Anonymous
2026-08-18 19:30:21
(3 days ago)
Banned by Fail2Ban on server
Web App Attack
๐ณ๐ฑ
Site.eu
2026-08-18 18:15:54
(3 days ago)
Excessive multi-domain requests
Brute-Force
๐ซ๐ท
dusfor72
2026-08-18 18:09:43
(3 days ago)
stupid access attempts on non-existant files
...
Brute-Force
Web App Attack
๐ฉ๐ช
maxpower
2026-08-18 17:48:59
(3 days ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.26.112.130 (US/United States/130.112. ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.26.112.130 (US/United States/130.112.26.34.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.26.112.130 - - [18/Aug/2026:19:48:55 +0200] "GET /.aws/credentials HTTP/2.0" 404 34192 "-" "Mozilla/5.0 (compatible; GoogleOther; +http://www.google.com/bot.html)" "-" host=www.circuitografico.it.etag.it
show less
Port Scan
๐จ๐ฟ
ddw
2026-08-18 07:56:24
(4 days ago)
Access Violation Attempts - Multiple 403 Forbidden responses.
Hacking
Bad Web Bot
Web App Attack
Anonymous
2026-08-18 04:11:56
(4 days ago)
Suspicious URL access.
Hacking
๐ฌ๐ง
andypiper
2026-08-18 01:02:30
(4 days ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
Anonymous
2026-08-18 00:09:54
(4 days ago)
[Tue Aug 18 02:09:53.116379 2026] [proxy_fcgi:error] [pid 1505:tid 1671] [client 34.26.112.130:51084 ...
show more
[Tue Aug 18 02:09:53.116379 2026] [proxy_fcgi:error] [pid 1505:tid 1671] [client 34.26.112.130:51084] AH01071: Got error 'Primary script unknown'
[Tue Aug 18 02:09:53.126571 2026] [proxy_fcgi:error] [pid 1505:tid 1665] [client 34.26.112.130:51092] AH01071: Got error 'Primary script unknown'
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
cwytech
2026-08-17 23:08:58
(4 days ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: cwy/http-honeypath-sniper-crit.
Bad Web Bot
Web App Attack
๐ฆ๐บ
clapper
2026-08-17 21:31:43
(4 days ago)
(mod_security) mod_security (id:980001) triggered by 34.26.112.130 (US/United States/130.112.26.34.b ...
show more
(mod_security) mod_security (id:980001) triggered by 34.26.112.130 (US/United States/130.112.26.34.bc.googleusercontent.com): 5 in the last 3600 secs; ID: Clar
show less
Brute-Force
Bad Web Bot
Anonymous
2026-08-17 19:05:30
(4 days ago)
34.26.112.130 - - [17/Aug/2026:21:05:30 +0200] "GET /.aws/config HTTP/2.0" 404 152 "-" "Mozilla/5.0 ...
show more
34.26.112.130 - - [17/Aug/2026:21:05:30 +0200] "GET /.aws/config HTTP/2.0" 404 152 "-" "Mozilla/5.0 (compatible; Applebot/0.1; +http://www.apple.com/go/applebot)"
34.26.112.130 - - [17/Aug/2026:21:05:30 +0200] "GET /.git/config HTTP/2.0" 404 121 "-" "Mozilla/5.0 (compatible; Applebot/0.1; +http://www.apple.com/go/applebot)"
34.26.112.130 - - [17/Aug/2026:21:05:30 +0200] "GET /.aws/credentials HTTP/2.0" 404 121 "-" "Mozilla/5.0 (compatible; Applebot/0.1; +http://www.apple.com/go/applebot)"
34.26.112.130 - - [17/Aug/2026:21:05:30 +0200] "GET /api/config HTTP/2.0" 404 121 "-" "Mozilla/5.0 (compatible; Applebot/0.1; +http://www.apple.com/go/applebot)"
34.26.112.130 - - [17/Aug/2026:21:05:30 +0200] "GET /z9x8c7v6b5-debug-trigger-media.dornberger.it HTTP/2.0" 403 129 "-" "Mozilla/5.0 (compatible; Applebot/0.1; +http://www.apple.com/go/applebot)"
...
show less
Brute-Force
SSH
๐ซ๐ท
thilo
2026-08-17 18:18:23
(4 days ago)
Probe for vulnerabilities. Path attempted: /.github/workflows/deploy.yml
Web App Attack
Anonymous
2026-08-17 17:34:27
(4 days ago)
[Mon Aug 17 19:34:24.822358 2026] [proxy_fcgi:error] [pid 2297:tid 2326] [client 34.26.112.130:38570 ...
show more
[Mon Aug 17 19:34:24.822358 2026] [proxy_fcgi:error] [pid 2297:tid 2326] [client 34.26.112.130:38570] AH01071: Got error 'Primary script unknown'
[Mon Aug 17 19:34:25.319054 2026] [proxy_fcgi:error] [pid 15927:tid 15975] [client 34.26.112.130:38600] AH01071: Got error 'Primary script unknown'
[Mon Aug 17 19:34:25.319054 2026] [proxy_fcgi:error] [pid 15927:tid 15975] [client 34.26.112.130:38600] AH01071: Got error 'Primary script unknown'
...
show less
Brute-Force
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-08-17 16:56:34
(4 days ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 16:11:54
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.26.112.130 (130.112.26.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.26.112.130 (130.112.26.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 12:11:47.174332 2026] [security2:error] [pid 8620:tid 8620] [client 34.26.112.130:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "abdulhameeds.art"] [uri "/.env.backup"] [unique_id "aoMyw6kNrSkA8A26o7_D0AAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack