๐ฉ๐ช
wpadm4
2026-10-05 00:33:56
(7 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐ฉ๐ช
ger-stg-sifi1
2026-10-05 00:04:09
(7 hours ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
๐ฉ๐ช
marten_o
2026-10-04 23:55:38
(8 hours ago)
34.35.119.187 - - [05/Oct/2026:01:55:37 +0200] "GET /tmp/phpinfo.php HTTP/1.1" 500 568 "-" "Mozilla/ ...
show more
34.35.119.187 - - [05/Oct/2026:01:55:37 +0200] "GET /tmp/phpinfo.php HTTP/1.1" 500 568 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" 321 766
...
show less
Web App Attack
๐ฉ๐ช
rh24
2026-10-04 23:54:16
(8 hours ago)
(secretscan) Secret-Scanner (env/git/ssh/credentials) from 34.35.119.187 (187.119.35.34.bc.googleuse ...
show more
(secretscan) Secret-Scanner (env/git/ssh/credentials) from 34.35.119.187 (187.119.35.34.bc.googleusercontent.com)
show less
Hacking
๐จ๐ญ
zynex
2026-10-04 23:29:23
(8 hours ago)
URL Probing: /server/.env
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-10-04 23:00:17
(8 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐ฉ๐ช
pltcldvlpr
2026-10-04 22:44:32
(9 hours ago)
CMS/framework probe: 34.35.119.187 - - [05/Oct/2026:00:44:32 +0200] "GET /.git/config HTTP/1.1" 404 ...
show more
CMS/framework probe: 34.35.119.187 - - [05/Oct/2026:00:44:32 +0200] "GET /.git/config HTTP/1.1" 404 564 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" asn=396982 org="Google LLC" country=ZA
...
show less
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-04 21:46:54
(10 hours ago)
[cb-16al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[cb-16al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.35.119.187 - - [04/Oct/2026:23:46:49 +0200] "GET /.git/config HTTP/2.0" 404 1338 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-04 21:38:15
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.35.119.187 (187.119.35.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.35.119.187 (187.119.35.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 17:38:10.152041 2026] [security2:error] [pid 18534:tid 18534] [client 34.35.119.187:45496] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "networthbuilding.com"] [uri "/.git/config"] [unique_id "asLHQhEgV1zx9RqPjx0ckAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-04 21:18:30
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.35.119.187 (187.119.35.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.35.119.187 (187.119.35.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 17:18:27.167777 2026] [security2:error] [pid 25081:tid 25081] [client 34.35.119.187:42936] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "networkteam.csennews.com"] [uri "/.git/config"] [unique_id "asLCo2GvSmY_XWS6QG9a3gAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-10-04 21:06:07
(10 hours ago)
Remote Command Execution: Unix Command Injection (command without evasion). Pattern match "(?i)(?:b ...
show more
Remote Command Execution: Unix Command Injection (command without evasion). Pattern match "(?i)(?:b (932235-195)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-04 20:40:19
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.35.119.187 (187.119.35.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.35.119.187 (187.119.35.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 16:40:14.676863 2026] [security2:error] [pid 2946:tid 2946] [client 34.35.119.187:49778] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "networkparanoia.com"] [uri "/.git/config"] [unique_id "asK5rrE3nAhFccqkMMdZ-wAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-04 20:19:18
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.35.119.187 (187.119.35.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.35.119.187 (187.119.35.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 16:19:13.286779 2026] [security2:error] [pid 11961:tid 11961] [client 34.35.119.187:44312] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "networklivemusic.com"] [uri "/.git/config"] [unique_id "asK0wUacdqjb2WziC8narAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-10-04 19:50:03
(12 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-04 18:45:36
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.35.119.187 (187.119.35.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.35.119.187 (187.119.35.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 14:45:30.761163 2026] [security2:error] [pid 9710:tid 9710] [client 34.35.119.187:38308] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "network22.net"] [uri "/.git/config"] [unique_id "asKeyiCWtYtTq9Vvr3HQRwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack