Anonymous
2026-09-16 05:35:08
(2 days ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
Anonymous
2026-09-16 03:03:09
(2 days ago)
Multiple pen test attempts.
Web App Attack
๐ณ๐ฑ
i-turnradio.nl
2026-09-16 01:31:24
(2 days ago)
2026-09-16 @ 03:31:18 (CET) ~ Blocked for trying to access: /__/firebase/init.json
Web App Attack
๐ฉ๐ช
jocurionline
2026-09-16 01:30:11
(2 days ago)
Auto-blocked by WAF: AUTO-BAN: Blocked request + AbuseIPDB 7 zile
Web App Attack
Anonymous
2026-09-16 00:44:50
(2 days ago)
Aggressive web scan
Web App Attack
๐ธ๐ช
eagle
2026-09-16 00:44:00
(2 days ago)
34.23.228.21 - - [16/Sep/2026:00:44:00 +0000] "GET /.git/config HTTP/1.1" 404 184 "-" "Mozilla/5.0 ( ...
show more
34.23.228.21 - - [16/Sep/2026:00:44:00 +0000] "GET /.git/config HTTP/1.1" 404 184 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)"
...
show less
Bad Web Bot
Web App Attack
๐ฎ๐ณ
evicky2002
2026-09-16 00:02:04
(2 days ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ฉ๐ช
s@ch@
2026-09-16 00:00:06
(2 days ago)
Jail: plesk-modsecurity | Web application attack (Plesk ModSecurity)
Web App Attack
๐ฉ๐ช
FD-IX
2026-09-15 23:01:47
(2 days ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐ช๐ธ
robotstxt
2026-09-15 22:54:16
(2 days ago)
34.23.228.21 - - [15/Sep/2026:22:53:42 +0000] "GET /.docker/config.json HTTP/2.0" 403 15928 "https:/ ...
show more
34.23.228.21 - - [15/Sep/2026:22:53:42 +0000] "GET /.docker/config.json HTTP/2.0" 403 15928 "https://robotstxt.es/.docker/config.json" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)" "-" edge="34.23.228.21"
34.23.228.21 - - [15/Sep/2026:22:53:42 +0000] "GET /.s3cfg HTTP/2.0" 403 15928 "https://robotstxt.es/.s3cfg" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" "-" edge="34.23.228.21"
34.23.228.21 - - [15/Sep/2026:22:53:42 +0000] "GET /.boto HTTP/2.0" 403 15928 "https://robotstxt.es/.boto" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" "-" edge="34.23.228.21"
34.23.228.21 - - [15/Sep/2026:22:53:42 +0000] "GET /z9x8c7v6b5-debug-trigger-robotstxt.es HTTP/2.0" 403 15928 "https://robotstxt.es/z9x8c7v6b5-debug-trigger-robotstxt.es" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] )" "-" edge="34.23.228.21"
34.23.228.21 - - [15/Sep/2026:22:53:42 +0000] "GET
...
show less
Web App Attack
๐บ๐ธ
jormaster3k
2026-09-15 22:54:02
(2 days ago)
Attack against Apache (too many 404s)
Web App Attack
๐ธ๐ฌ
Cloudkul Cloudkul
2026-09-15 22:53:23
(2 days ago)
Attempted Not Found (404 status code) requests on our application, more than 30% of their total requ ...
show more
Attempted Not Found (404 status code) requests on our application, more than 30% of their total requests.
show less
Brute-Force
Web App Attack
Anonymous
2026-09-15 21:54:04
(2 days ago)
2026/09/15 21:54:02 [error] 199232#199232: *581217 [client 34.23.228.21] ModSecurity: Access denied ...
show more
2026/09/15 21:54:02 [error] 199232#199232: *581217 [client 34.23.228.21] ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Ge' with parameter `5' against variable `TX:BLOCKING_INBOUND_ANOMALY_SCORE' (Value: `5' ) [file "/usr/local/owasp-modsecurity-crs-4.11.0/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "222"] [id "949110"] [rev ""] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [data ""] [severity "0"] [ver "OWASP_CRS/4.29.0"] [maturity "0"] [accuracy "0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "logiciensoft.com"] [uri "/@fs/app/.env"] [unique_id "178950924251.187401"] [ref ""], client: 34.23.228.21, server: logiciensoft.com, request: "GET /@fs/app/.env?raw?? HTTP/2.0", host: "logiciensoft.com"
2026/09/15 21:54:02 [error] 199232#199232: *581217 [client 34.23.228.21] ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Ge' with parameter `5' against variable `TX:BLOCKING_INBOUND_ANOMALY_SCORE' (Value: `5' ) [file "/usr/loc
...
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-15 21:39:21
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.23.228.21 (21.228.23.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.23.228.21 (21.228.23.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 17:39:14.166407 2026] [security2:error] [pid 19884:tid 19884] [client 34.23.228.21:54878] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kleens-uk.com"] [uri "/.github/.env"] [unique_id "aqm7AsY0kAJK_a0dARsFRgAAAC4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
rh24
2026-09-15 21:23:29
(2 days ago)
(badbots) Bad bot user-agent [redacted] from 34.23.228.21 (US/United States/21.228.23.34.bc.googleus ...
show more
(badbots) Bad bot user-agent [redacted] from 34.23.228.21 (US/United States/21.228.23.34.bc.googleusercontent.com)
show less
Hacking