Anonymous
2026-09-16 09:27:48
(11 minutes ago)
Banned by Fail2Ban on server
Web App Attack
Anonymous
2026-09-16 09:20:03
(19 minutes ago)
suspicious request in access.log
Web App Attack
๐ซ๐ฎ
mnazibo
2026-09-16 08:00:08
(1 hour ago)
Date: 16/Sep/2026 10:35:25 | Reported IP: 34.150.36.198 mod_security | id: 930130 932130 932235 9322 ...
show more
Date: 16/Sep/2026 10:35:25 | Reported IP: 34.150.36.198 mod_security | id: 930130 932130 932235 932260 933135 934100 934130 942151 942550 | HK/group.my_domain/- | Connections: 162 | Blocked: Permanent Block: [LF_MODSEC] | URIs: /admin/.env; /administrator/.env; /admin/phpinfo.php; /api/.env; /api/v1/.env; /api/v2/.env; /app/.env; /apps/.env; /backend/.env; /backup/.env; /backups/.env; /brevo/.env; /build/.env; /bulk/.env; /campaign/.env; /client/.env; /cms/.env; /config/.env; /core/app/.env; /core/Database/.env; /core/.env; /cpanel/phpinfo.php; /crm/.env; /cron/.env; /cronlab/.env; /current/.env; /dashboard/.env; /database/.env; /deploy/.env; /dev/.env; /dev/phpinfo.php; /dist/.env; /drupal/.env; /email/.env; /en/.env; /.env~; /.env.backup; /.env.bak; /.env.ci; /.env.dev; /.env.development; /.env.dist; /.env.docker; /.env.example; /.env.live; /.env.local; /.env.old; /.env.preprod; /.env.prod; /.env.production; /.env.remote; /.env.sample
show less
SQL Injection
Brute-Force
Bad Web Bot
๐ธ๐ช
vaia.cloud
2026-09-16 07:55:03
(1 hour ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 05:56:32
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.150.36.198 (198.36.150.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.150.36.198 (198.36.150.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 01:56:26.450004 2026] [security2:error] [pid 4230:tid 4230] [client 34.150.36.198:43558] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.wiro.am.greighhouse.com"] [uri "/.git/config"] [unique_id "aqovirPMhmLylAcTDYwz4gAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
rh24
2026-09-16 05:39:34
(4 hours ago)
34.150.36.198 (HK/Hong Kong/198.36.150.34.bc.googleusercontent.com), more than 25 Apache 403 hits
Hacking
๐ฆ๐บ
Klaverstyn
2026-09-16 04:40:01
(4 hours ago)
Cross-vhost secrets/RCE probing campaign
Web App Attack
Hacking
๐ฉ๐ช
ghostwarriors
2026-09-16 03:50:09
(5 hours ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-16 03:50:03
(5 hours ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
๐ฉ๐ช
yitzhaq
2026-09-16 03:27:28
(6 hours ago)
34.150.36.198 - - [16/Sep/2026:05:27:23 +0200] "GET /.env HTTP/1.1" 404 513 "-" "Mozilla/5.0 (X11; L ...
show more
34.150.36.198 - - [16/Sep/2026:05:27:23 +0200] "GET /.env HTTP/1.1" 404 513 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.150.36.198 - - [16/Sep/2026:05:27:24 +0200] "GET /.env.local HTTP/1.1" 404 513 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.150.36.198 - - [16/Sep/2026:05:27:24 +0200] "GET /.env.production HTTP/1.1" 404 513 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.150.36.198 - - [16/Sep/2026:05:27:24 +0200] "GET /.env.staging HTTP/1.1" 404 513 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.150.36.198 - - [16/Sep/2026:05:27:24 +0200] "GET /.env.development HTTP/1.1" 404 513 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.150.36.198 - - [16/Sep/2026:05:27:24 +02
show less
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-16 03:20:03
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.150.36.198 (198.36.150.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.150.36.198 (198.36.150.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 23:19:54.822869 2026] [security2:error] [pid 18242:tid 18242] [client 34.150.36.198:40020] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.winwin.albionglobalmarketing.com"] [uri "/.git/config"] [unique_id "aqoK2qkqpBxxRUz9ns28vAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
melroy89
2026-09-16 02:35:41
(7 hours ago)
34.150.36.198 - - [16/Sep/2026:04:34:40 +0200] "GET /phpinfo.php HTTP/1.1" 403 524 "-" "Mozilla/5.0 ...
show more
34.150.36.198 - - [16/Sep/2026:04:34:40 +0200] "GET /phpinfo.php HTTP/1.1" 403 524 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "softstack.biz" 0.000
34.150.36.198 - - [16/Sep/2026:04:34:40 +0200] "GET /info.php HTTP/1.1" 403 524 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "softstack.biz" 0.001
34.150.36.198 - - [16/Sep/2026:04:34:41 +0200] "GET /php.php HTTP/1.1" 403 524 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "softstack.biz" 0.000
34.150.36.198 - - [16/Sep/2026:04:34:41 +0200] "GET /i.php HTTP/1.1" 403 524 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "softstack.biz" 0.000
34.150.36.198 - - [16/Sep/2026:04:34:41 +0200] "GET /pi.php HTTP/1.1" 403 524 "-" "Mozilla/5.0 (Windows NT 10.0; Win
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 19:48:32
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.150.36.198 (198.36.150.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.150.36.198 (198.36.150.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 15:48:24.203624 2026] [security2:error] [pid 4721:tid 4721] [client 34.150.36.198:52002] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.winestoria.vittariadesign.com"] [uri "/.git/config"] [unique_id "aqmhCFOkQ660RnZz4IC31wAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 18:02:37
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.150.36.198 (198.36.150.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.150.36.198 (198.36.150.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 14:02:33.420404 2026] [security2:error] [pid 3162:tid 3162] [client 34.150.36.198:58500] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.windsorhills.iainrealtor.com"] [uri "/.git/config"] [unique_id "aqmIORL-RrNKpKn3qxtRVQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-15 10:48:44
(22 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking