Anonymous
2026-09-14 20:30:17
(14 hours ago)
"GET /admin/.env HTTP/1.1"
Hacking
Web App Attack
🇳🇱
Site.eu
2026-09-14 14:26:04
(21 hours ago)
Excessive multi-domain requests
Brute-Force
🇳🇱
e.fierstra
2026-09-14 14:01:52
(21 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇩🇪
gadix
2026-09-14 11:59:19
(23 hours ago)
[14/Sep/2026:13:59:17.529193 +0200] aqfhlaB-7k1h1hLBYBxJhgAAABE 34.75.163.138 50506 127.0.0.1 7081
[ ...
show more
[14/Sep/2026:13:59:17.529193 +0200] aqfhlaB-7k1h1hLBYBxJhgAAABE 34.75.163.138 50506 127.0.0.1 7081
[14/Sep/2026:13:59:17.901658 +0200] aqfhlSLo8HrCiu0UpTMZowAAAAc 34.75.163.138 50850 127.0.0.1 7081
[14/Sep/2026:13:59:18.004187 +0200] aqfhlqNV9TxnkpcB_pqDeQAAAAA 34.75.163.138 50876 127.0.0.1 7081
...
show less
Web App Attack
🇩🇰
HostingGroup
2026-09-14 09:06:53
(1 day ago)
Automated malicious activity (Honeypot Trap) detected and blocked at the CDN edge by NordicCDN Shiel ...
show more
Automated malicious activity (Honeypot Trap) detected and blocked at the CDN edge by NordicCDN Shield. Offenses: 12. First blocked: 2026-09-14.
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-14 01:16:04
(1 day ago)
34.75.163.138 - - [13/Sep/2026:20:16:02 -0500] "GET /config.json HTTP/1.1" 404 1288 "-" "Mozilla/5.0 ...
show more
34.75.163.138 - - [13/Sep/2026:20:16:02 -0500] "GET /config.json HTTP/1.1" 404 1288 "-" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)"
34.75.163.138 - - [13/Sep/2026:20:16:03 -0500] "GET /wp-json HTTP/1.1" 404 1288 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)"
34.75.163.138 - - [13/Sep/2026:20:16:03 -0500] "GET /api/v1/settings HTTP/1.1" 404 1288 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)"
...
show less
Bad Web Bot
🇫🇷
SpaceHost-Server
2026-09-13 22:20:51
(1 day ago)
Brute-Force
Web App Attack
🇳🇱
e.fierstra
2026-09-13 20:35:03
(1 day ago)
excessive HTTP 404 errors
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-13 14:16:26
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.75.163.138 (138.163.75.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.75.163.138 (138.163.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 10:16:19.109233 2026] [security2:error] [pid 28820:tid 28820] [client 34.75.163.138:35872] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||tremulant.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "tremulant.com"] [uri "/rclone.conf"] [unique_id "aqawM6LYtGJ3fBmmqBL4fwAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 12:48:57
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.75.163.138 (138.163.75.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.75.163.138 (138.163.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 08:48:49.331673 2026] [security2:error] [pid 25014:tid 25014] [client 34.75.163.138:37526] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||galaxyretro.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "galaxyretro.com"] [uri "/z9x8c7v6b5-debug-trigger-galaxyretro.com"] [unique_id "aqabsQFtcCtfjSoxdme3nAAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
bazter.pro
2026-09-13 12:39:07
(1 day ago)
Fail2Ban: apache-ratelimit - 20 failures
Port Scan
Bad Web Bot
Web App Attack
🇳🇱
Savvii
2026-09-13 12:38:37
(1 day ago)
20 attempts against mh-misbehave-ban on ozone
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 12:28:35
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.75.163.138 (138.163.75.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.75.163.138 (138.163.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 08:28:28.229168 2026] [security2:error] [pid 19567:tid 19567] [client 34.75.163.138:60020] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||curryfirm.com|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "curryfirm.com"] [uri "/privatekey.key"] [unique_id "aqaW7JhZpj1m-9zwIqcN5wAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
konseptit
2026-09-13 11:25:54
(2 days ago)
(mod_security) mod_security triggered on hostname [redacted] 34.75.163.138 (US/United States/138.163 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.75.163.138 (US/United States/138.163.75.34.bc.googleusercontent.com)
show less
SQL Injection
🇬🇧
bensmithurst
2026-09-13 11:05:22
(2 days ago)
34.75.163.138 - - [13/Sep/2026:11:05:21 +0000] "GET /@fs/..%2f..%2f..%2f..%2f..%2froot/.env HTTP/1.1 ...
show more
34.75.163.138 - - [13/Sep/2026:11:05:21 +0000] "GET /@fs/..%2f..%2f..%2f..%2f..%2froot/.env HTTP/1.1" 400 150 "-" "-"
34.75.163.138 - - [13/Sep/2026:11:05:21 +0000] "GET /@fs/..%2f..%2f..%2f..%2f..%2fproc/self/environ HTTP/1.1" 400 150 "-" "-"
34.75.163.138 - - [13/Sep/2026:11:05:22 +0000] "GET /..%2f.env HTTP/1.1" 400 150 "-" "-"
34.75.163.138 - - [13/Sep/2026:11:05:22 +0000] "GET /%2e%2e/.env HTTP/1.1" 400 150 "-" "-"
34.75.163.138 - - [13/Sep/2026:11:05:22 +0000] "GET /..%2f..%2f.env HTTP/1.1" 400 150 "-" "-"
... [host=LAN***]
show less
Web App Attack