Anonymous
2026-09-26 07:04:20
(36 minutes ago)
Aggressive web scan
Web App Attack
๐ฉ๐ช
JLKnoch Software GmbH
2026-09-26 06:49:51
(50 minutes ago)
CrowdSec crowdsecurity/grafana-cve-2021-43798
Brute-Force
Web App Attack
๐บ๐ธ
JustMeHere
2026-09-26 04:34:03
(3 hours ago)
[Sat Sep 26 00:33:57.854219 2026] [security2:error] [pid 803:tid 913] [client 34.77.110.89:54500] Mo ...
show more
[Sat Sep 26 00:33:57.854219 2026] [security2:error] [pid 803:tid 913] [client 34.77.110.89:54500] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.15.0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "account.yorknation.com"] [uri "/"] [unique_id "ardLNaknnGis4iH9alrgbgAAAAY"]
...
show less
Web App Attack
๐ซ๐ฎ
Christopher Hughes
2026-09-26 03:56:53
(3 hours ago)
34.77.110.89 - - [26/Sep/2026:04:56:52 +0100] "GET /backend/.env HTTP/2.0" 200 1455 "-" "Mozilla/5.0 ...
show more
34.77.110.89 - - [26/Sep/2026:04:56:52 +0100] "GET /backend/.env HTTP/2.0" 200 1455 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
...
show less
Web App Attack
Anonymous
2026-09-26 03:50:04
(3 hours ago)
[Sat Sep 26 03:50:03.056201 2026] [security2:error] [pid 2787390:tid 2787390] [client 34.77.110.89:4 ...
show more
[Sat Sep 26 03:50:03.056201 2026] [security2:error] [pid 2787390:tid 2787390] [client 34.77.110.89:47340] [client 34.77.110.89] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "warmides.com"] [uri "/.env.prod"] [unique_id "ardA68U7q82XqHHJaCUPnQAAAAU"]
[Sat Sep 26 03:50:03.373372 2026] [security2:error] [pid 2788592:tid 2788592] [client 34.77.110.89:47342] [client 34.77.110.89] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [sev
...
show less
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-26 03:47:40
(3 hours ago)
20 attempts against mh-misbehave-ban on frost
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐พ
Rizzy
2026-09-26 03:17:17
(4 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ซ๐ท
AGEPCom
2026-09-26 02:51:56
(4 hours ago)
Smart-Ban: IP bannie via score AbuseIPDB
Brute-Force
Web App Attack
๐บ๐ธ
ambor
2026-09-26 01:28:11
(6 hours ago)
L0ss Honeypot: Environment file access attempt. Path: /.env
Web App Attack
๐ฉ๐ช
JLKnoch Software GmbH
2026-09-26 01:17:18
(6 hours ago)
CrowdSec crowdsecurity/http-probing
Brute-Force
Web App Attack
๐ฉ๐ช
itsolon
2026-09-26 01:13:23
(6 hours ago)
[26/Sep/2026:03:13:22 +0200] 179038520269.908158 34.77.110.89 59352 217.154.7.177 443
[26/Sep/2026:0 ...
show more
[26/Sep/2026:03:13:22 +0200] 179038520269.908158 34.77.110.89 59352 217.154.7.177 443
[26/Sep/2026:03:13:23 +0200] 179038520396.918617 34.77.110.89 59346 217.154.7.177 443
[26/Sep/2026:03:13:23 +0200] 179038520319.674593 34.77.110.89 59346 217.154.7.177 443
[26/Sep/2026:03:13:23 +0200] 179038520328.900375 34.77.110.89 59346 217.154.7.177 443
[26/Sep/2026:03:13:23 +0200] 179038520356.230742 34.77.110.89 59346 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
๐ฉ๐ช
Phenix Info
2026-09-26 00:57:50
(6 hours ago)
SmallGuard.fr/Prestashop Forbidden Ext.
Web App Attack
๐ฉ๐ช
maxpower
2026-09-26 00:32:04
(7 hours ago)
(PERMBLOCK) 34.77.110.89 (BE/Belgium/89.110.77.34.bc.googleusercontent.com) has had more than 4 temp ...
show more
(PERMBLOCK) 34.77.110.89 (BE/Belgium/89.110.77.34.bc.googleusercontent.com) has had more than 4 temp blocks in the last 86400 secs; Ports: *; Direction: inout; Trigger: LF_PERMBLOCK_COUNT; Logs:
show less
Port Scan
๐ฉ๐ช
maxpower
2026-09-26 00:09:24
(7 hours ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.77.110.89 (BE/Belgium/89.110.77.34.bc ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.77.110.89 (BE/Belgium/89.110.77.34.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.77.110.89 - - [26/Sep/2026:02:09:20 +0200] "GET /config/secrets.yml HTTP/2.0" 200 4814 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)" "34.77.110.89" host=francescadandrea.com
show less
Port Scan
Anonymous
2026-09-25 23:36:07
(8 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking