🇩🇪
ghostwarriors
2026-09-09 23:50:07
(5 hours ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
🇩🇪
yitzhaq
2026-09-09 23:49:46
(5 hours ago)
34.65.222.184 - - [10/Sep/2026:01:49:44 +0200] "GET /backup/.env HTTP/1.1" 404 518 "-" "Mozilla/5.0 ...
show more
34.65.222.184 - - [10/Sep/2026:01:49:44 +0200] "GET /backup/.env HTTP/1.1" 404 518 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.65.222.184 - - [10/Sep/2026:01:49:44 +0200] "GET /backups/.env HTTP/1.1" 404 518 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.65.222.184 - - [10/Sep/2026:01:49:44 +0200] "GET /old/.env HTTP/1.1" 404 518 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.65.222.184 - - [10/Sep/2026:01:49:44 +0200] "GET /tmp/.env HTTP/1.1" 404 518 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.65.222.184 - - [10/Sep/2026:01:49:44 +0200] "GET /temp/.env HTTP/1.1" 404 518 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.65.222.184 - - [10/Sep/2026:01:49:44 +0200] "GET
show less
Web App Attack
Hacking
🇫🇷
dynamix
2026-09-09 22:11:44
(7 hours ago)
Multiple WAF Violations
Web App Attack
🇳🇱
e.fierstra
2026-09-09 20:37:24
(9 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇮🇹
CoreTech srl
2026-09-09 20:33:57
(9 hours ago)
cloudlinux2 fail2ban: 2026-09-09 22:29:13,194 fail2ban.filter [1892]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-09-09 22:29:13,194 fail2ban.filter [1892]: INFO [plesk-wordpress] Found 67.205.28.4 - 2026-09-09 22:29:12cloudlinux2 fail2ban: 2026-09-09 22:30:49,304 fail2ban.filter [1892]: INFO [plesk-wordpress] Found 136.144.19.38 - 2026-09-09 22:30:45cloudlinux2 fail2ban: 2026-09-09 22:31:52,588 fail2ban.filter [1892]: INFO [plesk-modsecurity] Found 34.65.222.184 - 2026-09-09 22:31:52cloudlinux2 fail2ban: 2026-09-09 22:31:52,540 fail2ban.filter [1892]: INFO [plesk-modsecurity] Found 34.65.222.184 - 2026-09-09 22:31:52cloudlinux2 fail2ban: 2026-09-09 22:31:52,428 fail2ban.filter [1892]: INFO [plesk-modsecurity] Found 34.65.222.184 - 2026-09-09 22:31:52cloudlinux2 fail2ban: 2026-09-09 22:31:52,485 fail2ban.filter [1892]: INFO [plesk-modsecurity] Found 34.65.222.184 - 2026-09-09 22:31:52cloudlinux2 fail2ban: 2026-09-09 22:31:52,512 fail2ban.filter [1892]: INFO [plesk-modsecurity] Found 34.65.222.184 - 2026-09-09 22:31:52c
show less
Web App Attack
Anonymous
2026-09-09 20:07:40
(9 hours ago)
Automatically blocked after 97 security events. Observed sensitive configuration-file probes. Source ...
show more
Automatically blocked after 97 security events. Observed sensitive configuration-file probes. Source: Cloudflare security controls.
show less
Hacking
Web App Attack
🇨🇭
zynex
2026-09-09 19:11:43
(10 hours ago)
URL Probing: /public/.env
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 18:51:22
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.65.222.184 (184.222.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.222.184 (184.222.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 14:51:16.403376 2026] [security2:error] [pid 913:tid 913] [client 34.65.222.184:52112] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "oruguitas.org"] [uri "/.git/config"] [unique_id "aqGqpN-j4Slr2VxFAaPQngAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-09-09 15:50:01
(13 hours ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 15:11:01
(14 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.65.222.184 (184.222.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:949110) triggered by 34.65.222.184 (184.222.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 11:10:55.034544 2026] [security2:error] [pid 18931:tid 18931] [client 34.65.222.184:48784] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.gatewayacoustics.armstrongenvironmental.com"] [uri "/.git/config"] [unique_id "aqF2_zh-AqkTsoonB8xS3AAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-09 14:49:31
(14 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
🇫🇷
masterguru
2026-09-09 10:48:21
(18 hours ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
🇮🇹
VHosting
2026-09-09 10:15:03
(19 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack