π³π±
Alt255
2026-09-21 00:31:50
(3 hours ago)
[ti-02ov] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-02ov] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.18.225.65 - - [21/Sep/2026:02:31:30 +0200] "GET /.git/config HTTP/1.1" 301 645 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
π¬π·
setupgr
2026-09-20 22:15:50
(5 hours ago)
(mod_security) mod_security (id:11000011) triggered by 34.18.225.65 (QA/Qatar/Baladiyat ad Dawhah/Do ...
show more
(mod_security) mod_security (id:11000011) triggered by 34.18.225.65 (QA/Qatar/Baladiyat ad Dawhah/Doha/-/[AS396982 Google LLC]): 1 in the last 86400 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Mon Sep 21 01:15:46.779106 2026] [security2:error] [pid 1025452:tid 1025598] [client 34.18.225.65:44978] ModSecurity: Access denied with code 406 (phase 1). Matched phrase "googleusercontent.com" at REMOTE_HOST. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "141"] [id "11000011"] [msg "BLOCKED BAD DOMAIN: 65.225.18.34.bc.googleusercontent.com"] [severity "CRITICAL"] [hostname "gyrosplace.gr"] [uri "/"] [unique_id "arBbEuQC6XCKgzUquGHYPQAAAxU"]
show less
Port Scan
π«π·
dynamix
2026-09-20 22:09:39
(5 hours ago)
Multiple WAF Violations
Web App Attack
πΊπΈ
Epimetheus
2026-09-20 21:36:34
(6 hours ago)
Unauthorized access attempts:
[GET] /google-key.json
[GET] /firebase-adminsdk.json
[GET] /gcp-sa.js ...
show more
Unauthorized access attempts:
[GET] /google-key.json
[GET] /firebase-adminsdk.json
[GET] /gcp-sa.json
[GET] /phpinfo.php.old
[GET] /pinfo.php
[GET] /info
[GET] /info.php
[GET] /job/.env
[GET] /k8s/.env
[GET] /gcp/.env
[GET] /uploads/.env
[GET] /api/v2/.env
[GET] /opt/.env
[GET] /storage/.env
[GET] /deploy/.env
[GET] /var/www/.env
[GET] /current/.env
[GET] /.env.ci
UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
show less
Web App Attack
π©πͺ
filstal.org
2026-09-20 20:59:29
(6 hours ago)
Web reconnaissance detected: automated probing for sensitive files, backup archives, admin panels an ...
show more
Web reconnaissance detected: automated probing for sensitive files, backup archives, admin panels and known vulnerability paths.
show less
Hacking
Brute-Force
Web App Attack
Anonymous
2026-09-20 20:00:09
(7 hours ago)
| [Dangerous/Qatar] Aggressive IP 34.18.225.65 (~30 hits). Type: DoS Defender- Web server 400 error ...
show more
| [Dangerous/Qatar] Aggressive IP 34.18.225.65 (~30 hits). Type: DoS Defender- Web server 400 error code
show less
Web App Attack
Hacking
SQL Injection
Anonymous
2026-09-20 18:58:06
(8 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
πΈπͺ
vaia.cloud
2026-09-20 18:10:02
(9 hours ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
π³π±
Site.eu
2026-09-20 16:08:34
(11 hours ago)
Excessive 404/403 errors
Brute-Force
π©πͺ
Gwyneth Llewelyn
2026-09-20 13:17:52
(14 hours ago)
2026/09/20 14:17:41 [error] 325888#325888: *744134 access forbidden by rule, client: 34.18.225.65, s ...
show more
2026/09/20 14:17:41 [error] 325888#325888: *744134 access forbidden by rule, client: 34.18.225.65, server: gwynethllewelyn.net, request: "GET /.env HTTP/2.0", host: "gwynethllewelyn.net"
34.18.225.65 - - [20/Sep/2026:14:17:41 +0100] "GET /.env HTTP/2.0" 403 1048 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
2026/09/20 14:17:50 [error] 325888#325888: *744182 access forbidden by rule, client: 34.18.225.65, server: gwynethllewelyn.net, request: "GET /app/.env HTTP/2.0", host: "gwynethllewelyn.net"
show less
Brute-Force
Web App Attack