๐บ๐ธ
TPI-Abuse
2026-09-25 13:23:00
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.21.228.2 (2.228.21.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.21.228.2 (2.228.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 25 09:22:54.942248 2026] [security2:error] [pid 26965:tid 26965] [client 34.21.228.2:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "365soft.top"] [uri "/.git/config"] [unique_id "arZ1rsHQa8bNEwdUFI0bdgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Epimetheus
2026-09-25 12:16:33
(6 hours ago)
Zombie network / Bot scanner detected:
[GET] /.env_sample
[GET] /.git/config.bak
[GET] /babel.confi ...
show more
Zombie network / Bot scanner detected:
[GET] /.env_sample
[GET] /.git/config.bak
[GET] /babel.config.js
[GET] /package.json
[GET] /.eslintrc.json
[GET] /debug/vars
[GET] /web.config
[GET] /.eslintrc.js
[GET] /web.config
[GET] /actuator/configprops
[GET] /docker-compose.prod.yml
[GET] /serverless.yml
[GET] /.aws/config
[GET] /.msmtprc
[GET] /.wp-config.php.save
[GET] /.env
[GET] /.env.production
UA: Mozilla/5.0 (iPhone; CPU iPhone OS 18_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1 Mobile/15E148 Safari/604.1
show less
Bad Web Bot
Exploited Host
Web App Attack
๐ฌ๐ง
Apache
2026-09-25 10:39:42
(7 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.21.228.2 (SG/Singapore/2.228.21.34.bc.google ...
show more
(mod_security) mod_security (id:210730) triggered by 34.21.228.2 (SG/Singapore/2.228.21.34.bc.googleusercontent.com): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
๐ธ๐ช
SkyDancer
2026-09-25 10:25:48
(7 hours ago)
Multiple intrusion attempts via http/https on known vulnerable url offsets. Attack automatically blo ...
show more
Multiple intrusion attempts via http/https on known vulnerable url offsets. Attack automatically blocked by SkyDancer Ai(web-X).
show less
Hacking
Brute-Force
๐ฉ๐ช
Blexyel
2026-09-25 08:19:48
(10 hours ago)
34.21.228.2 - - [25/Sep/2026:10:19:47 +0200] "GET /.git/config HTTP/1.1" 404 435 "-" "Mozilla/5.0 (W ...
show more
34.21.228.2 - - [25/Sep/2026:10:19:47 +0200] "GET /.git/config HTTP/1.1" 404 435 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36" "deranged.blog"
...
show less
Brute-Force
Web App Attack
๐ต๐ฑ
Budyn
2026-09-25 06:45:18
(11 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: definitelynotahoneypot.online | URI: /.git/config | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-09-25 04:45:46
(13 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-25 02:44:01
(15 hours ago)
[ti-11al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-11al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.21.228.2 - - [25/Sep/2026:04:43:54 +0200] "GET /.git/config HTTP/2.0" 301 347 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.0.0 Safari/537.36 Edg/130.0.0.0"
...
show less
Bad Web Bot
Web App Attack
๐ง๐พ
lns.bz
2026-09-25 00:45:31
(17 hours ago)
.env scanning [BY]
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-24 20:45:15
(21 hours ago)
Excessive multi-domain requests
Brute-Force
๐ซ๐ฎ
YF
2026-09-24 18:00:42
(1 day ago)
WordPress config file probe
Web App Attack
๐ฉ๐ช
maxpower
2026-09-24 16:06:45
(1 day ago)
(nginx_hardened) REGOLA 3 - Nginx Hardening Triggered 34.21.228.2 (SG/Singapore/2.228.21.34.bc.googl ...
show more
(nginx_hardened) REGOLA 3 - Nginx Hardening Triggered 34.21.228.2 (SG/Singapore/2.228.21.34.bc.googleusercontent.com): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 2026/09/24 18:06:42 [error] 3635332#3635332: *823574 access forbidden by rule, client: 34.21.228.2, server: emmeccisolution.it, request: "GET /.wp-config.php HTTP/1.1", host: "emmeccipubblicita.it"
2026/09/24 18:06:42 [error] 3635337#3635337: *823575 access forbidden by rule, client: 34.21.228.2, server: emmeccisolution.it, request: "GET /.wp-config.php HTTP/1.1", host: "emmeccipubblicita.it"
2026/09/24 18:06:43 [error] 3635332#3635332: *823574 access forbidden by rule, client: 34.21.228.2, server: emmeccisolution.it, request: "GET /.wp-config.php.bak HTTP/1.1", host: "emmeccipubblicita.it"
show less
Port Scan
๐ต๐ฑ
Budyn
2026-09-24 12:27:07
(1 day ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: status.teddypot.online | URI: /.git/config | UA: Mozilla/5.0 (iPhone; CPU iPhone OS 18_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1 Mobile/15E148 Safari/604.1 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-24 11:19:49
(1 day ago)
Aggressive web scan
Web App Attack
๐ต๐ฑ
Budyn
2026-09-24 04:13:12
(1 day ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: sql.dont-eat-the-pudding.xyz | URI: /.git/config | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 14_7_2) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1 Safari/605.1.15 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack