π§π·
Peregrine
2026-06-10 03:13:56
(23 hours ago)
Fail2Ban ct101 Jail: tomcat-honeypot | Evidence: - 34.179.236.31 - - [07/Jun/2026:22:52:27 -0300] "G ...
show more
Fail2Ban ct101 Jail: tomcat-honeypot | Evidence: - 34.179.236.31 - - [07/Jun/2026:22:52:27 -0300] "GET /.git/config HTTP/1.1" 404 18193
show less
Bad Web Bot
π¨π¦
lakered
2026-06-10 00:30:05
(1 day ago)
Detectors: [CROWDSEC] | Reasons: CrowdSec: Reconnaissance scan | Tech Evidence: JA4H: 4f9228cd43b6fc ...
show more
Detectors: [CROWDSEC] | Reasons: CrowdSec: Reconnaissance scan | Tech Evidence: JA4H: 4f9228cd43b6fc61dd53816d23304059, Minimal-Browser-Profile, Lazy-Header-Accept, Fake-Chrome-Desktop (No-CH), JA4: t13d1315h2 | UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36
show less
Port Scan
Web App Attack
π³π±
homeshowdomain.nl
2026-06-09 22:03:47
(1 day ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-06-08.
show less
Web App Attack
SSH
Hacking
π§π·
Peregrine
2026-06-09 03:13:54
(1 day ago)
Fail2Ban ct101 Jail: tomcat-honeypot | Evidence: - 34.179.236.31 - - [07/Jun/2026:22:52:27 -0300] "G ...
show more
Fail2Ban ct101 Jail: tomcat-honeypot | Evidence: - 34.179.236.31 - - [07/Jun/2026:22:52:27 -0300] "GET /.git/config HTTP/1.1" 404 18193
show less
Bad Web Bot
π¨π
TheCoon
2026-06-09 01:30:01
(2 days ago)
Automated: Credential theft attempt - JSON bomb served
Web App Attack
Hacking
π¬π§
AvonleaConsulting
2026-06-08 22:59:31
(2 days ago)
Attempts to probe web pages for vulnerable PHP or other applications
Web App Attack
π³π±
homeshowdomain.nl
2026-06-08 22:08:13
(2 days ago)
Auto-ban: >3000 req/min op 2026-06-08
Web App Attack
SSH
Hacking
Anonymous
2026-06-08 21:18:10
(2 days ago)
34.179.236.31 - - [08/Jun/2026:21:18:09 +0000] "GET /.git/config HTTP/1.1" 404 49870 "-" "Mozilla/5. ...
show more
34.179.236.31 - - [08/Jun/2026:21:18:09 +0000] "GET /.git/config HTTP/1.1" 404 49870 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3804.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
π·πΊ
6o6ep
2026-06-08 21:10:57
(2 days ago)
connection via IP or to a non-existent subdomain: GET /.git/config HTTP/1.1
Port Scan
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-08 21:08:23
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.179.236.31 (31.236.179.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.179.236.31 (31.236.179.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 17:08:16.195125 2026] [security2:error] [pid 3226:tid 3226] [client 34.179.236.31:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.wiszen.org"] [uri "/.git/config"] [unique_id "aicvQFwMgnZIdQKojRa4PwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-08 20:53:05
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.179.236.31 (31.236.179.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.179.236.31 (31.236.179.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 16:52:58.776799 2026] [security2:error] [pid 14772:tid 14772] [client 34.179.236.31:42184] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.amgstone.38floorsupply.com"] [uri "/.git/config"] [unique_id "aicrqnhEpBn6bRrca7N7vQAAACw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-08 19:57:23
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.179.236.31 (31.236.179.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.179.236.31 (31.236.179.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 15:57:16.332210 2026] [security2:error] [pid 10654:tid 10654] [client 34.179.236.31:51230] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.littlestarbookspub.com.flashbackmusicmemories.com"] [uri "/.git/config"] [unique_id "aicenL0YlFzQE9gNN2sGPAAAADs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-08 19:18:57
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.179.236.31 (31.236.179.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.179.236.31 (31.236.179.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 15:18:51.456600 2026] [security2:error] [pid 31317:tid 31317] [client 34.179.236.31:55616] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kaleidoscopeglassworks.kaleidoscope-glass.com"] [uri "/.git/config"] [unique_id "aicVmwZIy4MvT9IIgniYVQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
thetomtaylor.co.uk
2026-06-08 16:07:01
(2 days ago)
Fail2Ban - [WEB]Custom exploit pattern detected on customexploits ... [ice01,wa01,wa02]
Hacking
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
ghostwarriors
2026-06-08 15:20:26
(2 days ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack