🇩🇪
wpadm4
2026-09-08 09:32:15
(18 minutes ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇳🇱
JCB
2026-09-08 09:10:00
(41 minutes ago)
34.50.182.79 - - [08/Sep/2026:04:15:16 +0300] "GET /@fs/home/www-data/.aws/credentials?raw?? HTTP/1. ...
show more
34.50.182.79 - - [08/Sep/2026:04:15:16 +0300] "GET /@fs/home/www-data/.aws/credentials?raw?? HTTP/1.1" 404 236 "-" "Mozilla/5.0 (compatible; Claude-User/1.0; [email protected] )"
34.50.182.79 - - [08/Sep/2026:04:15:16 +0300] "GET /@fs/root/.aws/credentials.backup?raw?? HTTP/1.1" 404 236 "-" "Mozilla/5.0 (compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexity-user)"
...
show less
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-08 08:53:03
(58 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.50.182.79 (79.182.50.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.50.182.79 (79.182.50.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 04:52:54.914082 2026] [security2:error] [pid 2047:tid 2047] [client 34.50.182.79:18066] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.bendergloves.com"] [uri "/@fs/root/.env"] [unique_id "ap_M5jdNPx7uw7z_GnkG4QAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 07:46:57
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.50.182.79 (79.182.50.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.50.182.79 (79.182.50.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 03:46:49.554595 2026] [security2:error] [pid 11704:tid 11704] [client 34.50.182.79:9218] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "buffaloweddingdeejay.com"] [uri "/@fs/root/.env"] [unique_id "ap-9aVqjuZ29kjX6e469rQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 06:45:27
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.50.182.79 (79.182.50.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.50.182.79 (79.182.50.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 02:45:22.320065 2026] [security2:error] [pid 8229:tid 8229] [client 34.50.182.79:28772] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.pasamugo.com"] [uri "/@fs/root/.env"] [unique_id "ap-vAjjd8Wvgu4agn7r7oAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
Aetherweb Ark
2026-09-08 06:12:03
(3 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.50.182.79 (US/United States/79.182.50.34.bc. ...
show more
(mod_security) mod_security (id:949110) triggered by 34.50.182.79 (US/United States/79.182.50.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
Anonymous
2026-09-08 05:24:58
(4 hours ago)
34.50.182.79 - - [08/Sep/2026:06:55:28 +0200] "GET HTTP/1.1" 403 1856 "-" "Mozilla/5.0 AppleWebKit/ ...
show more
34.50.182.79 - - [08/Sep/2026:06:55:28 +0200] "GET HTTP/1.1" 403 1856 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Google-Extended/1.0; +http://www.google.com/bot.html)"
show less
Web Spam
Blog Spam
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 04:55:33
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.50.182.79 (79.182.50.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.50.182.79 (79.182.50.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 00:55:28.241316 2026] [security2:error] [pid 1110:tid 1110] [client 34.50.182.79:27200] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.saramics.net"] [uri "/@fs/.env"] [unique_id "ap-VQOqr7FIH3c-KxmcKiAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 04:44:02
(5 hours ago)
Multiple web server 400 error codes from same source ip
Web App Attack
🇳🇱
Site.eu
2026-09-08 04:36:40
(5 hours ago)
Excessive multi-domain requests
Brute-Force
🇧🇪
cmbplf
2026-09-08 04:32:21
(5 hours ago)
583 requests with url.path *.config/*
277 requests with url.path *.ssh/*
179 requests with url.pa ...
show more
583 requests with url.path *.config/*
277 requests with url.path *.ssh/*
179 requests with url.path */auth.json
show less
Brute-Force
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-08 04:08:36
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.50.182.79 (79.182.50.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.50.182.79 (79.182.50.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 00:08:29.670133 2026] [security2:error] [pid 19881:tid 19881] [client 34.50.182.79:30634] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.photospecialties.net"] [uri "/@fs/.env"] [unique_id "ap-KPUL19zLVw3jIsGQFxgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
ctidrv
2026-09-08 03:33:58
(6 hours ago)
Honeypot detection. Threat score: 100/100. Collector: honeypot. | Request: GET /@fs/proc/self/enviro ...
show more
Honeypot detection. Threat score: 100/100. Collector: honeypot. | Request: GET /@fs/proc/self/environ?raw?? | UA: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ChatGPT-User/1.0; +https://openai.com/bot) | rDNS: 79.182.50.34.bc.googleusercontent.com | Attacks detected: path_traversal | Reasons: bot_keyword, suspicious_path, no_sec_fetch, no_cookies, attack:path_traversal
show less
Web App Attack
Bad Web Bot
Anonymous
2026-09-08 03:18:21
(6 hours ago)
Web application attack detected.
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 02:50:34
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.50.182.79 (79.182.50.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.50.182.79 (79.182.50.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 22:50:27.452487 2026] [security2:error] [pid 32635:tid 32635] [client 34.50.182.79:34730] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.tbnkardesler.com"] [uri "/@fs/root/.env"] [unique_id "ap9382a1EoJ7-1X8sJ9yjQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack