๐ฉ๐ช
Skyrider
2026-09-29 20:19:30
(2 days ago)
Nginx: HTTP 4xx probe/scan attempts. Automated fail2ban report.
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-09-29 08:05:16
(2 days ago)
Abuse Detected (11)
Brute-Force
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-29 06:50:03
(2 days ago)
Excessive multi-domain requests
Brute-Force
๐ฌ๐ง
andypiper
2026-09-29 01:01:28
(3 days ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
๐ฉ๐ช
Skyrider
2026-09-29 00:14:06
(3 days ago)
crowdsecurity/http-sensitive-files
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-27 16:09:30
(4 days ago)
Excessive multi-domain requests
Brute-Force
๐ณ๐ฑ
Alt255
2026-09-27 08:12:20
(4 days ago)
[cb-04al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail ngin ...
show more
[cb-04al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail nginx-404. Example: 34.158.197.222 - - [27/Sep/2026:10:11:14 +0200] "GET /phpinfo.php HTTP/1.0" 404 165578 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.158.197.222 - - [27/Sep/2026:10:11:17 +0200] "GET /info.php HTTP/1.0" 404 165553 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.158.197.222 - - [27/Sep/2026:10:11:19 +0200] "GET /php.php HTTP/1.0" 404 165534 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.158.197.222 - - [27/Sep/2026:10:11:22 +0200] "GET /i.php HTTP/1.0" 404 165528 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) C
...
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-27 05:34:51
(4 days ago)
[ti-03ov] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-03ov] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.158.197.222 - - [27/Sep/2026:07:34:33 +0200] "GET /.git/config HTTP/1.1" 301 546 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-27 01:32:43
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.158.197.222 (222.197.158.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.158.197.222 (222.197.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 21:32:38.341522 2026] [security2:error] [pid 31129:tid 31129] [client 34.158.197.222:54754] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.marriedtv.com.whoore.com"] [uri "/.git/config"] [unique_id "arhyNqcTaCVR5Ou98FmEKQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Gwyneth Llewelyn
2026-09-27 00:28:07
(5 days ago)
34.158.197.222 - - [27/Sep/2026:01:28:04 +0100] "GET /.env HTTP/2.0" 301 162 "-" "Mozilla/5.0 (Macin ...
show more
34.158.197.222 - - [27/Sep/2026:01:28:04 +0100] "GET /.env HTTP/2.0" 301 162 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
2026/09/27 01:28:05 [error] 2462#2462: *157750 access forbidden by rule, client: 34.158.197.222, server: mar.pt, request: "GET /.env HTTP/2.0", host: "mar.pt"
34.158.197.222 - - [27/Sep/2026:01:28:05 +0100] "GET /.env HTTP/2.0" 403 1045 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
show less
Brute-Force
Web App Attack
๐ฌ๐ง
consul.to
2026-09-26 23:32:07
(5 days ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-26 17:05:04
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 34.158.197.222 (222.197.158.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.158.197.222 (222.197.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 13:04:57.283189 2026] [security2:error] [pid 14093:tid 14093] [client 34.158.197.222:33064] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.industrialdatasystems.net.samelsner.com|F|2"] [data ".env.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.industrialdatasystems.net.samelsner.com"] [uri "/.env.bak"] [unique_id "arf7OcfGKRXZLLRAAPSPCQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-26 16:34:51
(5 days ago)
Aggressive web scan
Web App Attack
๐ฉ๐ช
raph
2026-09-26 16:25:07
(5 days ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
Anonymous
2026-09-26 11:30:03
(5 days ago)
CrowdSec decision: crowdsecurity/http-admin-interface-probing (origin: crowdsec)
Web App Attack