Anonymous
2026-09-22 16:36:13
(22 hours ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
π³π±
Alt255
2026-09-20 23:39:56
(2 days ago)
[cb-05al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[cb-05al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.16.131.137 - - [21/Sep/2026:01:39:56 +0200] "GET /.git/config HTTP/1.1" 404 6850 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-20 23:26:21
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.16.131.137 (137.131.16.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.16.131.137 (137.131.16.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 19:26:18.858917 2026] [security2:error] [pid 32643:tid 32643] [client 34.16.131.137:34568] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "blue-attitude.net"] [uri "/.git/config"] [unique_id "arBrmtwg7JE82C69wDlxeAAAAEA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-20 23:08:54
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.16.131.137 (137.131.16.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.16.131.137 (137.131.16.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 19:08:50.211217 2026] [security2:error] [pid 5597:tid 5597] [client 34.16.131.137:50234] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "blublk.com"] [uri "/.git/config"] [unique_id "arBngiYlxmmgmbV7feiHAQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
middelkoopcc
2026-09-20 21:40:00
(2 days ago)
2026-09-20 23:38:13 GET /.git/config [301] && 2026-09-20 23:38:14 GET /.env [301] && 2026-09-20 23:3 ...
show more
2026-09-20 23:38:13 GET /.git/config [301] && 2026-09-20 23:38:14 GET /.env [301] && 2026-09-20 23:38:15 GET /.env.bak [301] && 230 more within 20 minutes
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-20 20:33:16
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.16.131.137 (137.131.16.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.16.131.137 (137.131.16.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 16:33:08.738906 2026] [security2:error] [pid 9554:tid 9554] [client 34.16.131.137:33500] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "blosoms.org"] [uri "/.git/config"] [unique_id "arBDBChtsrmGkYknaP3fzwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Savvii
2026-09-20 20:28:48
(2 days ago)
20 attempts against mh-misbehave-ban on ozone
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-20 18:38:18
(2 days ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
π³π±
e.fierstra
2026-09-20 16:17:49
(2 days ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
π©πͺ
todix
2026-09-20 15:41:36
(2 days ago)
Web App Attack Exploid from 34.16.131.137
Web App Attack
πΊπΈ
jormaster3k
2026-09-20 15:04:51
(3 days ago)
Attack against Apache (too many 404s)
Web App Attack
π©πͺ
Gwyneth Llewelyn
2026-09-20 14:35:41
(3 days ago)
2026/09/20 15:35:34 [error] 325888#325888: *759392 access forbidden by rule, client: 34.16.131.137, ...
show more
2026/09/20 15:35:34 [error] 325888#325888: *759392 access forbidden by rule, client: 34.16.131.137, server: betatechnologies.info, request: "GET /.env HTTP/2.0", host: "blogs.betatechnologies.info"
34.16.131.137 - - [20/Sep/2026:15:35:34 +0100] "GET /.env HTTP/2.0" 403 1045 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
2026/09/20 15:35:40 [error] 325888#325888: *759385 access forbidden by rule, client: 34.16.131.137, server: betatechnologies.info, request: "GET /app/.env HTTP/2.0", host: "blogs.betatechnologies.info"
show less
Brute-Force
Web App Attack
Anonymous
2026-09-20 13:46:55
(3 days ago)
34.16.131.137 - - [20/Sep/2026:10:46:54 -0300] "GET /.git/config HTTP/1.1" 301 162 "-" "Mozilla/5.0 ...
show more
34.16.131.137 - - [20/Sep/2026:10:46:54 -0300] "GET /.git/config HTTP/1.1" 301 162 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Port Scan
Hacking
SQL Injection
Brute-Force
Bad Web Bot
Exploited Host
π«π·
dynamix
2026-09-20 13:03:21
(3 days ago)
Multiple WAF Violations
Web App Attack
π³π±
tmiland
2026-09-20 13:02:04
(3 days ago)
Detected 164 connections from 34.16.131.137 last 10 minutes.; lone high-rate source (combined 328 re ...
show more
Detected 164 connections from 34.16.131.137 last 10 minutes.; lone high-rate source (combined 328 requests in both windows); Logs: 34.16.131.137 - - [20/Sep/2026:15:01:39 +0200] "GET / HTTP/1.1" 502 3281 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" 34.16.131.137 - - [20/Sep/2026:15:01:39 +0200] "POST / HTTP/1.1" 502 3281 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" 34.16.131.137 - - [20/Sep/2026:15:01:39 +0200] "POST / HTTP/1.1" 502 3281 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" 34.16.131.137 - - [20/Sep/2026:15:01:39 +0200] "POST / HTTP/1.1" 502 3281 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" 34.16.131.137 - - [20/Sep/2026:15:01:39 +0200] "GET /.git/config HTTP/1.1" 502 3281 "-" "Mozilla/
show less
DDoS Attack
Bad Web Bot
Web App Attack