Anonymous
2026-09-06 16:08:17
(1 week ago)
Banned by Fail2Ban on server
Web App Attack
๐ฉ๐ช
ger-stg-sifi1
2026-09-06 14:46:51
(1 week ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-09-06 11:33:12
(1 week ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ฉ๐ช
Roper123
2026-09-06 08:21:19
(1 week ago)
Web exploits
Web App Attack
๐ฉ๐ช
LRob
2026-09-06 08:13:44
(1 week ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.git/config (+1 more) | 2026-09-06 08:13 UTC
show less
Hacking
Web App Attack
๐ฉ๐ช
Grossmann-Gruppe
2026-09-06 06:32:22
(1 week ago)
Plesk Fail2Ban: plesk-modsecurity
Hacking
Brute-Force
Anonymous
2026-09-06 06:13:54
(1 week ago)
Scan for .env Files at 2026-09-06T06:13:54+00:00
Web App Attack
๐จ๐ญ
๐จ๐ญ Hosting
2026-09-06 05:10:25
(1 week ago)
Automated WAF report: 200-300 blocked requests from this IP detected by our WAF.
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-06 04:21:55
(1 week ago)
Excessive multi-domain requests
Brute-Force
๐ช๐ธ
Francisco Vallejo
2026-09-06 03:39:53
(1 week ago)
[Sun Sep 06 05:39:52.931075 2026] [authz_core:error] [pid 2508885:tid 125407038785216] [client 34.18 ...
show more
[Sun Sep 06 05:39:52.931075 2026] [authz_core:error] [pid 2508885:tid 125407038785216] [client 34.18.126.143:46506] AH01630: client denied by server configuration: proxy:https://localhost:3000/
[Sun Sep 06 05:39:53.050929 2026] [authz_core:error] [pid 2508885:tid 125406661306048] [client 34.18.126.143:46506] AH01630: client denied by server configuration: proxy:https://localhost:3000/
[Sun Sep 06 05:39:53.204542 2026] [authz_core:error] [pid 2508885:tid 125406652913344] [client 34.18.126.143:46506] AH01630: client denied by server configuration: proxy:https://localhost:3000/
[Sun Sep 06 05:39:53.331868 2026] [authz_core:error] [pid 2508885:tid 125406644520640] [client 34.18.126.143:46506] AH01630: client denied by server configuration: proxy:https://localhost:3000/
[Sun Sep 06 05:39:53.451531 2026] [authz_core:error] [pid 2508885:tid 125407055570624] [client 34.18.126.143:46506] AH01630: client denied by server configuration: proxy:https://localhost:3000/.git/config
...
show less
Brute-Force
SSH
๐ซ๐ฎ
mnazibo
2026-09-06 03:15:12
(1 week ago)
Date: Sep 06 05:56:23 2026 EAT | Reported IP: 34.18.126.143 mod_security | id: 932130 932235 932260 ...
show more
Date: Sep 06 05:56:23 2026 EAT | Reported IP: 34.18.126.143 mod_security | id: 932130 932235 932260 933135 934100 934130 942151 942550 949110 930130 920440 920500 | QA/usernameab.my_domain/- | Connections: 1 | Blocked: Permanent Block: [LF_MODSEC] | Logs: ; Remote Command Execution: Unix Shell Expression Found; Remote Command Execution: Unix Command Injection (command without evasion); Remote Command Execution: Direct Unix Command Execution; PHP Injection Attack: Variable Access Found; Node.js Injection Attack 1/2; Node.js Injection Attack 1/2; Node.js Injection Attack 1/2; JavaScript Prototype Pollution; JavaScript Prototype Pollution; SQL Injection Attack: SQL function name detected; JSON-Based SQL Injection; Inbound Anomaly Score Exceeded (Total Score: 55); Restricted File Access Attempt; Remote Command Execution: Unix Shell Expression Found; Remote Command Execution: Unix Command Injection (command without evasion); Remote Command E
show less
SQL Injection
Brute-Force
Bad Web Bot
Anonymous
2026-09-06 02:12:22
(1 week ago)
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: QA, Attack patterns: Word ...
show more
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: QA, Attack patterns: WordPress scanning, Backup file probing, Cloud secrets probing
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
Dominik Lysiak
2026-09-06 01:03:59
(1 week ago)
34.18.126.143 - - [06/Sep/2026:03:03:59 +0200] "GET /.git/config HTTP/1.1" 302 57 "-" "Mozilla/5.0 ( ...
show more
34.18.126.143 - - [06/Sep/2026:03:03:59 +0200] "GET /.git/config HTTP/1.1" 302 57 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.18.126.143 - - [06/Sep/2026:03:03:59 +0200] "GET /.env HTTP/1.1" 302 48 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.18.126.143 - - [06/Sep/2026:03:03:59 +0200] "GET /.env.local HTTP/1.1" 302 54 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐ฌ๐ง
andypiper
2026-09-06 01:02:04
(1 week ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
๐ต๐ฑ
Budyn
2026-09-06 00:57:22
(1 week ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: grafana.budyn.wtf | URI: /.git/config | UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack