๐จ๐ฆ
polycoda
2026-09-16 10:50:40
(1 day ago)
๐ฅ VERY AGGRESSIVE SCANNER probed over 200 inexistent files and PHP scripts in less than an hour.
Hacking
Web App Attack
๐ฉ๐ช
Gwyneth Llewelyn
2026-09-16 04:02:14
(2 days ago)
34.80.171.121 - - [16/Sep/2026:05:02:10 +0100] "GET /.env HTTP/2.0" 301 162 "-" "Mozilla/5.0 (X11; L ...
show more
34.80.171.121 - - [16/Sep/2026:05:02:10 +0100] "GET /.env HTTP/2.0" 301 162 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
2026/09/16 05:02:11 [error] 2229833#2229833: *1223148 access forbidden by rule, client: 34.80.171.121, server: alzulej.pt, request: "GET /.env HTTP/2.0", host: "alzulej.pt"
34.80.171.121 - - [16/Sep/2026:05:02:11 +0100] "GET /.env HTTP/2.0" 403 1045 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
show less
Brute-Force
Web App Attack
๐ฉ๐ช
EGP Abuse Dept
2026-09-16 02:33:36
(2 days ago)
Scanning for web/db/file exploits on www.jb-tubes.nl
SQL Injection
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 02:16:10
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.80.171.121 (121.171.80.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.171.121 (121.171.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 22:16:07.361387 2026] [security2:error] [pid 1905851:tid 1905851] [client 34.80.171.121:57396] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.jbservicesinc.jbtransportation.net"] [uri "/.git/config"] [unique_id "aqn750dKBAQvzxlbGP81nwAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
polycoda
2026-09-16 02:05:22
(2 days ago)
AutoBlock: ๐ฏ Vulnerability Scanner (Non Decay-Based) - โ๏ธ Configuration File Access (Non Decay-Based ...
show more
AutoBlock: ๐ฏ Vulnerability Scanner (Non Decay-Based) - โ๏ธ Configuration File Access (Non Decay-Based)
show less
Hacking
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-16 00:09:18
(2 days ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-15 22:31:51
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.80.171.121 (121.171.80.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.171.121 (121.171.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 18:31:44.329425 2026] [security2:error] [pid 5436:tid 5436] [client 34.80.171.121:57640] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.jayworthallen.com.drjaymissdiana.com"] [uri "/.git/config"] [unique_id "aqnHUIhd5lCVkrBd3eCh2wAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
melroy89
2026-09-15 21:40:06
(2 days ago)
34.80.171.121 - - [15/Sep/2026:23:39:01 +0200] "GET /phpinfo.php HTTP/1.1" 403 524 "-" "Mozilla/5.0 ...
show more
34.80.171.121 - - [15/Sep/2026:23:39:01 +0200] "GET /phpinfo.php HTTP/1.1" 403 524 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "melroy.org" 0.001
34.80.171.121 - - [15/Sep/2026:23:39:01 +0200] "GET /info.php HTTP/1.1" 403 524 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "melroy.org" 0.000
34.80.171.121 - - [15/Sep/2026:23:39:02 +0200] "GET /php.php HTTP/1.1" 403 524 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "melroy.org" 0.001
34.80.171.121 - - [15/Sep/2026:23:39:02 +0200] "GET /i.php HTTP/1.1" 403 524 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "melroy.org" 0.000
34.80.171.121 - - [15/Sep/2026:23:39:03 +0200] "GET /pi.php HTTP/1.1" 403 524 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) App
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 20:00:33
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.80.171.121 (121.171.80.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.171.121 (121.171.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 16:00:25.024414 2026] [security2:error] [pid 24341:tid 24341] [client 34.80.171.121:36458] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.javierreinoso.com.verdadesreales.com"] [uri "/.git/config"] [unique_id "aqmj2S19Gx8tsBL9qBDMgwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Melle
2026-09-15 19:49:22
(2 days ago)
Blocked by CrowdSec | Scenario: crowdsecurity/http-sensitive-files | 34.80.171.121 triggered 5 event ...
show more
Blocked by CrowdSec | Scenario: crowdsecurity/http-sensitive-files | 34.80.171.121 triggered 5 events | Detected: 2026-09-15T19:49:19.645571169Z
show less
Web App Attack
Hacking
๐ณ๐ฑ
Alt255
2026-09-15 12:16:35
(2 days ago)
[ti-14al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 34. ...
show more
[ti-14al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 34.80.171.121 - - \[15/Sep/2026:14:16:14 +0200\] "GET /.git/config HTTP/1.1" 301 556 "-" "Mozilla/5.0 \(X11\; Linux x86_64\) AppleWebKit/537.36 \(KHTML, like Gecko\) Chrome/131.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-15 11:52:50
(2 days ago)
Web attack/malicious scanning detected
Web App Attack
๐ซ๐ท
dynamix
2026-09-15 11:36:07
(2 days ago)
Multiple WAF Violations
Web App Attack
๐ซ๐ท
dynamix
2026-09-15 09:36:34
(2 days ago)
Automated web vulnerability and path enumeration scan with excessive 404 requests
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2026-09-15 09:33:06
(2 days ago)
block ruleset likely probe for CVE-2025-55182 619E65C9C14E5E741C55CC8FD5E5630F031EBB6A
Web App Attack