π³π±
homeshowdomain.nl
2026-10-02 21:59:36
(3 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-10-01.
show less
Web App Attack
SSH
Hacking
π§πͺ
cmbplf
2026-10-01 23:06:19
(4 days ago)
3.753 requests from abuseipdb.com blacklisted IP (1yr10mos3w)
Brute-Force
Bad Web Bot
π«π·
masterguru
2026-10-01 19:28:15
(5 days ago)
Restricted File Access Attempt. Matched phrase "config.json" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
π³π±
Savvii
2026-10-01 16:44:26
(5 days ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
πͺπΈ
robotstxt
2026-10-01 14:03:07
(5 days ago)
34.158.47.50 - - [01/Oct/2026:14:02:45 +0000] "GET //.env HTTP/2.0" 403 20 "-" rt="0.104" "Mozilla/5 ...
show more
34.158.47.50 - - [01/Oct/2026:14:02:45 +0000] "GET //.env HTTP/2.0" 403 20 "-" rt="0.104" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/)" "-" h="docs.robotstxt.es" sn="docs.robotstxt.es" ru="//.env" u="/index.php" ucs="-" ua="unix:/var/run/php/docs82.sock" us="301" uct="0.000" urt="0.103"
34.158.47.50 - - [01/Oct/2026:14:02:45 +0000] "GET /api/.env/public/.env HTTP/2.0" 403 10129 "-" rt="0.094" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)" "-" h="docs.robotstxt.es" sn="docs.robotstxt.es" ru="/api/.env/public/.env" u="/index.php" ucs="-" ua="unix:/var/run/php/docs82.sock" us="404" uct="0.000" urt="0.093"
34.158.47.50 - - [01/Oct/2026:14:02:45 +0000] "GET /%2eenv HTTP/2.0" 403 10129 "-" rt="0.094" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)" "-" h="docs.robotstxt.es" sn="docs.robotstxt.es" ru="/%2eenv" u="/index.php" ucs="-" ua="unix:/var/run/php/docs82.sock" us="404" uct="0.000" urt="0.094"
34.158.47.50 - - [01/Oct/2026:14:02:45 +0000]
...
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-01 13:46:46
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 34.158.47.50 (50.47.158.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.158.47.50 (50.47.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 09:46:40.420417 2026] [security2:error] [pid 17410:tid 17410] [client 34.158.47.50:56714] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||calogerolawfirm.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "calogerolawfirm.com"] [uri "/z9x8c7v6b5-debug-trigger-calogerolawfirm.com"] [unique_id "ar5kQDX2QoIFwM5tx1kjyQAAAC4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
thesimonmanuel
2026-10-01 13:30:59
(5 days ago)
34.158.47.50 - - [01/Oct/2026:19:00:58 +0530] "GET /openapi.json HTTP/2.0" 308 164 "-" "Mozilla/5.0 ...
show more
34.158.47.50 - - [01/Oct/2026:19:00:58 +0530] "GET /openapi.json HTTP/2.0" 308 164 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)" "-"
show less
Web App Attack
π©πͺ
palzer.IT
2026-10-01 12:55:20
(5 days ago)
Fail2ban automatic report for plesk-apache-badbot: 34.158.47.50 - - [01/Oct/2026:14:54:53 +0200] POS ...
show more
Fail2ban automatic report for plesk-apache-badbot: 34.158.47.50 - - [01/Oct/2026:14:54:53 +0200] POST / [DOMAIN_REMOVED] 200 5727 - Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; +claudebot@[DOMAIN_REMOVED])
show less
Bad Web Bot
Anonymous
2026-10-01 12:23:12
(5 days ago)
Portscan: TCP/8443 (5x), TCP/8080 (5x)
Port Scan
Anonymous
2026-10-01 11:45:02
(5 days ago)
suspicious request in access.log
Web App Attack
Anonymous
2026-10-01 11:30:05
(5 days ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection
π§πΎ
lns.bz
2026-10-01 11:23:20
(5 days ago)
.env scanning [BY]
Web App Attack
Anonymous
2026-10-01 10:45:03
(5 days ago)
Web application attack detected.
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-01 10:41:16
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.158.47.50 (50.47.158.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.158.47.50 (50.47.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 06:41:11.764233 2026] [security2:error] [pid 4696:tid 4703] [client 34.158.47.50:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.callaplusfirst.com"] [uri "/.env.dev"] [unique_id "ar44x0SBCH1PZtZYQCxcfgAAAEQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
dot.mg
2026-10-01 10:07:08
(5 days ago)
Scan of vulnerable files
Web App Attack