๐ณ๐ฑ
homeshowdomain.nl
2026-09-17 22:00:55
(1 day ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-16.
show less
Web App Attack
SSH
Hacking
๐ณ๐ฑ
Savvii
2026-09-16 05:11:52
(3 days ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 04:12:14
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.154.231.96 (96.231.154.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.154.231.96 (96.231.154.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 00:12:07.914788 2026] [security2:error] [pid 13151:tid 13151] [client 34.154.231.96:34528] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ambarsolar.com"] [uri "/.git/config"] [unique_id "aqoXFwiI8xdERP0IJKdvLQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-16 02:11:41
(3 days ago)
Automated web vulnerability and path enumeration scan with excessive 404 requests
Bad Web Bot
Web App Attack
Anonymous
2026-09-16 01:45:51
(3 days ago)
http scanning for .env files
...
Hacking
Web App Attack
๐ฉ๐ช
Hazzard
2026-09-15 10:18:42
(4 days ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-09-15 10:02:14
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.154.231.96 (96.231.154.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.154.231.96 (96.231.154.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 06:02:07.596711 2026] [security2:error] [pid 19222:tid 19222] [client 34.154.231.96:49796] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mta-sts.plugsinc.com"] [uri "/.git/config"] [unique_id "aqkXn53A-7ay_TfPZU011AAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
kosada.com
2026-09-15 10:01:23
(4 days ago)
Repeated exploit attempts, for example: /.env.staging /.env (HTTP/1.1 port 443, user agent: "Mozilla ...
show more
Repeated exploit attempts, for example: /.env.staging /.env (HTTP/1.1 port 443, user agent: "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36")
show less
Web App Attack
๐ฉ๐ช
Blexyel
2026-09-15 10:00:34
(4 days ago)
34.154.231.96 - - [15/Sep/2026:12:00:33 +0200] "GET /.git/config HTTP/1.1" 404 120 "-" "Mozilla/5.0 ...
show more
34.154.231.96 - - [15/Sep/2026:12:00:33 +0200] "GET /.git/config HTTP/1.1" 404 120 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Brute-Force
Web App Attack
๐ฉ๐ช
on-com
2026-09-15 09:45:25
(4 days ago)
URL scan
Brute-Force
Web App Attack
๐ธ๐ช
nekopavel
2026-09-15 09:30:48
(4 days ago)
34.154.231.96 - - [15/Sep/2026:11:30:46 +0200]"GET /.git/config HTTP/1.1" 404 178"-" mta-sts.neko.ch ...
show more
34.154.231.96 - - [15/Sep/2026:11:30:46 +0200]"GET /.git/config HTTP/1.1" 404 178"-" mta-sts.neko.chat "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36""0.000" "0.000""Milan" "IT"
34.154.231.96 - - [15/Sep/2026:11:30:47 +0200]"GET /.env HTTP/1.1" 404 178"-" mta-sts.neko.chat "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36""0.000" "0.000""Milan" "IT"
34.154.231.96 - - [15/Sep/2026:11:30:47 +0200]"GET /.env.local HTTP/1.1" 404 178"-" mta-sts.neko.chat "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36""0.001" "0.000""Milan" "IT"
...
show less
Hacking
Bad Web Bot
Web App Attack
๐ต๐ฑ
srebrakowski.com
2026-09-15 09:11:07
(4 days ago)
crowdsec/crowdsecurity/appsec-vpatch
Brute-Force
๐ต๐ฑ
maciejka
2026-09-15 08:51:34
(4 days ago)
34.154.231.96 - - [15/Sep/2026:10:51:34 +0200] "GET /mailer/.env HTTP/1.1" 404 189 "-" "Mozilla/5.0 ...
show more
34.154.231.96 - - [15/Sep/2026:10:51:34 +0200] "GET /mailer/.env HTTP/1.1" 404 189 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-"
34.154.231.96 - - [15/Sep/2026:10:51:34 +0200] "GET /mail/.env HTTP/1.1" 404 189 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-"
...
show less
Bad Web Bot
๐ฆ๐บ
Klaverstyn
2026-09-15 08:25:43
(4 days ago)
Excessive HTTP request rate
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-09-15 07:50:07
(4 days ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack