๐ฏ๐ต
ZEROVOX
2026-09-16 11:54:56
(19 minutes ago)
CrowdSec: crowdsecurity/http-sensitive-files detected
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-09-16 11:50:03
(24 minutes ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-16 11:34:24
(40 minutes ago)
Excessive multi-domain requests
Brute-Force
Anonymous
2026-09-16 11:25:52
(48 minutes ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐ฉ๐ช
yitzhaq
2026-09-16 11:24:07
(50 minutes ago)
34.35.44.204 - - [16/Sep/2026:13:23:59 +0200] "GET / HTTP/1.1" 200 16027 "-" "Mozilla/5.0 (X11; Linu ...
show more
34.35.44.204 - - [16/Sep/2026:13:23:59 +0200] "GET / HTTP/1.1" 200 16027 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.35.44.204 - - [16/Sep/2026:13:24:00 +0200] "POST / HTTP/1.1" 200 12028 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.35.44.204 - - [16/Sep/2026:13:24:01 +0200] "POST / HTTP/1.1" 200 12028 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.35.44.204 - - [16/Sep/2026:13:24:01 +0200] "GET /.git/config HTTP/1.1" 403 511 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.35.44.204 - - [16/Sep/2026:13:24:02 +0200] "GET /.env HTTP/1.1" 404 58183 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.35.44.204 - - [16/Sep/2026:13:24:02 +0200] "GET /.env.local HTTP/1.1" 404 581
show less
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-16 10:51:03
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.35.44.204 (204.44.35.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.35.44.204 (204.44.35.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 06:50:58.537103 2026] [security2:error] [pid 19599:tid 19617] [client 34.35.44.204:44110] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nrgla.com"] [uri "/.git/config"] [unique_id "aqp0kqt3tvh-a2y5rCDmawAAAIw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2026-09-16 10:46:41
(1 hour ago)
(php_susp_dir) srv102 PHP Suspicious Directory 34.35.44.204 (ZA/South Africa/204.44.35.34.bc.googleu ...
show more
(php_susp_dir) srv102 PHP Suspicious Directory 34.35.44.204 (ZA/South Africa/204.44.35.34.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-16 05:44:32
(6 hours ago)
Excessive 404/403 errors
Brute-Force
๐ฌ๐ง
rooster
2026-09-16 01:12:09
(11 hours ago)
[16/Sep/2026:02:11:53 +0100] - 405 405 - POST https npm01.netnexus.pt.eu.org "/" [Client 34.35.44.20 ...
show more
[16/Sep/2026:02:11:53 +0100] - 405 405 - POST https npm01.netnexus.pt.eu.org "/" [Client 34.35.44.204] [Length 556] [Gzip -] [Sent-to npm] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-"
[16/Sep/2026:02:11:53 +0100] - 405 405 - POST https npm01.netnexus.pt.eu.org "/" [Client 34.35.44.204] [Length 556] [Gzip -] [Sent-to npm] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-"
[16/Sep/2026:02:11:59 +0100] - 404 404 - GET https npm01.netnexus.pt.eu.org "/api/.env" [Client 34.35.44.204] [Length 52] [Gzip -] [Sent-to npm] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-"
[16/Sep/2026:02:11:59 +0100] - 404 404 - GET https npm01.netnexus.pt.eu.org "/api/.env" [Client 34.35.44.204] [Length 52] [Gzip -] [Sent-to npm] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-"
...
show less
Hacking
Web App Attack
๐ฉ๐ช
pscriptos
2026-09-16 01:03:11
(11 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ซ๐ท
GoodOldTOS
2026-09-15 23:46:43
(12 hours ago)
Bad keywords detected in request: /.git/config/.git
Web App Attack
๐จ๐ญ
4server
2026-09-15 21:07:36
(15 hours ago)
[TueSep1523:07:32.6996122026][security2:error][pid1982253:tid1982375][client34.35.44.204:0]ModSecuri ...
show more
[TueSep1523:07:32.6996122026][security2:error][pid1982253:tid1982375][client34.35.44.204:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\\$\(\?:\\\\\\\\\(\(\?:\\\\\\\\\(.\*\\\\\\\\\)\|.\*\)\\\\\\\\\)\|\\\\\\\\{.\*\\\\\\\\}\)\|[\<\>]\\\\\\\\\(.\*\\\\\\\\\)\)\"atARGS:0.[file\"/etc/apache2/conf.d/modsec_rules/10_asl_rules.conf\"][line\"396\"][id\"393655\"][rev\"17\"][msg\"Atomicorp.comWAFRules:PossibleRemoteCommandExecution:UnixShellExpressionFound\"][data\"MatchedData:\$\(\(41\*271\)\)foundwithinARGS:0:{then:\$1:__proto__:thenstatus:resolved_modelreason:-1value:{then:\$b1337}_response:{_prefix:varres=process.mainmodule.require\(child_process\).execsync\(echo\$\(\(41\*271\)\)\|base64-w0\).tostring\(\).trim\(\)throwobject.assign\(newerror\(next_redirect\){digest:\`next_redirectpush/login\?a=\${res}307\`}\)_chunks:\$q2_formdata:{get:\$1:constructor:constructor}}}\"][tag\"attack-rce\"][hostname\"npdesign360.ch\"][uri\"/\"][unique_id\"aqmzlPItqVcFfvgyEFyzhQAAAM8\"]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 20:55:47
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.35.44.204 (204.44.35.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.35.44.204 (204.44.35.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 16:55:40.732921 2026] [security2:error] [pid 21667:tid 21667] [client 34.35.44.204:55702] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "npcsouthernclassic.com"] [uri "/.git/config"] [unique_id "aqmwzJL4IVPEWD3zWPmi4AAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 19:49:44
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.35.44.204 (204.44.35.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.35.44.204 (204.44.35.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 15:49:37.557983 2026] [security2:error] [pid 10144:tid 10177] [client 34.35.44.204:45472] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "npaccountants.org"] [uri "/.git/config"] [unique_id "aqmhUbLxS6jRdy0S2GkoqwAAAEE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-09-15 18:55:03
(17 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack