Anonymous
2026-09-07 04:06:21
(1 hour ago)
Banned by Fail2Ban on server
Web App Attack
🇩🇪
ghostwarriors
2026-09-07 03:50:05
(1 hour ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
🇩🇪
yitzhaq
2026-09-07 03:37:13
(2 hours ago)
34.18.216.28 - - [07/Sep/2026:05:37:09 +0200] "GET /.env.sample HTTP/1.1" 404 511 "-" "Mozilla/5.0 ( ...
show more
34.18.216.28 - - [07/Sep/2026:05:37:09 +0200] "GET /.env.sample HTTP/1.1" 404 511 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.18.216.28 - - [07/Sep/2026:05:37:09 +0200] "GET /.env.example HTTP/1.1" 404 511 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.18.216.28 - - [07/Sep/2026:05:37:09 +0200] "GET /.env.dev HTTP/1.1" 404 511 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.18.216.28 - - [07/Sep/2026:05:37:09 +0200] "GET /.env.prod HTTP/1.1" 404 511 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.18.216.28 - - [07/Sep/2026:05:37:10 +0200] "GET /.env.stage HTTP/1.1" 404 511 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.18.216.28 - - [07/Sep/2026:05:37:10 +0200] "GET /.en
show less
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-07 01:46:31
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.18.216.28 (28.216.18.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.18.216.28 (28.216.18.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 21:46:24.464740 2026] [security2:error] [pid 902:tid 902] [client 34.18.216.28:60370] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hotglassgallery.com"] [uri "/.git/config"] [unique_id "ap4XcFhGbxI1LuFX-533bgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
cmbplf
2026-09-07 01:01:32
(4 hours ago)
48.562 requests in 1 hour (3mos2d16h)
Brute-Force
Bad Web Bot
🇪🇸
alferez
2026-09-07 00:33:06
(5 hours ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack
🇮🇹
CoreTech srl
2026-09-07 00:13:57
(5 hours ago)
cloudlinux2 fail2ban: 2026-09-07 02:09:48,098 fail2ban.filter [2048]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-07 02:09:48,098 fail2ban.filter [2048]: INFO [plesk-modsecurity] Found 34.18.216.28 - 2026-09-07 02:09:48cloudlinux2 fail2ban: 2026-09-07 02:09:49,758 fail2ban.filter [2048]: INFO [plesk-modsecurity] Found 34.18.216.28 - 2026-09-07 02:09:49cloudlinux2 fail2ban: 2026-09-07 02:09:49,730 fail2ban.filter [2048]: INFO [plesk-modsecurity] Found 34.18.216.28 - 2026-09-07 02:09:49cloudlinux2 fail2ban: 2026-09-07 02:09:49,713 fail2ban.filter [2048]: INFO [plesk-modsecurity] Found 34.18.216.28 - 2026-09-07 02:09:49cloudlinux2 fail2ban: 2026-09-07 02:09:49,854 fail2ban.actions [2048]: NOTICE [plesk-modsecurity] Ban 34.18.216.28cloudlinux2 fail2ban: 2026-09-07 02:09:49,738 fail2ban.filter [2048]: INFO [plesk-modsecurity] Found 34.18.216.28 - 2026-09-07 02:09:49cloudlinux2 fail2ban: 2026-09-07 02:09:49,848 fail2ban.filter [2048]: INFO [plesk-modsecurity] Found 34.18.216.28 - 2026-09-07 02:09:49cloudlinux2 fail2ban: 2026
show less
Web App Attack
🇬🇧
Aetherweb Ark
2026-09-06 21:24:31
(8 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.18.216.28 (QA/Qatar/28.216.18.34.bc.googleus ...
show more
(mod_security) mod_security (id:949110) triggered by 34.18.216.28 (QA/Qatar/28.216.18.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 21:04:22
(8 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.18.216.28 (28.216.18.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:949110) triggered by 34.18.216.28 (28.216.18.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 17:04:18.649295 2026] [security2:error] [pid 24352:tid 24352] [client 34.18.216.28:33822] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "hotelrevabookings.com.hamiltonbookings.com"] [uri "/.git/config"] [unique_id "ap3VUtd2weXBk0HRXaOycgAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 19:31:51
(10 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 18:10:41
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.18.216.28 (28.216.18.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.18.216.28 (28.216.18.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 14:10:37.760003 2026] [security2:error] [pid 862:tid 862] [client 34.18.216.28:51106] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hotelkona.com"] [uri "/.git/config"] [unique_id "ap2snbRM5EQpB1_k5akC3QAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 17:40:20
(12 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
Anonymous
2026-09-06 17:33:18
(12 hours ago)
Multiple web server 400 error codes from same source ip
Web App Attack
🇳🇱
Site.eu
2026-09-06 17:09:05
(12 hours ago)
Excessive multi-domain requests
Brute-Force
🇩🇪
paissangroup
2026-09-06 16:45:47
(12 hours ago)
Multiple WAF Violations
Web App Attack