🇩🇪
jasperedv.de
2026-09-13 00:04:06
(7 minutes ago)
Apache Login - Brutforcing
Web App Attack
Brute-Force
🇩🇪
EGP Abuse Dept
2026-09-13 00:02:07
(9 minutes ago)
Scanning for web/db/file exploits on www.ldcs-tools.com
SQL Injection
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 23:51:05
(20 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.48.25.70 (70.25.48.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.48.25.70 (70.25.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 19:50:58.961342 2026] [security2:error] [pid 7543:tid 7549] [client 34.48.25.70:34402] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lcncmo.com"] [uri "/@fs/.env"] [unique_id "aqXlYkFQcMSZ79QwFToIMwAAAIQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇷
Halux
2026-09-12 23:50:22
(21 minutes ago)
34.48.25.70 Web Application Firewall multiple violations
Hacking
Web App Attack
🇦🇺
artful
2026-09-12 23:41:00
(30 minutes ago)
Excessive errors in recent hours
Web App Attack
🇮🇹
CoreTech srl
2026-09-12 23:33:56
(37 minutes ago)
cloudlinux2 fail2ban: 2026-09-13 01:29:09,481 fail2ban.filter [1606]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-13 01:29:09,481 fail2ban.filter [1606]: INFO [plesk-modsecurity] Found 34.48.25.70 - 2026-09-13 01:29:09cloudlinux2 fail2ban: 2026-09-13 01:29:09,513 fail2ban.filter [1606]: INFO [plesk-modsecurity] Found 34.48.25.70 - 2026-09-13 01:29:09cloudlinux2 fail2ban: 2026-09-13 01:29:09,492 fail2ban.filter [1606]: INFO [plesk-modsecurity] Found 34.48.25.70 - 2026-09-13 01:29:09cloudlinux2 fail2ban: 2026-09-13 01:29:09,502 fail2ban.filter [1606]: INFO [plesk-modsecurity] Found 34.48.25.70 - 2026-09-13 01:29:09cloudlinux2 fail2ban: 2026-09-13 01:29:09,666 fail2ban.filter [1606]: INFO [plesk-modsecurity] Found 34.48.25.70 - 2026-09-13 01:29:09cloudlinux2 fail2ban: 2026-09-13 01:29:09,699 fail2ban.filter [1606]: INFO [plesk-modsecurity] Found 34.48.25.70 - 2026-09-13 01:29:09cloudlinux2 fail2ban: 2026-09-13 01:29:10,199 fail2ban.filter [1606]: INFO [recidive] Found 34.48.25.70 - 2026-09-13 01:29:10cloudlinux2 fail2b
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 23:21:06
(50 minutes ago)
(mod_security) mod_security (id:210730) triggered by 34.48.25.70 (70.25.48.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.48.25.70 (70.25.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 19:21:00.365785 2026] [security2:error] [pid 27086:tid 27086] [client 34.48.25.70:52104] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||lazymanvegan.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "lazymanvegan.com"] [uri "/rclone.conf"] [unique_id "aqXeXB0eXORRq2LWuDOXXwAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
neckaralb-admin.de
2026-09-12 23:03:15
(1 hour ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 22:57:43
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.48.25.70 (70.25.48.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.48.25.70 (70.25.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 18:57:36.603682 2026] [security2:error] [pid 9862:tid 9862] [client 34.48.25.70:45178] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lawyerholidaycards.com"] [uri "/%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env"] [unique_id "aqXY4KoY-jPaxxHDRn8TbQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
lavnet.net
2026-09-12 22:32:43
(1 hour ago)
34.48.25.70 - - [12/Sep/2026:22:32:42 +0000] "GET /z9x8c7v6b5-debug-trigger-lavweb.com HTTP/2.0" 404 ...
show more
34.48.25.70 - - [12/Sep/2026:22:32:42 +0000] "GET /z9x8c7v6b5-debug-trigger-lavweb.com HTTP/2.0" 404 286 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
34.48.25.70 - - [12/Sep/2026:22:32:42 +0000] "GET /assets../.env HTTP/2.0" 404 264 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)"
34.48.25.70 - - [12/Sep/2026:22:32:42 +0000] "GET /..%2f.env HTTP/2.0" 404 264 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)"
34.48.25.70 - - [12/Sep/2026:22:32:42 +0000] "GET /..%2f..%2f.env HTTP/2.0" 404 264 "-" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)"
34.48.25.70 - - [12/Sep/2026:22:32:42 +0000] "GET /%2e%2e/.env HTTP/2.0" 400 294 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)"
34.48.25.70 - - [12/Sep/2026:22:32:42 +0000] "GET /auth/login HTTP/2.0" 404 264 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36"
...
show less
Brute-Force
🇧🇪
taivas.nl
2026-09-12 22:32:10
(1 hour ago)
Bad_requests
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-12 22:31:43
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.48.25.70 (70.25.48.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.48.25.70 (70.25.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 18:31:39.531672 2026] [security2:error] [pid 23554:tid 23554] [client 34.48.25.70:43844] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lavozdominicana.com"] [uri "/@fs/../.env"] [unique_id "aqXSy1nnA5RYYeeCk_E2bwAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
pm33
2026-09-12 22:29:35
(1 hour ago)
Excessive crawling HTTP 404
Web App Attack
🇳🇱
middelkoopcc
2026-09-12 22:24:06
(1 hour ago)
2026-09-13 00:22:09 AH10244: invalid URI path (/%2e%2e/.env) && 2026-09-13 00:22:09 AH10244: invalid ...
show more
2026-09-13 00:22:09 AH10244: invalid URI path (/%2e%2e/.env) && 2026-09-13 00:22:09 AH10244: invalid URI path (/public/plugins/alertlist/../../../../../../../../proc/self/environ) && 2026-09-13 00:22:10 AH10244: invalid URI path (/icons/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/proc/self/environ) && 152 more within 20 minutes
show less
Web App Attack
🇳🇱
Savvii
2026-09-12 22:10:38
(2 hours ago)
20 attempts against mh-misbehave-ban on ozone
Brute-Force
Bad Web Bot
Web App Attack