Anonymous
2026-09-17 17:12:26
(20 hours ago)
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: IL, Attack patterns: Word ...
show more
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: IL, Attack patterns: WordPress scanning, Backup file probing, Cloud secrets probing
show less
Bad Web Bot
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-09-17 12:11:19
(1 day ago)
csagent: score 19.9: secrets grab x2; 1 domain(s) in 1s
Web App Attack
๐ช๐ธ
robotstxt
2026-09-17 02:29:02
(1 day ago)
34.165.242.121 - - [17/Sep/2026:02:28:50 +0000] "GET /.env HTTP/1.1" 403 25845 "-" "Mozilla/5.0 (X11 ...
show more
34.165.242.121 - - [17/Sep/2026:02:28:50 +0000] "GET /.env HTTP/1.1" 403 25845 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="34.165.242.121"
34.165.242.121 - - [17/Sep/2026:02:28:50 +0000] "GET /.env.local HTTP/1.1" 403 25845 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="34.165.242.121"
34.165.242.121 - - [17/Sep/2026:02:28:50 +0000] "GET /.env.production HTTP/1.1" 403 25845 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="34.165.242.121"
34.165.242.121 - - [17/Sep/2026:02:28:50 +0000] "GET /.env.staging HTTP/1.1" 403 25845 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="34.165.242.121"
34.165.242.121 - - [17/Sep/2026:02:28:51 +0000] "GET /.env.development HTTP/1.1" 403 25845 "-" "Mozilla/5.0 (X11; Linux x86
...
show less
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-16 16:40:18
(1 day ago)
Excessive 404/403 errors
Brute-Force
Anonymous
2026-09-16 16:21:48
(1 day ago)
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: IL, Attack patterns: Word ...
show more
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: IL, Attack patterns: WordPress scanning, Backup file probing, Cloud secrets probing
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-09-16 16:17:44
(1 day ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.git/config (+15 more) | 2026-09-16 16:17 UTC
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 15:41:02
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.165.242.121 (121.242.165.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.165.242.121 (121.242.165.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 11:40:55.810212 2026] [security2:error] [pid 32561:tid 32561] [client 34.165.242.121:52690] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "chandlerowen.com"] [uri "/.git/config"] [unique_id "aqq4h3qf6Z7fAhM1lGqQowAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-16 15:14:55
(1 day ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐ซ๐ท
Hippoline
2026-09-16 15:00:25
(1 day ago)
[Wed Sep 16 17:00:14.790146 2026] [authz_core:error] [pid 7196] [client 34.165.242.121:52454] AH0163 ...
show more
[Wed Sep 16 17:00:14.790146 2026] [authz_core:error] [pid 7196] [client 34.165.242.121:52454] AH01630: client denied by server configuration: /var/www/championat.lu/web/cakephp
[Wed Sep 16 17:00:24.589830 2026] [authz_core:error] [pid 3082] [client 34.165.242.121:48842] AH01630: client denied by server configuration: /var/www/championat.lu/web/phpinfo.php
[Wed Sep 16 17:00:24.664144 2026] [authz_core:error] [pid 3082] [client 34.165.242.121:48842] AH01630: client denied by server configuration: /var/www/championat.lu/web/info.php
[Wed Sep 16 17:00:24.736477 2026] [authz_core:error] [pid 3082] [client 34.165.242.121:48842] AH01630: client denied by server configuration: /var/www/championat.lu/web/php.php
[Wed Sep 16 17:00:24.805006 2026] [authz_core:error] [pid 3082] [client 34.165.242.121:48842] AH01630: client denied by server configuration: /var/www/championat.lu/web/i.php
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
9LEVEL.com.br
2026-09-16 14:54:44
(1 day ago)
Blocked by Fail2ban for traefik-404 abuse
Web App Attack
๐ฌ๐ง
consul.to
2026-09-16 14:46:59
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
๐ซ๐ท
dynamix
2026-09-16 14:33:48
(1 day ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-09-16 14:15:01
(1 day ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 13:42:57
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.165.242.121 (121.242.165.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.165.242.121 (121.242.165.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 09:42:54.421908 2026] [security2:error] [pid 17877:tid 17877] [client 34.165.242.121:48102] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "chalet-4saisons.com"] [uri "/.git/config"] [unique_id "aqqc3oJtD1ZXWm9GZCKsWQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 13:22:59
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.165.242.121 (121.242.165.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.165.242.121 (121.242.165.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 09:22:55.763018 2026] [security2:error] [pid 12134:tid 12134] [client 34.165.242.121:33598] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "chaire-construction-4-0.com"] [uri "/.git/config"] [unique_id "aqqYLxx0NjG44N8pehCgPQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack