🇩🇪
ger-stg-sifi1
2026-09-15 19:10:00
(4 hours ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
Anonymous
2026-09-15 09:57:35
(13 hours ago)
git/env leak probe
Web App Attack
🇬🇧
consul.to
2026-09-14 11:31:30
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
🇩🇪
cybertailor
2026-09-14 10:33:55
(1 day ago)
34.48.122.116 - - [14/Sep/2026:15:33:49 +0500] "GET / HTTP/1.1" 404 142 "-" "Mozilla/5.0 (Macintosh; ...
show more
34.48.122.116 - - [14/Sep/2026:15:33:49 +0500] "GET / HTTP/1.1" 404 142 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
34.48.122.116 - - [14/Sep/2026:15:33:49 +0500] "POST / HTTP/1.1" 404 146 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)"
34.48.122.116 - - [14/Sep/2026:15:33:49 +0500] "GET /z9x8c7v6b5-debug-trigger-wildcard.sysrq.in HTTP/1.1" 404 146 "-" "Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)"
34.48.122.116 - - [14/Sep/2026:15:33:49 +0500] "GET /.git/config HTTP/1.1" 404 146 "-" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)"
34.48.122.116 - - [14/Sep/2026:15:33:49 +0500] "GET /.aws/credentials HTTP/1.1" 404 146 "-" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)"
...
show less
Port Scan
🇳🇱
middelkoopcc
2026-09-14 10:31:06
(1 day ago)
2026-09-14 12:29:28 GET /firebase-config.json [301] && 2026-09-14 12:29:29 GET /__/firebase/init.jso ...
show more
2026-09-14 12:29:28 GET /firebase-config.json [301] && 2026-09-14 12:29:29 GET /__/firebase/init.json [301] && 2026-09-14 12:29:29 GET /settings.json [301] && 178 more within 20 minutes
show less
Web App Attack
🇱🇻
garmtech.com
2026-09-14 09:32:59
(1 day ago)
Attempted access to sensitive endpoint (/openapi.json) detected. Automated scan or unauthorized prob ...
show more
Attempted access to sensitive endpoint (/openapi.json) detected. Automated scan or unauthorized probing.
show less
Web App Attack
🇩🇪
creoline GmbH
2026-09-14 08:17:15
(1 day ago)
[WAF] Multiple suspicious HTTP requests has been blocked
Bad Web Bot
Web App Attack
🇳🇱
Alt255
2026-09-13 10:22:24
(2 days ago)
[ti-24al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-24al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.48.122.116 - - [13/Sep/2026:12:22:23 +0200] "GET /.github/.env HTTP/2.0" 403 525 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ChatGPT-User/1.0; +https://openai.com/bot)"
...
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 08:54:37
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.48.122.116 (116.122.48.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.48.122.116 (116.122.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 04:54:31.518523 2026] [security2:error] [pid 19514:tid 19514] [client 34.48.122.116:42484] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||pentesters.in|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "pentesters.in"] [uri "/rclone.conf"] [unique_id "aqZkx9-UUN_qQZpAlFFl_gAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
creoline GmbH
2026-09-13 07:40:14
(2 days ago)
[WAF] Multiple suspicious HTTP requests has been blocked
Bad Web Bot
Web App Attack
🇫🇷
david.houstin
2026-09-13 07:28:22
(2 days ago)
34.48.122.116 - - [13/Sep/2026:09:28:17 +0200] "GET /..%2f.env HTTP/2.0" 404 288 "-" "Mozilla/5.0 (c ...
show more
34.48.122.116 - - [13/Sep/2026:09:28:17 +0200] "GET /..%2f.env HTTP/2.0" 404 288 "-" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)" 2644 -
34.48.122.116 - - [13/Sep/2026:09:28:18 +0200] "GET /..%2f..%2f.env HTTP/2.0" 404 265 "-" "Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)" 992 -
34.48.122.116 - - [13/Sep/2026:09:28:19 +0200] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fproc/self/environ HTTP/2.0" 404 265 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )" 731 -
34.48.122.116 - - [13/Sep/2026:09:28:20 +0200] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f.env HTTP/2.0" 404 288 "-" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)" 2161 -
34.48.122.116 - - [13/Sep/2026:09:28:20 +0200] "GET /admin%2F.env HTTP/2.0" 404 265 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)" 976 -
34.48.122.116 - - [13/Sep/2026:09:28:20
...
show less
Web App Attack
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-13 07:26:07
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.48.122.116 (116.122.48.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.48.122.116 (116.122.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 03:26:00.845787 2026] [security2:error] [pid 30138:tid 30138] [client 34.48.122.116:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||chaitanyaconsult.in|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "chaitanyaconsult.in"] [uri "/rclone.conf"] [unique_id "aqZQCJjkTPXnCaeSjutiIQAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-13 06:46:48
(2 days ago)
Web attack/malicious scanning detected
Web App Attack
Anonymous
2026-09-13 06:24:30
(2 days ago)
Web application attack detected.
Web App Attack
🇧🇪
cmbplf
2026-09-12 17:49:46
(3 days ago)
219 requests with url.path */@fs/*
Brute-Force
Bad Web Bot