🇩🇪
loebas
2026-09-08 06:00:32
(17 hours ago)
[4xx]Probing for non existant files, or client not authorized
Hacking
Bad Web Bot
Web App Attack
🇮🇹
CoreTech srl
2026-09-08 01:48:56
(21 hours ago)
cloudlinux2 fail2ban: 2026-09-08 03:43:50,744 fail2ban.filter [1794]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-09-08 03:43:50,744 fail2ban.filter [1794]: INFO [plesk-wordpress] Found 141.98.143.170 - 2026-09-08 03:43:50cloudlinux2 fail2ban: 2026-09-08 03:44:14,373 fail2ban.filter [1794]: INFO [plesk-modsecurity] Found 34.125.223.14 - 2026-09-08 03:44:14cloudlinux2 fail2ban: 2026-09-08 03:44:13,683 fail2ban.filter [1794]: INFO [plesk-modsecurity] Found 34.125.223.14 - 2026-09-08 03:44:13cloudlinux2 fail2ban: 2026-09-08 03:44:14,057 fail2ban.filter [1794]: INFO [plesk-modsecurity] Found 34.125.223.14 - 2026-09-08 03:44:14cloudlinux2 fail2ban: 2026-09-08 03:44:14,480 fail2ban.actions [1794]: NOTICE [plesk-modsecurity] Ban 34.125.223.14cloudlinux2 fail2ban: 2026-09-08 03:44:14,212 fail2ban.filter [1794]: INFO [plesk-modsecurity] Found 34.125.223.14 - 2026-09-08 03:44:14cloudlinux2 fail2ban: 2026-09-08 03:44:14,487 fail2ban.filter [1794]: INFO [recidive] Found 34.125.223.14 - 2026-09-08 03:44:14cloudlinux2 fail2ban: 2026-09
show less
FTP Brute-Force
Web App Attack
🇩🇪
marten_o
2026-09-07 22:55:22
(1 day ago)
34.20.170.185 - - [08/Sep/2026:00:55:21 +0200] "GET /tmp/phpinfo.php HTTP/1.1" 404 236 "-" "Mozilla/ ...
show more
34.20.170.185 - - [08/Sep/2026:00:55:21 +0200] "GET /tmp/phpinfo.php HTTP/1.1" 404 236 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" 329 458
...
show less
Web App Attack
🇳🇱
Mangelot Hosting
2026-09-07 22:10:24
(1 day ago)
(modsecurity) srv103 ModSecurity 34.20.170.185 (US/United States/185.170.20.34.bc.googleusercontent. ...
show more
(modsecurity) srv103 ModSecurity 34.20.170.185 (US/United States/185.170.20.34.bc.googleusercontent.com): 30 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
🇨🇭
zynex
2026-09-07 20:04:39
(1 day ago)
URL Probing: /.env
Web App Attack
🇳🇱
Site.eu
2026-09-07 18:21:03
(1 day ago)
Excessive 404/403 errors
Brute-Force
🇩🇪
FeG Deutschland
2026-09-07 17:19:56
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
🇳🇱
Webhoster
2026-09-07 16:17:05
(1 day ago)
CrowdSec detected crowdsecurity/http-sensitive-files on a monitored service.
Web App Attack
🇳🇱
e.fierstra
2026-09-07 15:02:59
(1 day ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇩🇪
snhosting
2026-09-07 14:09:50
(1 day ago)
34.20.170.185 - - [07/Sep/2026:16:09:39 +0200] "GET /phpinfo.php HTTP/1.1" 404 836 "-" "Mozilla/5.0 ...
show more
34.20.170.185 - - [07/Sep/2026:16:09:39 +0200] "GET /phpinfo.php HTTP/1.1" 404 836 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.20.170.185 - - [07/Sep/2026:16:09:40 +0200] "GET /info.php HTTP/1.1" 404 836 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.20.170.185 - - [07/Sep/2026:16:09:40 +0200] "GET /php.php HTTP/1.1" 404 836 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.20.170.185 - - [07/Sep/2026:16:09:40 +0200] "GET /i.php HTTP/1.1" 404 836 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.20.170.185 - - [07/Sep/2026:16:09:40 +0200] "GET /pi.php HTTP/1.1" 404 836 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
DNS Compromise
DNS Poisoning
Phishing
Email Spam
Brute-Force
Web App Attack
SSH
🇺🇸
TPI-Abuse
2026-09-07 12:56:51
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.20.170.185 (185.170.20.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.20.170.185 (185.170.20.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 08:56:45.213076 2026] [security2:error] [pid 17414:tid 17414] [client 34.20.170.185:35782] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||link.rustyog.net|F|2"] [data ".env.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "link.rustyog.net"] [uri "/.env.bak"] [unique_id "ap60jf2kUCOVjWcI4AS8ywAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-07 12:16:10
(1 day ago)
Aggressive web scan
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-09-07 12:05:15
(1 day ago)
Scanning/Probing (13)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 10:38:40
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.20.170.185 (185.170.20.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.20.170.185 (185.170.20.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 06:38:34.099165 2026] [security2:error] [pid 20383:tid 20383] [client 34.20.170.185:50734] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "linzylyne.com"] [uri "/.git/config"] [unique_id "ap6UKlzU8hHEBSe0CvG3qAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 09:03:42
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.20.170.185 (185.170.20.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.20.170.185 (185.170.20.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 05:03:39.085864 2026] [security2:error] [pid 4788:tid 4788] [client 34.20.170.185:42216] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "linuxforpoets.com"] [uri "/.git/config"] [unique_id "ap5963zYlGrNu3UyUZa-WgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack