🇫🇷
Little Iguana
2026-09-01 13:51:43
(1 week ago)
Attempt to hack Wordpress Login, XMLRPC or other login
Hacking
🇩🇪
Marcin Stepien
2026-09-01 13:48:45
(1 week ago)
Hit honeypot endpoint /.git/config. Automated scanner/bot detected.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-01 12:04:19
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.34.112.200 (200.112.34.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.34.112.200 (200.112.34.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 08:04:15.966992 2026] [security2:error] [pid 20082:tid 20151] [client 34.34.112.200:36542] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.eisdigitall.com"] [uri "/.git/config"] [unique_id "apa_P0zo3XFLOK5zIgCIHAAAAEY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇷🇴
clauss
2026-09-01 10:40:39
(1 week ago)
34.34.112.200 - - [01/Sep/2026:13:40:38 +0300] "GET /.git/config HTTP/1.1" 403 177 "-" "Mozilla/5.0 ...
show more
34.34.112.200 - - [01/Sep/2026:13:40:38 +0300] "GET /.git/config HTTP/1.1" 403 177 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.34.112.200 - - [01/Sep/2026:13:40:38 +0300] "GET /.env.local HTTP/1.1" 403 177 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-01 09:17:10
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.34.112.200 (200.112.34.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.34.112.200 (200.112.34.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 05:17:05.093363 2026] [security2:error] [pid 24020:tid 24020] [client 34.34.112.200:35352] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.ed-co-corp.com"] [uri "/.git/config"] [unique_id "apaYEe4r5cOh38vzcLDBjQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
ecs.ge
2026-09-01 09:09:25
(1 week ago)
Automatic Fail2Ban report from jail plesk-modsecurity: multiple matching events detected.
Web App Attack
Hacking
🇨🇿
Prcek
2026-09-01 08:50:05
(1 week ago)
PortScan:HOST=34.34.112.200,DPORTS=443
Port Scan
🇩🇪
Hazzard
2026-09-01 08:18:37
(1 week ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
🇨🇦
danieljamesbertrand
2026-09-01 06:31:33
(1 week ago)
fail2ban jail=nginx-access-exploit on canadapaywall (automatic report; categories 19,21)
Bad Web Bot
Web App Attack
🇫🇮
mnazibo
2026-09-01 04:45:15
(1 week ago)
Date: Sep 01 07:35:04 2026 EAT | Reported IP: 34.34.112.200 mod_security | id: 920440 930130 932130 ...
show more
Date: Sep 01 07:35:04 2026 EAT | Reported IP: 34.34.112.200 mod_security | id: 920440 930130 932130 932235 932260 933135 934100 934130 942151 942550 949110 920500 | NL/usernameab.my_domain/- | Connections: 1 | Blocked: Permanent Block: [LF_MODSEC] | Logs: ; URL file extension is restricted by policy; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Remote Command Execution: Unix Shell Expression Found; Remote Command Execution: Unix Shell Expression Found; Remote Command Execution: Unix Command Injection (command without evasion); Remote Command Execution: Unix Command Injection (command without evasion); Remote Command Execution: Direct Unix Command Execution; Remote Command Execution: Direct Unix Com
show less
SQL Injection
Brute-Force
Bad Web Bot
🇳🇱
WeCloudit-Anti-Abuse
2026-09-01 04:40:11
(1 week ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇳🇱
debestelapp
2026-09-01 00:45:10
(1 week ago)
Web App Attack
🇩🇪
FD-IX
2026-09-01 00:25:04
(1 week ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇬🇧
Apache
2026-08-31 07:57:59
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.34.112.200 (200.112.34.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.34.112.200 (200.112.34.34.bc.googleusercontent.com): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
🇩🇪
IloGus
2026-08-31 07:46:00
(1 week ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack