๐ฎ๐ช
Jim Keir
2026-08-28 06:34:40
(5 hours ago)
2026-08-28 06:34:40 34.56.149.66 File scanning, blocking 34.56.149.66 for 5 minutes
Web App Attack
Anonymous
2026-08-27 22:35:15
(13 hours ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
๐ฉ๐ช
hackthetime
2026-08-27 22:13:29
(13 hours ago)
Tried to access .env file (`/.env.bak`) [which does not exist]
Web App Attack
๐ฎ๐ช
AutosOnShow
2026-08-27 21:50:04
(14 hours ago)
blocked for webapp attack | path requested: / | seen at 2026-08-27 21:49:18.767 |
Web App Attack
๐ซ๐ท
LoneRider
2026-08-27 21:02:44
(15 hours ago)
[27/Aug/2026:23:02:44.327043 +0200] apCl9CCJ1Mt0p-6eugStGwAAAAE 34.56.149.66 44460 127.0.0.1 7081
[2 ...
show more
[27/Aug/2026:23:02:44.327043 +0200] apCl9CCJ1Mt0p-6eugStGwAAAAE 34.56.149.66 44460 127.0.0.1 7081
[27/Aug/2026:23:02:44.386462 +0200] apCl9GI0BNOex8kexTFabAAAAAA 34.56.149.66 44470 127.0.0.1 7081
[27/Aug/2026:23:02:44.395594 +0200] apCl9LK9GddJg3SruUKqdQAAAAU 34.56.149.66 44498 127.0.0.1 7081
...
show less
Hacking
Anonymous
2026-08-27 20:27:02
(15 hours ago)
[Thu Aug 27 22:27:01.223598 2026] [access_compat:error] [pid 2667] [client 34.56.149.66:50776] AH017 ...
show more
[Thu Aug 27 22:27:01.223598 2026] [access_compat:error] [pid 2667] [client 34.56.149.66:50776] AH01797: client denied by server configuration: /var/www/html/.env
[Thu Aug 27 22:27:01.225391 2026] [access_compat:error] [pid 2668] [client 34.56.149.66:50804] AH01797: client denied by server configuration: /var/www/html/.env.backup
[Thu Aug 27 22:27:01.230359 2026] [access_compat:error] [pid 2559] [client 34.56.149.66:50836] AH01797: client denied by server configuration: /var/www/html/.env.dev
...
show less
Web App Attack
๐ฎ๐น
mediarama.com
2026-08-27 19:18:07
(16 hours ago)
Banned by Fail2Ban
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 19:16:14
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.56.149.66 (66.149.56.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.56.149.66 (66.149.56.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 15:16:06.733400 2026] [security2:error] [pid 7323:tid 7444] [client 34.56.149.66:55450] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kd9uri.com"] [uri "/.env"] [unique_id "apCM9vne9eOBn6uhxkmDngAAAQE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
Burayot
2026-08-27 18:15:35
(17 hours ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 34.56.149.66 (US/United States/66.1 ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 34.56.149.66 (US/United States/66.149.56.34.bc.googleusercontent.com): 1 in the last 3600 secs
show less
Web App Attack
๐ง๐ช
Saec
2026-08-27 17:38:01
(18 hours ago)
Jarvis auto-ban: CF top attacker on saec.ovh (26 hits, US)
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 17:37:50
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.56.149.66 (66.149.56.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.56.149.66 (66.149.56.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 13:37:42.642038 2026] [security2:error] [pid 30518:tid 30518] [client 34.56.149.66:46584] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jerryhazlett.com"] [uri "/wp-config.php~"] [unique_id "apB15v_-T42bRLpAj3F9cQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 16:56:37
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.56.149.66 (66.149.56.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.56.149.66 (66.149.56.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 12:56:29.574396 2026] [security2:error] [pid 4797:tid 4797] [client 34.56.149.66:45752] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "martinsgenser.com"] [uri "/.env"] [unique_id "apBsPUoKC7uXQGQ6a7eYNQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-08-27 16:40:02
(19 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
Anonymous
2026-08-27 16:22:28
(19 hours ago)
RdpGuard detected brute-force attempt on HTTP
Brute-Force
๐ซ๐ท
โจ
2026-08-27 16:22:04
(19 hours ago)
Domain : comunicados-cgt.es
Rule : env
2026-08-27 16:20:24 ***hidden-privacy*** GET /.env.bak - 443 ...
show more
Domain : comunicados-cgt.es
Rule : env
2026-08-27 16:20:24 ***hidden-privacy*** GET /.env.bak - 443 - 34.56.149.66 HTTP/1.1 crusader-worker/1.0 - comunicados-cgt.es 301 0 0 555 98 275 - -
show less
Hacking
SQL Injection