๐ณ๐ฑ
Site.eu
2026-10-07 10:09:24
(6 hours ago)
Excessive multi-domain requests
Brute-Force
๐ฌ๐ง
sc user
2026-10-07 00:48:06
(15 hours ago)
Fail2Ban nginx: repeated suspicious HTTP requests consistent with automated probing, scanning or bad ...
show more
Fail2Ban nginx: repeated suspicious HTTP requests consistent with automated probing, scanning or bad bot behaviour. Technical log details and local server identifiers intentionally omitted for privacy.
show less
Bad Web Bot
Web App Attack
Port Scan
๐ฉ๐ช
Holger
2026-10-06 17:42:44
(22 hours ago)
Bruteforce WebAttack
Brute-Force
Web App Attack
๐ธ๐ฌ
khairilgunawan
2026-10-05 12:32:12
(2 days ago)
ZonaKuota Sentinel: Malicious automated scanner/exploit probe trapped. Blocked.
Web App Attack
Bad Web Bot
๐ซ๐ฎ
Christopher Hughes
2026-10-05 12:05:25
(2 days ago)
34.62.3.214 - - [05/Oct/2026:13:05:25 +0100] "GET /gcp-service.json HTTP/2.0" 200 1456 "-" "Mozilla/ ...
show more
34.62.3.214 - - [05/Oct/2026:13:05:25 +0100] "GET /gcp-service.json HTTP/2.0" 200 1456 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
...
show less
Web App Attack
๐บ๐ธ
WizardsToolkit
2026-10-05 11:58:30
(2 days ago)
tried to access server backup files
Web App Attack
Anonymous
2026-10-05 11:18:26
(2 days ago)
fail2ban jail apache-secrets-probe: 34.62.3.214 - - [05/Oct/2026:04:18:22 -0700] "GET /cache/origina ...
show more
fail2ban jail apache-secrets-probe: 34.62.3.214 - - [05/Oct/2026:04:18:22 -0700] "GET /cache/original/%2e%2e/.env HTTP/1.1" 404 65489 "-" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)"
show less
Web App Attack
๐บ๐ธ
chrisj
2026-10-05 11:08:29
(2 days ago)
[Mon Oct 05 11:08:28.540705 2026] [proxy_fcgi:error] [pid 162926:tid 162952] [remote 34.62.3.214:558 ...
show more
[Mon Oct 05 11:08:28.540705 2026] [proxy_fcgi:error] [pid 162926:tid 162952] [remote 34.62.3.214:55832] AH01071: Got error 'Primary script unknown'
[Mon Oct 05 11:08:28.546855 2026] [proxy_fcgi:error] [pid 162926:tid 162953] [remote 34.62.3.214:55832] AH01071: Got error 'Primary script unknown'
[Mon Oct 05 11:08:28.831893 2026] [proxy_fcgi:error] [pid 162926:tid 162961] [remote 34.62.3.214:55832] AH01071: Got error 'Primary script unknown'
...
show less
Brute-Force
๐ฟ๐ฆ
vanderhost
2026-10-05 11:08:26
(2 days ago)
[Laravel HoneypotPlus] Automated report - Honeypot access detected on path: /config/firebase-admin.j ...
show more
[Laravel HoneypotPlus] Automated report - Honeypot access detected on path: /config/firebase-admin.json via rule: /config
show less
Web App Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-05 10:27:34
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.62.3.214 (214.3.62.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.62.3.214 (214.3.62.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 06:27:27.868839 2026] [security2:error] [pid 11923:tid 11923] [client 34.62.3.214:34078] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||tmarketingproducts.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "tmarketingproducts.com"] [uri "/z9x8c7v6b5-debug-trigger-tmarketingproducts.com"] [unique_id "asN7j2zldv71-C2n6XwucQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-10-05 09:58:43
(2 days ago)
20 attempts against mh-misbehave-ban on mensa
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-05 09:44:04
(2 days ago)
34.62.3.214 - - [05/Oct/2026:04:43:57 -0500] "GET /.env?raw?? HTTP/1.1" 403 199 "http://synapseresul ...
show more
34.62.3.214 - - [05/Oct/2026:04:43:57 -0500] "GET /.env?raw?? HTTP/1.1" 403 199 "http://synapseresults.com/@fs/../.env?raw??" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)" 172.71.119.79
34.62.3.214 - - [05/Oct/2026:04:44:01 -0500] "GET /.env?import&raw?? HTTP/1.1" 403 199 "http://synapseresults.com/@fs/../.env?import&raw??" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)" 172.71.119.79
34.62.3.214 - - [05/Oct/2026:04:44:02 -0500] "GET /.env?raw HTTP/1.1" 301 247 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)" 172.71.118.148
34.62.3.214 - - [05/Oct/2026:04:44:02 -0500] "GET /.env?import&raw HTTP/1.1" 301 258 "-" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)" 172.69.222.249
34.62.3.214 - - [05/Oct/2026:04:44:02 -0500] "GET /.env?raw HTTP/1.1" 403 199 "http://synapseresults.com/.env?raw" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)" 172.71.119.79
34.62.3.214 - - [05/Oct/202
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
roxyapi
2026-10-05 08:14:23
(2 days ago)
Honeypot: automated vulnerability scan / web app attack. Last probe: GET /.dockerenv
Web App Attack
Bad Web Bot
๐บ๐ธ
ph
2026-10-05 06:48:56
(2 days ago)
Bad web bot attempting to run wp-json on non-WP site
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
antlac1
2026-10-05 05:50:41
(2 days ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack