๐ง๐ช
taivas.nl
2026-09-10 04:33:26
(3 weeks ago)
Many_bad_calls
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-09 12:40:55
(3 weeks ago)
Excessive multi-domain requests
Brute-Force
๐ญ๐บ
miszterx.hu
2026-09-09 10:33:41
(3 weeks ago)
XORP (haproxy): 12x HTTP 404/403/500 or handshake failure in 24h. Automated report from log_check_ip ...
show more
XORP (haproxy): 12x HTTP 404/403/500 or handshake failure in 24h. Automated report from log_check_iptables_generator.sh (xorp.hu)
show less
Web App Attack
๐ง๐ช
taivas.nl
2026-09-09 08:32:14
(3 weeks ago)
Bad_requests
Bad Web Bot
๐ช๐ธ
el-brujo
2026-09-09 07:19:46
(3 weeks ago)
09/Sep/2026:09:19:45.739831 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
09/Sep/2026:09:19:45.739831 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 34.78.177.0] ModSecurity: Warning. Pattern match "(?:\\\\\\\\$(?:\\\\\\\\((?:\\\\\\\\(.*\\\\\\\\)|.*)\\\\\\\\)|\\\\\\\\{.*\\\\\\\\})|[<>]\\\\\\\\(.*\\\\\\\\))" at ARGS:0. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "367"] [id "932130"] [msg "Remote Command Execution: Unix Shell Expression Found"] [data "Matched Data: $((41*271)) found within ARGS:0: {then: $1:__proto__:then status: resolved_model reason: -1 value: {then:$b1337} _response: {_prefix: var res=process.mainmodule.require(child_process).execsync(echo $((41*271)) | base64 -w 0).tostring().trim() throw object.assign(new error(next_redirect) {digest: `next_redirect push/login?a=${res} 307 `}) _chunks: $q2 _formdata: {get: $1:constructor:constructor}}}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-shell"] [tag "platform-unix"] [tag "atta
...
show less
Hacking
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-09-08 21:59:56
(3 weeks ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-07.
show less
Web App Attack
SSH
Hacking
๐ณ๐ด
Abuse Buster
2026-09-07 20:56:20
(3 weeks ago)
34.78.177.0 - [07/Sep/2026:22:56:16 +0200] "GET /.git/config HTTP/2.0" 403 548 "-" "Mozilla/5.0 (Win ...
show more
34.78.177.0 - [07/Sep/2026:22:56:16 +0200] "GET /.git/config HTTP/2.0" 403 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" Connecting ip: 34.78.177.0 Forwared for: 34.78.177.0
34.78.177.0 - [07/Sep/2026:22:56:17 +0200] "GET /.env HTTP/2.0" 403 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" Connecting ip: 34.78.177.0 Forwared for: 34.78.177.0
...
show less
Web App Attack
๐ฉ๐ช
paissangroup
2026-09-07 20:05:16
(3 weeks ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
verlon
2026-09-07 20:02:44
(3 weeks ago)
2026/09/07 22:02:29 [error] 1225462#1225462: *709766 access forbidden by rule, client: 34.78.177.0, ...
show more
2026/09/07 22:02:29 [error] 1225462#1225462: *709766 access forbidden by rule, client: 34.78.177.0, server: suitandmore.hu, request: "GET /.git/config HTTP/2.0", host: "suitandmore.hu"
2026/09/07 22:02:39 [error] 1225462#1225462: *709755 access forbidden by rule, client: 34.78.177.0, server: suitandmore.hu, request: "GET /.env.bak HTTP/2.0", host: "suitandmore.hu"
2026/09/07 22:02:41 [error] 1225462#1225462: *709755 access forbidden by rule, client: 34.78.177.0, server: suitandmore.hu, request: "GET /.env.save HTTP/2.0", host: "suitandmore.hu"
...
show less
Hacking
Web App Attack
๐ฌ๐ง
AvonleaConsulting
2026-09-07 11:30:01
(3 weeks ago)
Scanning unused Default website or suspicious access to valid sites from IP marked as abusive
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-07 11:11:12
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.78.177.0 (0.177.78.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.78.177.0 (0.177.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 07:11:07.518717 2026] [security2:error] [pid 2727:tid 2727] [client 34.78.177.0:53410] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "suffecool.suffe.cool"] [uri "/.git/config"] [unique_id "ap6by77Ya7uFZobs9I-oQwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-07 09:21:45
(3 weeks ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
๐ฉ๐ช
raph
2026-09-07 09:16:55
(3 weeks ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-07 09:02:07
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.78.177.0 (0.177.78.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.78.177.0 (0.177.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 05:02:00.331368 2026] [security2:error] [pid 15994:tid 15994] [client 34.78.177.0:44094] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "suedblick.com"] [uri "/.git/config"] [unique_id "ap59iCvc8IBIwNrkHMNpMAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-07 08:42:23
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.78.177.0 (0.177.78.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.78.177.0 (0.177.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 04:42:20.023534 2026] [security2:error] [pid 20393:tid 20414] [client 34.78.177.0:52570] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sue.n2play.net"] [uri "/.git/config"] [unique_id "ap547C4grdKzJv0EBJuf8wAAAJI"]
show less
Brute-Force
Bad Web Bot
Web App Attack