๐ณ๐ฑ
Site.eu
2026-10-02 00:23:23
(1 day ago)
Excessive multi-domain requests
Brute-Force
๐ฉ๐ช
grassau.com
2026-10-01 15:45:19
(1 day ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 34.60.58.39 (US/Unit ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 34.60.58.39 (US/United States/Iowa/Council Bluffs/39.58.60.34.bc.googleusercontent.com)
show less
Bad Web Bot
๐บ๐ธ
Sonoflet
2026-10-01 14:56:36
(1 day ago)
CrowdSec detection | scenario: http-bad-user-agent
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-01 14:54:47
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.60.58.39 (39.58.60.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.60.58.39 (39.58.60.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 10:54:42.499304 2026] [security2:error] [pid 4051:tid 4051] [client 34.60.58.39:38290] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.goldengatecorgis.org"] [uri "/.env.js"] [unique_id "ar50MmLcGZt1WdW2AaVnEAAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-01 14:25:08
(1 day ago)
[honeypot-scan] 2026-10-01 14:25:08, Client: 34.60.58.39, Protocol: 6 (TCP), Service: HTTP, Activity ...
show more
[honeypot-scan] 2026-10-01 14:25:08, Client: 34.60.58.39, Protocol: 6 (TCP), Service: HTTP, Activity: bait-path scan (.env/.git probing)
show less
Web App Attack
๐ฉ๐ช
BiancaNL
2026-10-01 14:15:31
(1 day ago)
Fail2Ban: jail=code-runner-scanner-probe on <fqdn> (port=<port>)
Hacking
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-10-01 13:42:52
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐ซ๐ท
dynamix
2026-10-01 13:15:54
(1 day ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
macrob
2026-10-01 13:04:39
(1 day ago)
2026/10/01 13:04:37 [error] 1652779#1652779: *4938122 access forbidden by rule, client: 34.60.58.39, ...
show more
2026/10/01 13:04:37 [error] 1652779#1652779: *4938122 access forbidden by rule, client: 34.60.58.39, server: fn.binixo.es, request: "GET /dist/.vite/manifest.json HTTP/2.0", host: "feedback.wellbin.org"
2026/10/01 13:04:37 [error] 1652779#1652779: *4938124 access forbidden by rule, client: 34.60.58.39, server: fn.binixo.es, request: "GET /.vite/manifest.json HTTP/2.0", host: "feedback.wellbin.org"
2026/10/01 13:04:38 [error] 1652784#1652784: *4938131 access forbidden by rule, client: 34.60.58.39, server: fn.binixo.es, request: "GET /admin HTTP/2.0", host: "feedback.wellbin.org"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 12:57:36
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.60.58.39 (39.58.60.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.60.58.39 (39.58.60.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 08:57:31.395229 2026] [security2:error] [pid 8238:tid 8238] [client 34.60.58.39:53366] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.helpkccare.org"] [uri "/.env.js"] [unique_id "ar5Yu9gHtjSIiVhyD_MpLgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
dot.mg
2026-10-01 12:50:12
(1 day ago)
Scan of vulnerable files
Web App Attack
Anonymous
2026-10-01 12:16:24
(1 day ago)
PROTO=TCP DPT=8080
Port Scan
Hacking
๐ซ๐ท
JPPO
2026-10-01 10:53:06
(2 days ago)
Multiport scan 4 ports : 80 443 8080 8443
Port Scan
๐ฑ๐น
NotACaptcha
2026-10-01 10:33:09
(2 days ago)
Unauthorised access (Oct 1 13:33) SRC=34.60.58.39 LEN=60 TTL=59 ID=25461 DF TCP DPT=8080 WINDOW=653 ...
show more
Unauthorised access (Oct 1 13:33) SRC=34.60.58.39 LEN=60 TTL=59 ID=25461 DF TCP DPT=8080 WINDOW=65320 SYN
show less
Port Scan