๐ณ๐ฑ
e.fierstra
2026-09-01 11:47:20
(7 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-01 10:32:15
(9 hours ago)
Excessive multi-domain requests
Brute-Force
๐ฉ๐ช
marten_o
2026-09-01 09:52:51
(9 hours ago)
34.23.213.94 - - [01/Sep/2026:11:52:51 +0200] "GET /tmp/phpinfo.php HTTP/1.1" 500 573 "-" "Mozilla/5 ...
show more
34.23.213.94 - - [01/Sep/2026:11:52:51 +0200] "GET /tmp/phpinfo.php HTTP/1.1" 500 573 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" 321 771
...
show less
Web App Attack
๐ฉ๐ช
4server
2026-09-01 07:08:42
(12 hours ago)
[TueSep0109:08:35.9787952026][security2:error][pid3830781:tid3830880][client34.23.213.94:0]ModSecuri ...
show more
[TueSep0109:08:35.9787952026][security2:error][pid3830781:tid3830880][client34.23.213.94:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"krausbeck.ch.136-243-54-122.cpanel.site\"][uri\"/.env.bak\"][unique_id\"apZ584RxB2j3_H13CuxHEAAAAMo\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ญ๐บ
kranem
2026-09-01 06:00:16
(13 hours ago)
Triggered Cloudflare WAF from US.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/1.1 (G ...
show more
Triggered Cloudflare WAF from US.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/1.1 (GET method)
Endpoint: /
Timestamp: 2026-09-01T05:02:07Z
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
show less
Bad Web Bot
๐ฉ๐ช
FD-IX
2026-09-01 05:16:02
(14 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐ฉ๐ช
DEV-DNS
2026-09-01 04:38:34
(15 hours ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
๐ธ๐ช
vaia.cloud
2026-09-01 03:05:02
(16 hours ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 13:08:51
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.23.213.94 (94.213.23.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.23.213.94 (94.213.23.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 09:08:46.847322 2026] [security2:error] [pid 13874:tid 13874] [client 34.23.213.94:49328] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lawson-insurance.com"] [uri "/.git/config"] [unique_id "apV83lbrIReJMj968MZAKQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
Inartis
2026-08-31 11:43:56
(1 day ago)
34.23.213.94 - - [31/Aug/2026:13:43:55 +0200] "GET /.git/config HTTP/1.1" 200 51429 "-" "Mozilla/5.0 ...
show more
34.23.213.94 - - [31/Aug/2026:13:43:55 +0200] "GET /.git/config HTTP/1.1" 200 51429 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-08-31 11:31:58
(1 day ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-08-31 10:34:04
(1 day ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.git/config (+1 more) | 2026-08-31 10:34 UTC
show less
Hacking
Web App Attack
๐ฎ๐น
Progetto1
2026-08-31 10:20:02
(1 day ago)
Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
Victor Lรณpez
2026-08-31 10:07:48
(1 day ago)
lavadodepisosbogota.com 34.23.213.94 - - [31/Aug/2026:05:07:46 -0500] "GET /.git/config HTTP/1.1" 40 ...
show more
lavadodepisosbogota.com 34.23.213.94 - - [31/Aug/2026:05:07:46 -0500] "GET /.git/config HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" -
lavadodepisosbogota.com 34.23.213.94 - - [31/Aug/2026:05:07:47 -0500] "GET /.env HTTP/1.1" 404 11470 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" -
lavadodepisosbogota.com 34.23.213.94 - - [31/Aug/2026:05:07:48 -0500] "GET /.env.local HTTP/1.1" 404 11470 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" -
...
show less
Hacking
Web App Attack
๐ง๐ท
Halux
2026-08-31 09:45:05
(1 day ago)
34.23.213.94 Probing protected path or service
Web App Attack