🇳🇱
Savvii
2026-09-11 02:02:01
(6 minutes ago)
20 attempts against mh-misbehave-ban on frost
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-09-11 01:15:02
(53 minutes ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
Anonymous
2026-09-11 01:09:24
(59 minutes ago)
Trapped by Fail2Ban: Too many login failures from 34.39.42.89
Brute-Force
Hacking
🇳🇱
Site.eu
2026-09-11 00:56:34
(1 hour ago)
Excessive multi-domain requests
Brute-Force
🇩🇪
maxpower
2026-09-11 00:56:23
(1 hour ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.39.42.89 (GB/United Kingdom/89.42.39. ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.39.42.89 (GB/United Kingdom/89.42.39.34.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.39.42.89 - - [11/Sep/2026:02:56:18 +0200] "GET /secrets.json HTTP/2.0" 429 41 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)" "34.39.42.89" host=fisacabruzzomolise.com
show less
Port Scan
🇩🇪
itsolon
2026-09-11 00:30:16
(1 hour ago)
[11/Sep/2026:02:30:14 +0200] 17890866141.228943 34.39.42.89 0 217.154.7.177 443
[11/Sep/2026:02:30:1 ...
show more
[11/Sep/2026:02:30:14 +0200] 17890866141.228943 34.39.42.89 0 217.154.7.177 443
[11/Sep/2026:02:30:15 +0200] 178908661564.701888 34.39.42.89 0 217.154.7.177 443
[11/Sep/2026:02:30:14 +0200] 178908661475.008299 34.39.42.89 0 217.154.7.177 443
[11/Sep/2026:02:30:16 +0200] 178908661652.317487 34.39.42.89 0 217.154.7.177 443
[11/Sep/2026:02:30:14 +0200] 178908661458.905355 34.39.42.89 0 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
🇪🇸
el-brujo
2026-09-11 00:20:55
(1 hour ago)
34.39.42.89 - - [11/Sep/2026:02:20:55 +0200] "GET /.dockerenv HTTP/2.0" 404 15989 "-" "Mozilla/5.0 ( ...
show more
34.39.42.89 - - [11/Sep/2026:02:20:55 +0200] "GET /.dockerenv HTTP/2.0" 404 15989 "-" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)"
34.39.42.89 - - [11/Sep/2026:02:20:55 +0200] "GET /rclone.conf HTTP/2.0" 404 15989 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; OAI-SearchBot/1.0; +https://openai.com/searchbot)"
34.39.42.89 - - [11/Sep/2026:02:20:55 +0200] "GET /z9x8c7v6b5-debug-trigger-elhacker.net HTTP/2.0" 404 15989 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1)"
34.39.42.89 - - [11/Sep/2026:02:20:55 +0200] "GET /proc/self/cgroup HTTP/2.0" 404 15989 "-" "Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)"
...
show less
Web App Attack
Hacking
🇩🇪
big-cloud.nl
2026-09-11 00:20:39
(1 hour ago)
Try to access /admin/.env
Web App Attack
🇺🇸
TPI-Abuse
2026-09-10 23:54:12
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.39.42.89 (89.42.39.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.42.89 (89.42.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 19:54:06.260197 2026] [security2:error] [pid 17479:tid 17479] [client 34.39.42.89:38234] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "doctorc.net"] [uri "/%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env"] [unique_id "aqNDHvlof9hKqqd8ypOKEQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-10 23:46:30
(2 hours ago)
☣️ WAF rule violation. Dangerous payload detected in the request.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-10 23:19:20
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.39.42.89 (89.42.39.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.39.42.89 (89.42.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 19:19:14.912214 2026] [security2:error] [pid 6957:tid 6957] [client 34.39.42.89:48004] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||creartest.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "creartest.com"] [uri "/rclone.conf"] [unique_id "aqM68myjjWUfwjQ00BFdSwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
countdownmail.com
2026-09-10 23:17:01
(2 hours ago)
Extensive web application scanning for vulnerabilities.
Web App Attack
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-10 22:31:12
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.39.42.89 (89.42.39.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.42.89 (89.42.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 18:31:04.867605 2026] [security2:error] [pid 9166:tid 9166] [client 34.39.42.89:53882] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "certifiedfarmersmarkets.org"] [uri "/.github/.env"] [unique_id "aqMvqE3rRlj39ClJdkA_BQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
paissangroup
2026-09-10 22:29:29
(3 hours ago)
Multiple WAF Violations
Web App Attack
🇫🇷
SpaceHost-Server
2026-09-10 22:21:53
(3 hours ago)
Brute-Force
Web App Attack