๐ฉ๐ช
MBombeck
2026-08-30 06:01:15
(1 day ago)
Fail2Ban/traefik-botsearch on apps-01: banned after 5 failures
Web App Attack
๐ณ๐ฑ
DonAtari
2026-08-30 05:04:29
(1 day ago)
DShield firewall scan - TCP to port 8080
Brute-Force
SSH
๐ฌ๐ง
Artelis
2026-08-30 02:48:30
(1 day ago)
34.75.9.206 - - [30/Aug/2026:02:48:29 +0000] "GET /.env.bak HTTP/1.1" 404 146 "-" "crusader-worker/1 ...
show more
34.75.9.206 - - [30/Aug/2026:02:48:29 +0000] "GET /.env.bak HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
...
show less
Web App Attack
๐ธ๐ช
SkyDancer
2026-08-30 02:38:36
(1 day ago)
Multiple unauthorized attempts to access using wrong credentials. Attack automatically blocked by Sk ...
show more
Multiple unauthorized attempts to access using wrong credentials. Attack automatically blocked by SkyDancer Ai. EXT-SYS-Vx
show less
Hacking
Brute-Force
SSH
๐ฏ๐ต
Green_
2026-08-30 02:34:29
(1 day ago)
fail2ban pubweb-trap ban
Port Scan
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-08-30 02:08:29
(1 day ago)
Try to access /.env
Web App Attack
๐ญ๐บ
miszterx.hu
2026-08-29 06:08:48
(2 days ago)
XORP (haproxy): 3x HTTP 404/403/500 or handshake failure in 24h. Automated report from log_check_ipt ...
show more
XORP (haproxy): 3x HTTP 404/403/500 or handshake failure in 24h. Automated report from log_check_iptables_generator.sh (xorp.hu)
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 03:16:41
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.75.9.206 (206.9.75.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.75.9.206 (206.9.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 23:16:35.440098 2026] [security2:error] [pid 31528:tid 31528] [client 34.75.9.206:42748] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "platinumkissband.com"] [uri "/.env.example"] [unique_id "apJPE82xC7oBIzviqxemKAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
โจ
2026-08-29 02:53:12
(2 days ago)
Domain : seanicweb.co.uk
Rule : hack
2026-08-29 02:51:01 ***hidden-privacy*** GET /wp-config.php.bak ...
show more
Domain : seanicweb.co.uk
Rule : hack
2026-08-29 02:51:01 ***hidden-privacy*** GET /wp-config.php.bak - 443 - 34.75.9.206 HTTP/1.1 crusader-worker/1.0 - www.seanicweb.co.uk 404 0 2 1443 108 93 - -
show less
Hacking
SQL Injection
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-29 02:09:53
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.75.9.206 (206.9.75.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.75.9.206 (206.9.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 22:09:47.247924 2026] [security2:error] [pid 31749:tid 31749] [client 34.75.9.206:41194] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.go.azultigre.com"] [uri "/wp-config.php.swp"] [unique_id "apI_a3g63GG1TicItEhgYAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
MBombeck
2026-08-29 01:45:37
(2 days ago)
Fail2Ban/traefik-botsearch on apps-01: banned after 5 failures
Web App Attack
๐ฉ๐ช
maxpower
2026-08-29 01:35:30
(2 days ago)
(nginx_hardened) REGOLA 3 - Nginx Hardening Triggered 34.75.9.206 (US/United States/206.9.75.34.bc.g ...
show more
(nginx_hardened) REGOLA 3 - Nginx Hardening Triggered 34.75.9.206 (US/United States/206.9.75.34.bc.googleusercontent.com): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 2026/08/29 03:35:29 [error] 1941216#1941216: *882301 access forbidden by rule, client: 34.75.9.206, server: arkon.it, request: "GET /wp-config.php.bak HTTP/1.1", host: "thekna.eu"
2026/08/29 03:35:29 [error] 1941221#1941221: *882304 access forbidden by rule, client: 34.75.9.206, server: arkon.it, request: "GET /wp-config.php~ HTTP/1.1", host: "thekna.eu"
2026/08/29 03:35:29 [error] 1941209#1941209: *882307 access forbidden by rule, client: 34.75.9.206, server: arkon.it, request: "GET /wp-config.php.swp HTTP/1.1", host: "thekna.eu"
show less
Port Scan
๐บ๐ธ
entangled_mongoose
2026-08-29 01:06:33
(2 days ago)
Probed /wp-config.php.swp.
Web App Attack
Anonymous
2026-08-29 01:05:02
(2 days ago)
suspicious request in access.log
Web App Attack
๐ง๐ท
noconex
2026-08-29 01:04:07
(2 days ago)
Wazuh Alert | Rule ID: 110100 | Desc: Suricata: Exploit (ET WEB_SERVER Tilde in URI - potential .php ...
show more
Wazuh Alert | Rule ID: 110100 | Desc: Suricata: Exploit (ET WEB_SERVER Tilde in URI - potential .php~ source disclosure vulnerability) 34.75.9.206
show less
Port Scan
Brute-Force
SSH