ππΊ
miszterx.hu
2026-09-18 08:04:59
(2 days ago)
XORP (haproxy): 106x HTTP 404/403/500 or handshake failure in 24h. Automated report from log_check_i ...
show more
XORP (haproxy): 106x HTTP 404/403/500 or handshake failure in 24h. Automated report from log_check_iptables_generator.sh (xorp.hu)
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-18 07:31:43
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.151.171.104 (104.171.151.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.151.171.104 (104.171.151.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 03:31:40.403847 2026] [security2:error] [pid 25664:tid 25664] [client 34.151.171.104:39716] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "altermondo.com"] [uri "/.git/config"] [unique_id "aqzo3GVvg6ETTDMd6iLeQAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
maza
2026-09-18 07:30:58
(2 days ago)
Malicious activity detected from 396982 Google LLC towards host alterminds.xyz (POST HTTP/1.1) @ 20 ...
show more
Malicious activity detected from 396982 Google LLC towards host alterminds.xyz (POST HTTP/1.1) @ 2026-09-18T07:30:58Z
show less
Open Proxy
VPN IP
Port Scan
Hacking
SQL Injection
Bad Web Bot
Exploited Host
Web App Attack
πΊπΈ
Major Hostility
2026-09-18 06:04:44
(2 days ago)
"GET /.git/config HTTP/1.1" 404
"GET /.env HTTP/1.1" 404
"GET /.env.local HTTP/1.1" 404
"GET /.env.p ...
show more
"GET /.git/config HTTP/1.1" 404
"GET /.env HTTP/1.1" 404
"GET /.env.local HTTP/1.1" 404
"GET /.env.production HTTP/1.1" 404
show less
Web App Attack
π©πͺ
FeG Deutschland
2026-09-18 05:52:23
(2 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 27
Exploited Host
Web App Attack
Anonymous
2026-09-17 19:39:45
(3 days ago)
(mod_security) mod_security triggered on hostname [redacted] 34.151.171.104 (AU/Australia/104.171.15 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.151.171.104 (AU/Australia/104.171.151.34.bc.googleusercontent.com)
show less
SQL Injection
π³π±
Site.eu
2026-09-17 18:24:45
(3 days ago)
Excessive multi-domain requests
Brute-Force
πΊπΈ
TPI-Abuse
2026-09-17 14:29:41
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.151.171.104 (104.171.151.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.151.171.104 (104.171.151.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 10:29:33.440670 2026] [security2:error] [pid 10949:tid 10949] [client 34.151.171.104:49672] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aiamur.com.aiamur.photo"] [uri "/.git/config"] [unique_id "aqv5TZLrJ4GMfEfRlGVX8AAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΈπͺ
vaia.cloud
2026-09-17 14:10:01
(3 days ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
π³π±
Site.eu
2026-09-17 11:49:10
(3 days ago)
Excessive 404/403 errors
Brute-Force
πΊπΈ
xxkodedxx
2026-09-17 10:41:21
(3 days ago)
[Zorvexus edge-defense] GET .env / WordPress honeypot probe
Trigger: 1Γ honeypot-get, 2Γ edge-block ...
show more
[Zorvexus edge-defense] GET .env / WordPress honeypot probe
Trigger: 1Γ honeypot-get, 2Γ edge-block in 10m window.
Origin: AU / AS396982 Google LLC
Active: 10:40:29β10:40:50 UTC
Volume: 68 HTTP req, 6 honeypot probe(s)
Bait taken: /wp-admin/phpinfo.php, /credentials.json, /service-account.json, /.env.production, /.env.local
Status mix: 200Γ62 405Γ4 444Γ2
UA: "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
Auto-banned 30d. zorvexus-banner.
show less
Bad Web Bot
Web App Attack
πͺπΈ
robotstxt
2026-09-16 20:54:13
(4 days ago)
34.151.171.104 - - [16/Sep/2026:20:54:08 +0000] "GET /.env HTTP/1.1" 403 208 "-" "Mozilla/5.0 (Windo ...
show more
34.151.171.104 - - [16/Sep/2026:20:54:08 +0000] "GET /.env HTTP/1.1" 403 208 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="34.151.171.104"
34.151.171.104 - - [16/Sep/2026:20:54:08 +0000] "GET /.env.local HTTP/1.1" 403 208 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="34.151.171.104"
34.151.171.104 - - [16/Sep/2026:20:54:08 +0000] "GET /.env.production HTTP/1.1" 403 208 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="34.151.171.104"
34.151.171.104 - - [16/Sep/2026:20:54:09 +0000] "GET /.env.staging HTTP/1.1" 403 208 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="34.151.171.104"
34.151.171.104 - - [16/Sep/2026:20:54:09 +0000] "GET /.env.development HTTP/1.1" 403 208 "-
...
show less
Web App Attack
π¦πΊ
KevinNeale
2026-09-16 18:14:18
(4 days ago)
Fail2Ban recidive block for repeated malicious authentication attempts.
Brute-Force
Web App Attack
Anonymous
2026-09-16 16:17:23
(4 days ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
π«π·
dynamix
2026-09-16 15:40:43
(4 days ago)
Multiple WAF Violations
Web App Attack