π³π±
homeshowdomain.nl
2026-10-02 21:59:49
(4 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-10-01.
show less
Web App Attack
SSH
Hacking
Anonymous
2026-10-02 02:50:36
(5 days ago)
Blocked by ModSec and CSF
Port Scan
π¦πΊ
Asimar
2026-10-02 02:36:30
(5 days ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted]): (CF_ENABLE)
Bad Web Bot
π§π·
Sysadmin-CLC
2026-10-02 02:30:07
(5 days ago)
2026/10/02 02:30:06 [error] 475#475: *9912 limiting requests, excess: 40.660 by zone "general", clie ...
show more
2026/10/02 02:30:06 [error] 475#475: *9912 limiting requests, excess: 40.660 by zone "general", client: 34.34.115.73, server: git.literaturaclassica.com.br, request: "GET /.env.save HTTP/1.1", host: "git.literaturaclassica.com.br"
...
show less
Web App Attack
DDoS Attack
π³π±
debestelapp
2026-10-02 00:50:06
(5 days ago)
Web App Attack
π©πͺ
Philister11
2026-10-02 00:38:57
(5 days ago)
CrowdSec: crowdsecurity/http-sensitive-files (NL/AS396982)
Web App Attack
Hacking
πΊπΈ
TPI-Abuse
2026-10-02 00:03:53
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.34.115.73 (73.115.34.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.34.115.73 (73.115.34.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 20:03:45.732014 2026] [security2:error] [pid 1529:tid 1529] [client 34.34.115.73:53380] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.liadisengineering.com"] [uri "/wp-config.php.bak"] [unique_id "ar704fikIdDlaNuh4tzLQAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¦πΊ
rubixstudios
2026-10-01 23:22:02
(5 days ago)
Excessive HTTP requests consistent with automated attack behaviour detected by Imunify360
DDoS Attack
Brute-Force
Web App Attack
πͺπΈ
robotstxt
2026-10-01 22:18:34
(5 days ago)
34.34.115.73 - - [01/Oct/2026:22:17:34 +0000] "GET /z9x8c7v6b5-debug-trigger-www.leydeciberresilienc ...
show more
34.34.115.73 - - [01/Oct/2026:22:17:34 +0000] "GET /z9x8c7v6b5-debug-trigger-www.leydeciberresiliencia.com HTTP/2.0" 403 12653 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)" "-" edge="34.34.115.73"
34.34.115.73 - - [01/Oct/2026:22:17:34 +0000] "GET /r7xglqdbjqei6fw1c5zh/ HTTP/2.0" 403 12676 "https://www.leydeciberresiliencia.com/r7xglqdbjqei6fw1c5zh" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)" "-" edge="34.34.115.73"
34.34.115.73 - - [01/Oct/2026:22:17:34 +0000] "GET /zcu1hjtzwj3yhhi4s7ub/ HTTP/2.0" 403 12653 "https://www.leydeciberresiliencia.com/zcu1hjtzwj3yhhi4s7ub" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )" "-" edge="34.34.115.73"
34.34.115.73 - - [01/Oct/2026:22:17:34 +0000] "GET /build/manifest.json HTTP/2.0" 403 12312 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safa
...
show less
Web App Attack
π³π±
Alt255
2026-10-01 21:50:58
(5 days ago)
[ti-07al] Excessive 404 errors (web scanning): 26 suspicious requests detected by fail2ban jail apac ...
show more
[ti-07al] Excessive 404 errors (web scanning): 26 suspicious requests detected by fail2ban jail apache-404. Example: 34.34.115.73 - - [01/Oct/2026:23:50:57 +0200] "GET /nvvrrx4csfctysqzopp3 HTTP/1.1" 404 2050 "-" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)"
34.34.115.73 - - [01/Oct/2026:23:50:57 +0200] "POST /graphql HTTP/1.1" 404 7386 "https://manage.lejardinsalondethe.nl" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36"
34.34.115.73 - - [01/Oct/2026:23:50:57 +0200] "POST /api/graphql HTTP/1.1" 404 2050 "https://manage.lejardinsalondethe.nl" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36"
34.34.115.73 - - [01/Oct/2026:23:50:57 +0200] "POST /v1/graphql HTTP/1.1" 404 2050 "https://manage.
...
show less
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-01 20:29:49
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.34.115.73 (73.115.34.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.34.115.73 (73.115.34.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 16:29:43.539309 2026] [security2:error] [pid 4102:tid 4102] [client 34.34.115.73:36464] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.lightupaustralia.com"] [uri "/.git/config"] [unique_id "ar7Ct5iBpkjkQUcR49ueGAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
Octopuce
2026-10-01 19:32:07
(5 days ago)
Aggressive web search of vulnerable pages: /files../.env /media../.env /static../.env /assets../.env ...
show more
Aggressive web search of vulnerable pages: /files../.env /media../.env /static../.env /assets../.env /images../.env ...
show less
Web App Attack
Anonymous
2026-10-01 18:20:05
(5 days ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection
πΊπΈ
TPI-Abuse
2026-10-01 17:46:13
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.34.115.73 (73.115.34.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.34.115.73 (73.115.34.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 13:46:10.514368 2026] [security2:error] [pid 20052:tid 20052] [client 34.34.115.73:55752] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.lbee.com"] [uri "/.env"] [unique_id "ar6cYozUXu7QjeTP05oKTgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-01 17:28:23
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 34.34.115.73 (73.115.34.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.34.115.73 (73.115.34.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 13:28:20.256927 2026] [security2:error] [pid 19878:tid 19878] [client 34.34.115.73:56994] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||leothecolorman.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "leothecolorman.com"] [uri "/z9x8c7v6b5-debug-trigger-leothecolorman.com"] [unique_id "ar6YNLfwHGC9xaoK-5AaIgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack