🇳🇱
Site.eu
2026-09-11 23:46:14
(6 hours ago)
Excessive 404/403 errors
Brute-Force
🇺🇸
NXTwoThou
2026-09-11 20:31:27
(10 hours ago)
/config.json
Web App Attack
🇩🇪
Hazzard
2026-09-11 18:50:45
(11 hours ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
🇳🇱
Savvii
2026-09-11 18:16:54
(12 hours ago)
20 attempts against mh_ha-misbehave-ban on pf221116
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-11 18:06:42
(12 hours ago)
Excessive multi-domain requests
Brute-Force
🇺🇸
IndigoRidge
2026-09-11 18:05:43
(12 hours ago)
34.31.48.244 - - [11/Sep/2026:14:05:42 -0400] "GET /.aws/credentials HTTP/1.1" 404 4851 "-" "Mozilla ...
show more
34.31.48.244 - - [11/Sep/2026:14:05:42 -0400] "GET /.aws/credentials HTTP/1.1" 404 4851 "-" "Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)"
34.31.48.244 - - [11/Sep/2026:14:05:42 -0400] "GET /.git/config HTTP/1.1" 404 4851 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.3; +https://openai.com/gptbot)"
34.31.48.244 - - [11/Sep/2026:14:05:43 -0400] "GET /img../.env HTTP/1.1" 404 4851 "-" "Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)"
...
show less
Web App Attack
Anonymous
2026-09-11 18:00:06
(12 hours ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection
🇺🇸
TPI-Abuse
2026-09-11 17:39:24
(13 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.31.48.244 (244.48.31.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.31.48.244 (244.48.31.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 13:39:19.628978 2026] [security2:error] [pid 2217522:tid 2217540] [client 34.31.48.244:53542] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||sparkhypnotherapy.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "sparkhypnotherapy.com"] [uri "/z9x8c7v6b5-debug-trigger-sparkhypnotherapy.com"] [unique_id "aqQ8xy2ChxZfYxBtuDWhcAAAAQ8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
Swiptly
2026-09-11 17:37:44
(13 hours ago)
Bot scanning for environment files .env .env/\*
...
Web App Attack
Anonymous
2026-09-11 17:25:13
(13 hours ago)
SPARSDE WEBEXPLOIT 34.31.48.244 (244.48.31.34.bc.googleusercontent.com)
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 17:19:40
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.31.48.244 (244.48.31.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.31.48.244 (244.48.31.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 13:19:34.617692 2026] [security2:error] [pid 13748:tid 13748] [client 34.31.48.244:59296] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "spanishweddinginvitations.com"] [uri "/.svn/entries"] [unique_id "aqQ4Jlonlko8MFOm69mDKAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Alboweb B.V.
2026-09-11 17:11:03
(13 hours ago)
Bad web bot activity detected by Fail2Ban in plesk-apache-badbot jail
Bad Web Bot
🇫🇷
masterguru
2026-09-11 17:05:33
(13 hours ago)
Restricted File Access Attempt. Matched phrase ".aws/" at REQUEST_FILENAME. (930130-195)
Hacking
Web App Attack
🇳🇱
debestelapp
2026-09-11 16:45:12
(13 hours ago)
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 16:43:21
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.31.48.244 (244.48.31.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.31.48.244 (244.48.31.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 12:43:14.244722 2026] [security2:error] [pid 32416:tid 32416] [client 34.31.48.244:34286] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "spacebooger.com"] [uri "/.env.production"] [unique_id "aqQvogIGfb7yD71Y1rlFZAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack