๐ง๐ท
radardatelecom
2026-09-30 22:26:03
(6 days ago)
Blocked by Radar da Telecom firewall โ abuseipdb
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-09-30 22:01:34
(6 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-29.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
interbiznw.com
2026-09-30 02:46:14
(1 week ago)
malicious-web-requests-vulnerability-scanning
Hacking
Brute-Force
Exploited Host
Web App Attack
๐ฉ๐ช
altenglaner
2026-09-30 02:18:16
(1 week ago)
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show more
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
Hacking
Web App Attack
๐บ๐ธ
agenciahypelab.com.br
2026-09-30 02:11:22
(1 week ago)
WordPress login brute-force detectado e bloqueado pelo CSF/LFD. Trigger: LF_TRIGGER
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-09-30 01:02:41
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 34.186.196.50 (50.196.186.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.186.196.50 (50.196.186.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 21:02:34.173522 2026] [security2:error] [pid 19899:tid 19899] [client 34.186.196.50:49122] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.powdercoatovens.net.daveweisman.com|F|2"] [data ".powdercoatovens.net.daveweisman.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.powdercoatovens.net.daveweisman.com"] [uri "/z9x8c7v6b5-debug-trigger-www.powdercoatovens.net.daveweisman.com"] [unique_id "arxfqglDvRBRGtcTIMttBQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-09-30 00:37:32
(1 week ago)
116 requests with url.path */proc/*
Brute-Force
Bad Web Bot
๐ณ๐ฑ
Alt255
2026-09-29 23:51:37
(1 week ago)
[ti-12al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 34. ...
show more
[ti-12al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 34.186.196.50 - - \[30/Sep/2026:01:51:24 +0200\] "GET /userfiles\?path=../../.env HTTP/2.0" 404 1863 "-" "Mozilla/5.0 \(Macintosh\; Intel Mac OS X 10_15_7\) AppleWebKit/605.1.15 \(KHTML, like Gecko\) Version/17.0 Safari/605.1.15 \(Applebot/0.1\)"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 23:03:07
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.186.196.50 (50.196.186.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.186.196.50 (50.196.186.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 19:03:04.274148 2026] [security2:error] [pid 9899:tid 10048] [client 34.186.196.50:33448] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.poeticdialogues.wizart.org"] [uri "/.env"] [unique_id "arxDqLjD7-oPOcKDwwGhKwAAAVE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 21:15:09
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.186.196.50 (50.196.186.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.186.196.50 (50.196.186.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 17:15:02.988977 2026] [security2:error] [pid 18450:tid 18450] [client 34.186.196.50:45250] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ichi51e.net"] [uri "/.env.bak"] [unique_id "arwqViknd9ahzOLC65EN-wAAADk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-29 20:58:03
(1 week ago)
[ti-02ov] Excessive 404 errors (web scanning): 28 suspicious requests detected by fail2ban jail apac ...
show more
[ti-02ov] Excessive 404 errors (web scanning): 28 suspicious requests detected by fail2ban jail apache-404. Example: 34.186.196.50 - - [29/Sep/2026:22:57:56 +0200] "GET /einz5rhh31qiyh6ja8y9 HTTP/2.0" 404 2004 "-" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)"
34.186.196.50 - - [29/Sep/2026:22:57:56 +0200] "GET /dxur0rca4rufw8gvuiap HTTP/2.0" 404 2004 "-" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)"
34.186.196.50 - - [29/Sep/2026:22:57:56 +0200] "POST /graphql HTTP/2.0" 404 2004 "https://elearning.ppinternationalbv.nl" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Mobile Safari/537.36"
34.186.196.50 - - [29/Sep/2026:22:57:56 +0200] "GET /api/v1/env HTTP/2.0" 404 2004 "-" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/)"
02.overtheweb.n
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-29 19:47:57
(1 week ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐ซ๐ท
COMAITE
2026-09-29 19:36:51
(1 week ago)
Suspicious URL access.
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-09-29 19:35:31
(1 week ago)
Try to access /.env.js
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-29 19:33:59
(1 week ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack