๐ซ๐ท
Catalin Negru
2026-09-21 19:06:25
(1 day ago)
Recidive ban by fail2ban on server.blackbit.ro
Brute-Force
๐ง๐พ
lns.bz
2026-09-15 04:19:25
(1 week ago)
.env scanning [BY]
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 01:50:47
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.136.221.199 (199.221.136.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.136.221.199 (199.221.136.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 21:50:43.944228 2026] [security2:error] [pid 22965:tid 22965] [client 34.136.221.199:46158] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "a.hvacs-aircon.com"] [uri "/.git/config"] [unique_id "aqikcyeJJOeB1nW71TEpoQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Catalin Negru
2026-09-15 00:13:26
(1 week ago)
Recidive ban by fail2ban on server.blackbit.ro
Brute-Force
๐บ๐ธ
ipblock.com
2026-09-14 23:50:00
(1 week ago)
IPBlock protected site ID [4055-d][s=02].
Persistent 404, vulnerability scanner
Hacking
Bad Web Bot
Web App Attack
๐ฉ๐ช
Dominik Lysiak
2026-09-14 21:45:14
(1 week ago)
34.136.221.199 - - [14/Sep/2026:23:45:12 +0200] "GET /.git/config HTTP/1.1" 404 271 "-" "Mozilla/5.0 ...
show more
34.136.221.199 - - [14/Sep/2026:23:45:12 +0200] "GET /.git/config HTTP/1.1" 404 271 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.136.221.199 - - [14/Sep/2026:23:45:14 +0200] "GET /.env HTTP/1.1" 404 271 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.136.221.199 - - [14/Sep/2026:23:45:14 +0200] "GET /.env.local HTTP/1.1" 404 271 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Web App Attack
Anonymous
2026-09-14 17:02:53
(1 week ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-13 17:30:51
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.136.221.199 (199.221.136.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.136.221.199 (199.221.136.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 13:30:47.935198 2026] [security2:error] [pid 10929:tid 10929] [client 34.136.221.199:36896] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "86mountaineers.net"] [uri "/.git/config"] [unique_id "aqbdx4oRP3O5TAQAKM3srwAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
IndigoRidge
2026-09-13 14:48:17
(1 week ago)
[13/Sep/2026:10:48:16.220387 --0400] aqa3sOdp6rBJlmizyhrVUAAAAIs 34.136.221.199 36164 205.233.18.17 ...
show more
[13/Sep/2026:10:48:16.220387 --0400] aqa3sOdp6rBJlmizyhrVUAAAAIs 34.136.221.199 36164 205.233.18.17 7081
[13/Sep/2026:10:48:16.512401 --0400] aqa3sOdp6rBJlmizyhrVUgAAAIE 34.136.221.199 36188 205.233.18.17 7081
[13/Sep/2026:10:48:16.628851 --0400] aqa3sOdp6rBJlmizyhrVUwAAAIw 34.136.221.199 36190 205.233.18.17 7081
[13/Sep/2026:10:48:16.715006 --0400] aqa3sKATJCv4YF9TDBZQpAAAABA 34.136.221.199 36198 205.233.18.17 7081
[13/Sep/2026:10:48:16.848001 --0400] aqa3sOdp6rBJlmizyhrVVAAAAIo 34.136.221.199 36210 205.233.18.17 7081
...
show less
Hacking
Anonymous
2026-09-12 06:34:53
(1 week ago)
34.136.221.199 - - [12/Sep/2026:08:34:51 +0200] "POST / HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Macintos ...
show more
34.136.221.199 - - [12/Sep/2026:08:34:51 +0200] "POST / HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.136.221.199 - - [12/Sep/2026:08:34:51 +0200] "POST / HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.136.221.199 - - [12/Sep/2026:08:34:51 +0200] "POST / HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.136.221.199 - - [12/Sep/2026:08:34:51 +0200] "GET /.git/config HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.136.221.199 - - [12/Sep/2026:08:34:52 +0200] "GET /.env HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.3
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
WellSpring
2026-09-12 04:52:22
(1 week ago)
env leak on 325.today/public/.env โ WellSpr.ing/NetSentinel civic-AI security layer
Web App Attack
๐ท๐บ
themrdogs
2026-09-12 02:59:53
(1 week ago)
$f2bV_matches
Brute-Force
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-09-11 21:59:39
(1 week ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-10.
show less
Web App Attack
SSH
Hacking
๐ซ๐ท
Catalin Negru
2026-09-11 17:47:12
(1 week ago)
Recidive ban by fail2ban on server.blackbit.ro
Brute-Force
๐ฎ๐น
VHosting
2026-09-11 16:50:04
(1 week ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack