π©πͺ
ghostwarriors
2026-10-05 19:50:04
(4 hours ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
π©πͺ
Gwyneth Llewelyn
2026-10-05 05:14:00
(18 hours ago)
2026/10/05 06:13:58 [error] 3069275#3069275: *147718 access forbidden by rule, client: 34.151.237.12 ...
show more
2026/10/05 06:13:58 [error] 3069275#3069275: *147718 access forbidden by rule, client: 34.151.237.12, server: api.betatechnologies.info, request: "GET /api/.env/public/.env HTTP/2.0", host: "api.betatechnologies.info"
2026/10/05 06:13:58 [error] 3069275#3069275: *147721 access forbidden by rule, client: 34.151.237.12, server: api.betatechnologies.info, request: "GET /assets../.env HTTP/2.0", host: "api.betatechnologies.info"
2026/10/05 06:13:58 [error] 3069277#3069277: *147714 access forbidden by rule, client: 34.151.237.12, server: api.betatechnologies.info, request: "GET /images../.env HTTP/2.0", host: "api.betatechnologies.info"
show less
Brute-Force
Web App Attack
π«π·
Lunix
2026-10-05 04:39:11
(19 hours ago)
Brute-Force
Web App Attack
π³π±
Alt255
2026-10-05 04:20:21
(19 hours ago)
[ti-07al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-07al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.151.237.12 - - [05/Oct/2026:06:20:00 +0200] "GET /files../.env HTTP/1.1" 404 2050 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)"
...
show less
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-05 02:58:53
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.151.237.12 (12.237.151.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.151.237.12 (12.237.151.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 22:58:48.236434 2026] [security2:error] [pid 12445:tid 12445] [client 34.151.237.12:55302] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wildemar.info"] [uri "/.htpasswd"] [unique_id "asMSaHJwjquH65YISGuzKQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
masterguru
2026-10-05 02:38:09
(21 hours ago)
BAD BOT - Detected and Blocked.. Matched phrase "baidu" at REQUEST_HEADERS:user-agent. (1100000-135)
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-10-05 02:35:15
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.151.237.12 (12.237.151.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.151.237.12 (12.237.151.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 22:35:12.371644 2026] [security2:error] [pid 8523:tid 8523] [client 34.151.237.12:55002] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sheldondesigns.info"] [uri "/.htpasswd"] [unique_id "asMM4BaPAm-YOg5h2jVciAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
enpepet
2026-10-05 02:23:42
(21 hours ago)
GENERAL: parametres: [url:env=] UA:Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/) URL:/doc ...
show more
GENERAL: parametres: [url:env=] UA:Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/) URL:/docker/.env
show less
Port Scan
Hacking
Brute-Force
Bad Web Bot
π©πͺ
Petros Stefanakis
2026-10-05 02:21:13
(21 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.151.237.12 (BR/Brazil/12.237.151.34. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.151.237.12 (BR/Brazil/12.237.151.34.bc.googleusercontent.com)
show less
SQL Injection
πΊπΈ
TPI-Abuse
2026-10-05 02:16:23
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.151.237.12 (12.237.151.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.151.237.12 (12.237.151.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 22:16:18.360068 2026] [security2:error] [pid 4697:tid 4697] [client 34.151.237.12:58064] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "oss-in-atm.info"] [uri "/%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env"] [unique_id "asMIcp_bqD6UZXDXL4fWKQAAACo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
β¨
2026-10-05 02:10:08
(22 hours ago)
Domain : musicdna.info
Rule : config
2026-10-05 02:08:58 W3SVC385 PLESK72 79.171.34.85 GET /.vite/ma ...
show more
Domain : musicdna.info
Rule : config
2026-10-05 02:08:58 W3SVC385 PLESK72 79.171.34.85 GET /.vite/manifest.json - 80 - 34.151.237.12 HTTP/1.1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 Edg/153.0.0.0 - - musicdna.info 404 0 2 1529 830 198 - -
show less
Hacking
SQL Injection
π©πͺ
ger-stg-sifi1
2026-10-05 02:09:06
(22 hours ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-05 01:51:30
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.151.237.12 (12.237.151.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.151.237.12 (12.237.151.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 21:51:27.135589 2026] [security2:error] [pid 15557:tid 15557] [client 34.151.237.12:59086] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "marat.info"] [uri "/css../.env"] [unique_id "asMCnw5COONKZ5zNfWEqlgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-05 01:04:02
(23 hours ago)
Portscan: TCP/8443 (5x), TCP/8080 (5x)
Port Scan
Anonymous
2026-10-05 01:03:49
(23 hours ago)
[Mon Oct 05 03:03:43.764215 2026] [authz_core:error] [pid 1899143:tid 1899143] [client 34.151.237.12 ...
show more
[Mon Oct 05 03:03:43.764215 2026] [authz_core:error] [pid 1899143:tid 1899143] [client 34.151.237.12:0] AH01630: client denied by server configuration: /var/www/wordpress/loretlargent.info/server-status, referer: https://loretlargent.info/server-status
[Mon Oct 05 03:03:45.572587 2026] [access_compat:error] [pid 1899160:tid 1899160] [client 34.151.237.12:0] AH01797: client denied by server configuration: /var/www/wordpress/loretlargent.info/.dockerenv, referer: https://loretlargent.info/.dockerenv
[Mon Oct 05 03:03:46.136520 2026] [access_compat:error] [pid 1899159:tid 1899159] [client 34.151.237.12:0] AH01797: client denied by server configuration: /var/www/wordpress/loretlargent.info/.aws, referer: https://loretlargent.info/.aws/credentials
[Mon Oct 05 03:03:46.291055 2026] [access_compat:error] [pid 1899160:tid 1899160] [client 34.151.237.12:0] AH01797: client denied by server configuration: /var/www/wordpress/loretlargent.info/.aws, referer: https://loretlargent.info/.aws/config
[M
...
show less
Web Spam
Web App Attack