ago)
WordPress attack blocked (wp-defender): exploit-probe: https://cryptovibe.news/userfiles/x?path=..%2 ...
show more
WordPress attack blocked (wp-defender): exploit-probe: https://cryptovibe.news/userfiles/x?path=..%2F..%2F.env
show less
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-10-10 12:09:55
(9 hours ago)
csagent: score 23.7: 404 noise floor x15, secrets grab x2; 1 domain(s) in 5s
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-10 10:37:23
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.12.113.64 (64.113.12.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.12.113.64 (64.113.12.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 06:37:16.774536 2026] [security2:error] [pid 3894:tid 3894] [client 34.12.113.64:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.topbrand.co"] [uri "/media../.env"] [unique_id "asoVXBhsSvkUNzE7qD4JjgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-10 10:19:30
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.12.113.64 (64.113.12.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.12.113.64 (64.113.12.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 06:19:23.526324 2026] [security2:error] [pid 18967:tid 18972] [client 34.12.113.64:46560] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.nothingwithoutwater.co"] [uri "/appearance/../../.env"] [unique_id "asoRKzLG4FnvOtg1xiyT0QAAAUM"]
show less
Brute-Force
Bad Web Bot
Web App Attack