🇩🇪
Skyrider
2026-06-11 03:40:28
(4 days ago)
Nginx: HTTP 4xx probe/scan attempts. Automated fail2ban report.
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-06-11 02:41:12
(4 days ago)
Web attack/malicious scanning detected
Web App Attack
🇸🇪
nekopavel
2026-06-11 01:29:45
(4 days ago)
34.7.11.78 - - [11/Jun/2026:02:53:26 +0200]"GET /wp-json/gravitysmtp/v1/settings HTTP/1.1" 404 118"- ...
show more
34.7.11.78 - - [11/Jun/2026:02:53:26 +0200]"GET /wp-json/gravitysmtp/v1/settings HTTP/1.1" 404 118"-" mta-sts.neko.chat "Mozilla/5.0 (PLAYSTATION 3; 2.00)""0.001" "0.001""Groningen" "NL"
34.7.11.78 - - [11/Jun/2026:02:53:26 +0200]"GET /wp-json/gravitysmtp/v1/tests/mock-data?page=gravitysmtp-settings HTTP/1.1" 404 118"-" mta-sts.neko.chat "Mozilla/5.0 (X11; U; Linux x86_64; en-US; rv:1.9.1.17) Gecko/20110123 SeaMonkey/2.0.12""0.001" "0.000""Groningen" "NL"
34.7.11.78 - - [11/Jun/2026:02:53:26 +0200]"GET /wp-json/gravitysmtp/v1/tests/mock-data HTTP/1.1" 404 118"-" mta-sts.neko.chat "Mozilla/5.0 (iPhone; CPU iPhone OS 11_4 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/11.0 Mobile/15E148 Safari/604.1""0.000" "0.001""Groningen" "NL"
...
show less
Hacking
Bad Web Bot
Web App Attack
🇫🇷
Rom74
2026-06-10 21:49:51
(4 days ago)
[Wed Jun 10 23:49:51.570507 2026] [security2:error] [pid 1065205:tid 131877952276160] [client 34.7.1 ...
show more
[Wed Jun 10 23:49:51.570507 2026] [security2:error] [pid 1065205:tid 131877952276160] [client 34.7.11.78:41382] [client 34.7.11.78] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "teslogiciels.com"] [uri "/wp-json/gravitysmtp/v1/settings"] [unique_id "ainb_4rBZrYv0Xmla2OoTwAAABE"]
[Wed Jun 10 23:49:51.582955 2026] [security2:error] [pid 1065206:tid 131878969317056] [client 34.7.11.78:41410] [client 34.7.11.78] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Scor
...
show less
Web App Attack
🇩🇪
SCHAPPY
2026-06-10 20:16:18
(4 days ago)
Bad bot identified by user agent
Bad Web Bot
🇫🇷
masterguru
2026-06-10 13:01:19
(5 days ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.7.11.78 (NL/The Netherlands/78.11. ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.7.11.78 (NL/The Netherlands/78.11.7.34.bc.googleusercontent.com): 1 in the last 3600 secs (0-195)
show less
Hacking
🇩🇪
Vegascosmetics
2026-06-10 07:26:00
(5 days ago)
(Kingcopy.org-AI-IDS-Report):IP automatically blocked after suspicious activity. Vegas Security
DDoS Attack
Hacking
Exploited Host
🇨🇭
SOC [GOLINE SA]
2026-06-10 03:11:41
(5 days ago)
[RoutePulse | 2026-06-10T03:11:41Z]
ATTACK: Threat IP Active
SOURCE: 34.7.11.78 · AS396982 Google LL ...
show more
[RoutePulse | 2026-06-10T03:11:41Z]
ATTACK: Threat IP Active
SOURCE: 34.7.11.78 · AS396982 Google LLC · The Netherlands
EVIDENCE: severity=warning · 16 flows · 345 KB
INTEL: AbuseIPDB 94% (18 reports) | RoutePulse score 2/100
MITRE: T1071 Application Layer Protocol
DETECTION: sFlow/IPFIX flow analysis + 14-detector ML stack (6-model weighted ensemble) + threat-intel correlation
ACTION: Pre-blackhole intelligence report (live monitoring continues)
show less
Hacking
Exploited Host
🇩🇪
strxmpp
2026-06-10 01:38:38
(5 days ago)
34.7.11.78 - - [10/Jun/2026:03:38:37 +0200] "GET /wp-json/gravitysmtp/v1/settings HTTP/1.1" 404 4742 ...
show more
34.7.11.78 - - [10/Jun/2026:03:38:37 +0200] "GET /wp-json/gravitysmtp/v1/settings HTTP/1.1" 404 4742 "-" "HTMLParser/1.6"
...
show less
Bad Web Bot
🇨🇭
lufi
2026-06-10 00:55:11
(5 days ago)
2026-06-10T02:55:10+02:00 lufischer04 ids442 2026-06-10 02:55:10 34.7.11.78: blacklisted Pattern: /w ...
show more
2026-06-10T02:55:10+02:00 lufischer04 ids442 2026-06-10 02:55:10 34.7.11.78: blacklisted Pattern: /wp-json
...
show less
Web Spam
Brute-Force
Hacking
Web App Attack
🇬🇧
consul.to
2026-06-10 00:38:03
(5 days ago)
Web attack/malicious scanning detected
Web App Attack
🇬🇧
Interceptor_HQ
2026-06-09 21:16:53
(5 days ago)
request_uri: /wp-json/gravitysmtp/v1/settings -- automatic report --
Brute-Force
Hacking
🇨🇭
ALPHANET
2026-06-09 20:26:38
(5 days ago)
web exploits
Hacking
Exploited Host
Web App Attack
🇨🇭
4server
2026-06-09 17:58:22
(5 days ago)
[TueJun0919:58:15.5293352026][security2:error][pid2197541:tid2197825][client34.7.11.78:0]ModSecurity ...
show more
[TueJun0919:58:15.5293352026][security2:error][pid2197541:tid2197825][client34.7.11.78:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.9\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"aesthetische.beauty.81-17-25-250.cpanel.site\"][uri\"/wp-json/gravitysmtp/v1/settings\"][unique_id\"aihUN5WVac_6dpx-t1RWHgAAARg\"]
show less
Hacking
Web App Attack
🇷🇺
homeodor
2026-06-09 17:21:31
(5 days ago)
Automated scanner detected.
Hacking
Web App Attack