🇩🇪
Savvii
2026-08-31 02:41:49
(2 hours ago)
20 attempts against mh-misbehave-ban on heat
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-31 01:34:25
(3 hours ago)
SIEM ALERT AUTO REPORT
Email Spam
🇺🇸
TPI-Abuse
2026-08-30 11:40:08
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.138.14.43 (43.14.138.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.138.14.43 (43.14.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 07:40:00.852518 2026] [security2:error] [pid 7140:tid 7140] [client 34.138.14.43:17836] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.88"] [uri "/static../.env"] [unique_id "apQWkPUyOFb54-scQrgFsQAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇨
ACE-INFORMATIQUE.NC
2026-08-30 06:00:04
(22 hours ago)
Malicious CGI/web attack blocked by Fail2ban
Web App Attack
🇮🇹
mgarofano80
2026-08-30 05:41:12
(23 hours ago)
Brute-Force
Web App Attack
🇳🇱
Savvii
2026-08-30 05:21:56
(23 hours ago)
20 attempts against mh-misbehave-ban on jva-jammy-dev
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-30 04:29:43
(1 day ago)
Path traversal /etc/passwd attempts + .env/credential probing - blocked by FortiGate IPS (Generic.Pa ...
show more
Path traversal /etc/passwd attempts + .env/credential probing - blocked by FortiGate IPS (Generic.Path.Traversal.Detection)
show less
Web App Attack
🇵🇱
Wepted
2026-08-30 00:36:20
(1 day ago)
Port scan detected by honeypot
Port Scan
Hacking
🇺🇸
TPI-Abuse
2026-08-29 15:51:32
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.138.14.43 (43.14.138.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.138.14.43 (43.14.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 11:51:25.317623 2026] [security2:error] [pid 1481:tid 1481] [client 34.138.14.43:14238] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.38"] [uri "/static../.env"] [unique_id "apL__RUZYUa1qiMkLug8vQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
xmission.com
2026-08-29 15:44:08
(1 day ago)
Blocked by UFW (TCP on 8443)
Source port: 9988
TTL: 60
Packet length: 60
TOS: 0x00
This report (for ...
show more
Blocked by UFW (TCP on 8443)
Source port: 9988
TTL: 60
Packet length: 60
TOS: 0x00
This report (for 34.138.14.43) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
🇺🇸
TPI-Abuse
2026-08-29 12:17:24
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.138.14.43 (43.14.138.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.138.14.43 (43.14.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 08:17:17.333295 2026] [security2:error] [pid 25333:tid 25333] [client 34.138.14.43:20906] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.75"] [uri "/static../.env"] [unique_id "apLNzSDaPpMg1EcCzhqFqgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇩
Antasena
2026-08-29 11:10:26
(1 day ago)
Triggered IDS Description:Sensitive Configuration File Probe from 34.138.14.43 | src_ip: 34.138.14.4 ...
show more
Triggered IDS Description:Sensitive Configuration File Probe from 34.138.14.43 | src_ip: 34.138.14.43 | Path: static../.env
show less
Web App Attack
🇳🇿
Antinson
2026-08-29 10:22:11
(1 day ago)
Scraping with a high error ratio and request rate
Bad Web Bot
🇺🇸
TPI-Abuse
2026-08-29 07:33:28
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.138.14.43 (43.14.138.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.138.14.43 (43.14.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 03:33:20.862703 2026] [security2:error] [pid 27107:tid 27107] [client 34.138.14.43:5952] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.53"] [uri "/static../.env"] [unique_id "apKLQJf-x_wfDU8xLGqfbgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇾
lns.bz
2026-08-29 06:04:55
(1 day ago)
.env scanning [BY]
Web App Attack