🇧🇷
Peregrine
2026-09-07 14:05:17
(34 minutes ago)
Fail2Ban Jail: tomcat-404 | Evidence: - 34.175.4.194 - - [07/Sep/2026:11:05:09 -0300] "GET /env HTTP ...
show more
Fail2Ban Jail: tomcat-404 | Evidence: - 34.175.4.194 - - [07/Sep/2026:11:05:09 -0300] "GET /env HTTP/1.1" 404 414
- 34.175.4.194 - - [07/Sep/2026:11:05:09 -0300] "GET /crusader-404-probe HTTP/1.1" 404 414
- 34.175.4.194 - - [07/Sep/2026:11:05:09 -0300] "GET /actuator/configprops HTTP/1.1" 404 414
- 34.175.4.194 - - [07/Sep/2026:11:05:09 -0300] "GET /wp-config.php.swp HTTP/1.1" 404 414
- 34.175.4.194 - - [07/Sep/2026:11:05:09 -0300] "GET /actuator/env HTTP/1.1" 404 414
- 34.175.4.194 - - [07/Sep/2026:11:05:09 -0300] "GET /wp-config.php~ HTTP/1.1" 404 414
- 34.175.4.194 - - [07/Sep/2026:11:05:09 -0300] "GET /_ignition/health-check HTTP/1.1" 404 414
- 34.175.4.194 - - [07/Sep/2026:11:05:09 -0300] "GET /storage/logs/laravel.log HTTP/1.1" 404 414
- 34.175.4.194 - - [07/Sep/2026:11:05:09 -0300] "GET /wp-config.php.bak HTTP/1.1" 404 414
show less
Bad Web Bot
Web App Attack
🇩🇪
Holger
2026-09-07 11:09:11
(3 hours ago)
URL probing: GET /.env.production
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 05:43:47
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.175.4.194 (194.4.175.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.175.4.194 (194.4.175.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 01:43:39.566443 2026] [security2:error] [pid 2956:tid 2956] [client 34.175.4.194:50510] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||harborcomputer.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "harborcomputer.com"] [uri "/data.sql"] [unique_id "apz9i9YhNYhxVOn6ynaSwQAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:50:52
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.175.4.194 (194.4.175.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.175.4.194 (194.4.175.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:50:44.777681 2026] [security2:error] [pid 17710:tid 17718] [client 34.175.4.194:54488] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.luckystonebeads.com"] [uri "/.env.prod"] [unique_id "apzjFOS0YOXFhsVTUqMC7gAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Stefan Dreher
2026-09-06 02:45:34
(1 day ago)
34.175.4.194 - - [06/Sep/2026:04:45:33 +0200] "GET /actuator/env HTTP/1.1" 404 153 "-" "crusader-wor ...
show more
34.175.4.194 - - [06/Sep/2026:04:45:33 +0200] "GET /actuator/env HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.175.4.194 - - [06/Sep/2026:04:45:33 +0200] "GET /actuator/configprops HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.175.4.194 - - [06/Sep/2026:04:45:33 +0200] "GET /wp-config.php~ HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.175.4.194 - - [06/Sep/2026:04:45:33 +0200] "GET /.env.save HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.175.4.194 - - [06/Sep/2026:04:45:33 +0200] "GET /.env.example HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
...
show less
Hacking
Brute-Force
🇸🇪
SkyDancer
2026-09-06 02:09:12
(1 day ago)
Multiple unauthorized attempts to access using wrong credentials. Attack automatically blocked by Sk ...
show more
Multiple unauthorized attempts to access using wrong credentials. Attack automatically blocked by SkyDancer Ai. EXT-SYS-Vx
show less
Hacking
Brute-Force
SSH
🇫🇷
dynamix
2026-09-06 01:35:22
(1 day ago)
Multiple WAF Violations
Web App Attack
🇩🇪
raph
2026-09-06 00:35:59
(1 day ago)
[Wordpress] crawler /wp-admin/*, /wp-content/*, etc.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 00:31:39
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.175.4.194 (194.4.175.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.175.4.194 (194.4.175.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:31:33.137766 2026] [security2:error] [pid 17484:tid 17484] [client 34.175.4.194:55176] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bluemarineboats.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bluemarineboats.com"] [uri "/storage/logs/laravel.log"] [unique_id "apy0ZQ2ML1M_J1DuVguwKQAAAGc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-06 00:20:59
(1 day ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
Anonymous
2026-09-05 23:55:04
(1 day ago)
suspicious request in access.log
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 23:53:39
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.175.4.194 (194.4.175.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.175.4.194 (194.4.175.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:53:32.552708 2026] [security2:error] [pid 26662:tid 26662] [client 34.175.4.194:42930] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.razeemco.com"] [uri "/.env.bak"] [unique_id "apyrfGMr-AtYnvejo1SL_QAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 22:59:26
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.175.4.194 (194.4.175.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.175.4.194 (194.4.175.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:59:18.821407 2026] [security2:error] [pid 7647:tid 7647] [client 34.175.4.194:45330] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||pixals.net|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "pixals.net"] [uri "/dump.sql"] [unique_id "apyexoK0Ru9v-HLN46WYCwAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
BlueWire Hosting
2026-09-05 22:45:41
(1 day ago)
High-confidence malicious configuration/VCS probe
Web App Attack
🇩🇪
FD-IX
2026-09-05 22:14:40
(1 day ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack