🇫🇷
dynamix
2026-09-12 04:22:58
(5 minutes ago)
Multiple WAF Violations
Web App Attack
🇳🇱
svr
2026-09-12 03:59:10
(29 minutes ago)
Abusive Automated Web Scanner
Web App Attack
🇳🇱
Site.eu
2026-09-12 03:15:47
(1 hour ago)
Excessive multi-domain requests
Brute-Force
🇺🇦
URAN Publishing Service
2026-09-11 18:22:47
(10 hours ago)
[11/Sep/2026:21:22:47 +0300] -- 34.47.94.25 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/c ...
show more
[11/Sep/2026:21:22:47 +0300] -- 34.47.94.25 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/config HTTP/1.1
show less
Bad Web Bot
Web App Attack
🇩🇪
FD-IX
2026-09-11 18:09:26
(10 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-11 01:54:10
(1 day ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-196)
Hacking
Web App Attack
🇨🇦
Sakusen
2026-09-11 01:13:46
(1 day ago)
Automated web attack: 277 reqs, 267 paths probed, 232 returned 404; probed: 206 .env, 44 .php, 9 .js ...
show more
Automated web attack: 277 reqs, 267 paths probed, 232 returned 404; probed: 206 .env, 44 .php, 9 .json, 4 secret, 2 other, 1 .git, 1 cloud-cred
show less
Hacking
Bad Web Bot
Web App Attack
🇪🇸
Francisco Vallejo
2026-09-11 01:07:07
(1 day ago)
[Fri Sep 11 03:07:06.049795 2026] [authz_core:error] [pid 216787:tid 123165206361792] [client 34.47. ...
show more
[Fri Sep 11 03:07:06.049795 2026] [authz_core:error] [pid 216787:tid 123165206361792] [client 34.47.94.25:60810] AH01630: client denied by server configuration: proxy:https://localhost:9090/
[Fri Sep 11 03:07:06.328460 2026] [authz_core:error] [pid 216787:tid 123164696770240] [client 34.47.94.25:60810] AH01630: client denied by server configuration: proxy:https://localhost:9090/
[Fri Sep 11 03:07:06.601541 2026] [authz_core:error] [pid 216787:tid 123165197969088] [client 34.47.94.25:60810] AH01630: client denied by server configuration: proxy:https://localhost:9090/
[Fri Sep 11 03:07:06.877040 2026] [authz_core:error] [pid 216787:tid 123164688377536] [client 34.47.94.25:60810] AH01630: client denied by server configuration: proxy:https://localhost:9090/
[Fri Sep 11 03:07:07.171371 2026] [authz_core:error] [pid 216787:tid 123165231539904] [client 34.47.94.25:60810] AH01630: client denied by server configuration: proxy:https://localhost:9090/.git/config
...
show less
Brute-Force
SSH
🇵🇱
Budyn
2026-09-11 00:58:16
(1 day ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: prometheus.astropot.site | URI: /.git/config | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
🇫🇷
Octopuce
2026-09-10 23:07:54
(1 day ago)
Aggressive web search of vulnerable pages: / /.env /.env.local /app/.env /apps/.env ...
Web App Attack
🇺🇸
TPI-Abuse
2026-09-10 22:29:18
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.47.94.25 (25.94.47.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.47.94.25 (25.94.47.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 18:29:11.052609 2026] [security2:error] [pid 1522:tid 1522] [client 34.47.94.25:37386] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "projectthinkspot.com"] [uri "/.git/config"] [unique_id "aqMvN92TvIjP73sLC4xosgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Gwyneth Llewelyn
2026-09-10 21:52:39
(1 day ago)
2026/09/10 22:52:29 [error] 1267648#1267648: *6398 access forbidden by rule, client: 34.47.94.25, se ...
show more
2026/09/10 22:52:29 [error] 1267648#1267648: *6398 access forbidden by rule, client: 34.47.94.25, server: projects.betatechnologies.info, request: "GET /.env HTTP/2.0", host: "projects.betatechnologies.info"
34.47.94.25 - - [10/Sep/2026:22:52:29 +0100] "GET /.env HTTP/2.0" 403 1045 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
2026/09/10 22:52:37 [error] 1267648#1267648: *6398 access forbidden by rule, client: 34.47.94.25, server: projects.betatechnologies.info, request: "GET /app/.env HTTP/2.0", host: "projects.betatechnologies.info"
show less
Brute-Force
Web App Attack
🇸🇪
vaia.cloud
2026-09-10 04:05:02
(2 days ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
Anonymous
2026-09-10 03:49:35
(2 days ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
🇦🇺
paulshipley.com.au
2026-09-10 03:13:50
(2 days ago)
[Thu Sep 10 13:13:49.705032 2026] [security2:error] [pid 461552] [client 34.47.94.25:46802] [client ...
show more
[Thu Sep 10 13:13:49.705032 2026] [security2:error] [pid 461552] [client 34.47.94.25:46802] [client 34.47.94.25] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "rjryanpartners.com.au"] [uri "/"] [unique_id "aqIgba4fSTA-5Sl3YPL_awAAAAI"]
...
show less
Web App Attack