π³π±
Mangelot Hosting
2026-09-28 07:04:09
(21 hours ago)
(php_susp_dir) srv104 PHP Suspicious Directory 34.70.200.68 (US/United States/68.200.70.34.bc.google ...
show more
(php_susp_dir) srv104 PHP Suspicious Directory 34.70.200.68 (US/United States/68.200.70.34.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-28 06:21:38
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.70.200.68 (68.200.70.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.70.200.68 (68.200.70.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 02:21:30.670665 2026] [security2:error] [pid 5942:tid 5942] [client 34.70.200.68:37404] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "the-it-man.com"] [uri "/.git/config"] [unique_id "aroHar_5UadcgdZPImIy4gAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
Little Iguana
2026-09-27 16:29:32
(1 day ago)
Attempt to hack Wordpress Login, XMLRPC or other login
Hacking
π§π·
vfAcceloReporter
2026-09-27 15:15:41
(1 day ago)
34.70.200.68 - - [27/Sep/2026:12:15:40 -0300] "GET /.env HTTP/1.1" 301 169 "-" "Mozilla/5.0 (Macinto ...
show more
34.70.200.68 - - [27/Sep/2026:12:15:40 -0300] "GET /.env HTTP/1.1" 301 169 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Brute-Force
Web App Attack
Exploited Host
π³π±
Site.eu
2026-09-27 04:07:55
(1 day ago)
Excessive 404/403 errors
Brute-Force
πΊπΈ
TPI-Abuse
2026-09-26 11:13:33
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.70.200.68 (68.200.70.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.70.200.68 (68.200.70.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 07:13:28.632059 2026] [security2:error] [pid 19451:tid 19451] [client 34.70.200.68:42628] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "abbeygardensllandudno.com"] [uri "/.git/config"] [unique_id "areo2CDPca2L0FPh61cRnAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-26 10:24:45
(2 days ago)
[server.tmg.gr] httpd-config-scan: sites=www.mastermind.gr; logs=/var/log/httpd/domains/tmg.gr.log; ...
show more
[server.tmg.gr] httpd-config-scan: sites=www.mastermind.gr; logs=/var/log/httpd/domains/tmg.gr.log; samples=/.git/config | /.env | /.env.local
show less
Hacking
Web App Attack
π³π±
Savvii
2026-09-25 17:03:10
(3 days ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
grassau.com
2026-09-24 17:27:01
(4 days ago)
(mod_security) mod_security triggered on hostname [redacted] 34.70.200.68 (US/United States/Iowa/Cou ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.70.200.68 (US/United States/Iowa/Council Bluffs/68.200.70.34.bc.googleusercontent.com)
show less
SQL Injection
πΊπΈ
TPI-Abuse
2026-09-24 01:33:23
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.70.200.68 (68.200.70.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.70.200.68 (68.200.70.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 21:33:17.148907 2026] [security2:error] [pid 25398:tid 25398] [client 34.70.200.68:42086] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "toxicwater.com"] [uri "/.git/config"] [unique_id "arR93df9Q-pSuurop2F9AwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¨π
zynex
2026-09-22 09:08:04
(6 days ago)
URL Probing: /server/.env
Web App Attack
π³π±
homeshowdomain.nl
2026-09-21 22:03:14
(1 week ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-20.
show less
Web App Attack
SSH
Hacking
πΊπΈ
mnsf
2026-09-21 17:05:42
(1 week ago)
Scanning/Probing (12)
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 02:06:21
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.70.200.68 (68.200.70.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.70.200.68 (68.200.70.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 22:06:15.126244 2026] [security2:error] [pid 21170:tid 21170] [client 34.70.200.68:49150] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "votefordave.org"] [uri "/.git/config"] [unique_id "arCRF0iDQSID0T4PVSNU3AAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack