🇩🇪
FeG Deutschland
2026-09-09 12:23:33
(7 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
Anonymous
2026-09-09 10:23:41
(9 hours ago)
Aggressive web scan
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-09 08:12:48
(11 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
aks4226
2026-09-09 08:01:19
(11 hours ago)
Bot search, attacking common web applications.
Web App Attack
🇸🇪
vaia.cloud
2026-09-09 07:50:02
(11 hours ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
🇩🇪
MBombeck
2026-09-09 07:24:41
(12 hours ago)
Fail2Ban/traefik-botsearch on apps-01: banned after 5 failures
Web App Attack
🇺🇸
mnsf
2026-09-08 07:05:21
(1 day ago)
Abuse Detected (9)
Brute-Force
Web App Attack
🇩🇪
wpadm4
2026-09-08 06:26:02
(1 day ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇮🇳
evicky2002
2026-09-08 06:00:01
(1 day ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
🇺🇸
TPI-Abuse
2026-09-08 03:39:45
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.186.9.48 (48.9.186.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.186.9.48 (48.9.186.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 23:39:38.593106 2026] [security2:error] [pid 23115:tid 23115] [client 34.186.9.48:39382] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kountz.org"] [uri "/.git/config"] [unique_id "ap-DetuSdBH_QOlcHn2DtAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
dot.mg
2026-09-08 03:18:02
(1 day ago)
Bad behaviour
Web Spam
🇺🇸
TPI-Abuse
2026-09-08 02:34:27
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.186.9.48 (48.9.186.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.186.9.48 (48.9.186.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 22:34:20.673387 2026] [security2:error] [pid 1447793:tid 1447798] [client 34.186.9.48:45434] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "koublacat.com"] [uri "/.git/config"] [unique_id "ap90LC0ftCeS2e5Z6q3w-AAAAEI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇮
6kilowatti
2026-09-08 00:23:25
(1 day ago)
[08/Sep/2026:00:23:23 +0000] - 403 403 - GET https koti.6kw.fi "/.git/config" [Client 34.186.9.48] [ ...
show more
[08/Sep/2026:00:23:23 +0000] - 403 403 - GET https koti.6kw.fi "/.git/config" [Client 34.186.9.48] [Length 186] [Gzip -] [Sent-to 10.144.0.13] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-"
[08/Sep/2026:00:23:24 +0000] - 403 403 - GET https koti.6kw.fi "/.env" [Client 34.186.9.48] [Length 186] [Gzip -] [Sent-to 10.144.0.13] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-"
[08/Sep/2026:00:23:24 +0000] - 403 403 - GET https koti.6kw.fi "/.env.local" [Client 34.186.9.48] [Length 186] [Gzip -] [Sent-to 10.144.0.13] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-"
[08/Sep/2026:00:23:24 +0000] - 403 403 - GET https koti.6kw.fi "/.env.production" [Client 34.186.9.48] [Length 186] [Gzip -] [Sent-to 10.144.0.13] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-"
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 22:55:23
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.186.9.48 (48.9.186.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.186.9.48 (48.9.186.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 18:55:19.737812 2026] [security2:error] [pid 8555:tid 8555] [client 34.186.9.48:41734] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "koswerks.net"] [uri "/.git/config"] [unique_id "ap9A1wvfzx7kmLZPSj7z1wAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-07 22:07:22
(1 day ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack