๐ฉ๐ช
ghostwarriors
2026-09-01 02:50:10
(10 hours ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ฉ๐ช
yitzhaq
2026-09-01 02:47:22
(10 hours ago)
34.80.52.196 - - [01/Sep/2026:04:47:17 +0200] "POST / HTTP/1.1" 200 665 "-" "Mozilla/5.0 (Windows NT ...
show more
34.80.52.196 - - [01/Sep/2026:04:47:17 +0200] "POST / HTTP/1.1" 200 665 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.80.52.196 - - [01/Sep/2026:04:47:17 +0200] "GET /.git/config HTTP/1.1" 403 515 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.80.52.196 - - [01/Sep/2026:04:47:17 +0200] "GET /.env HTTP/1.1" 404 512 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.80.52.196 - - [01/Sep/2026:04:47:17 +0200] "GET /.env.local HTTP/1.1" 404 512 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.80.52.196 - - [01/Sep/2026:04:47:18 +0200] "GET /.env.production HTTP/1.1" 404 512 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.80.52.196 -
show less
Web App Attack
Hacking
๐ต๐ฑ
lns.bz
2026-09-01 02:20:24
(10 hours ago)
Web app attack [PL.Lu]
Exploited Host
Web App Attack
Anonymous
2026-09-01 00:43:02
(12 hours ago)
Bot / scanning and/or hacking attempts: GET /live/.env HTTP/1.1, GET /public_html/.env HTTP/1.1, GET ...
show more
Bot / scanning and/or hacking attempts: GET /live/.env HTTP/1.1, GET /public_html/.env HTTP/1.1, GET /var/www/.env HTTP/1.1, GET /build/.env HTTP/1.1, GET /html/.env HTTP/1.1, GET /htdocs/.env HTTP/1.1, GET /.env.yaml HTTP/1.1, GET /symfony/.env HTTP/1.1, GET /var/www/html/.env HTTP/1.1, GET /shared/.env HTTP/1.1, GET /releases/.env HTTP/1.1, GET /dev/.env HTTP/1.1, GET /current/.env HTTP/1.1, GET /prod/.env HTTP/1.1, GET /opt/.env HTTP/1.1, GET /staging/.env HTTP/1.1, GET /deploy/.env HTTP/1.1, GET /www/.env HTTP/1.1, GET /release/.env HTTP/1.1, GET /laravel/.env HTTP/1.1, GET /dist/.env HTTP/1.1
show less
Hacking
Web App Attack
๐ฌ๐ง
noise.agency
2026-08-31 17:19:59
(19 hours ago)
34.80.52.196 (TW/Taiwan/196.52.80.34.bc.googleusercontent.com), more than 10 Apache 403 hits
Hacking
๐บ๐ฆ
URAN Publishing Service
2026-08-31 15:43:45
(21 hours ago)
[31/Aug/2026:18:43:44 +0300] -- 34.80.52.196 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/ ...
show more
[31/Aug/2026:18:43:44 +0300] -- 34.80.52.196 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/config HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 14:06:35
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.80.52.196 (196.52.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.52.196 (196.52.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 10:06:29.983126 2026] [security2:error] [pid 28701:tid 28701] [client 34.80.52.196:54924] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "suretrap.com"] [uri "/.git/config"] [unique_id "apWKZZPxNYCP_UXfk0wAnwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Lee Daniel
2026-08-31 13:42:35
(23 hours ago)
34.80.52.196 - - [31/Aug/2026:09:42:34 -0400] "GET /.env HTTP/1.1" 403 6297 "-" "Mozilla/5.0 (Macint ...
show more
34.80.52.196 - - [31/Aug/2026:09:42:34 -0400] "GET /.env HTTP/1.1" 403 6297 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
DDoS Attack
Web Spam
Email Spam
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
zumbo.net
2026-08-31 13:17:01
(23 hours ago)
[Mon Aug 31 16:16:55.367624 2026] [proxy_fcgi:error] [pid 153479:tid 153526] [client 34.80.52.196:0] ...
show more
[Mon Aug 31 16:16:55.367624 2026] [proxy_fcgi:error] [pid 153479:tid 153526] [client 34.80.52.196:0] AH01071: Got error 'Primary script unknown'
[Mon Aug 31 16:16:55.581176 2026] [proxy_fcgi:error] [pid 153479:tid 153524] [client 34.80.52.196:0] AH01071: Got error 'Primary script unknown'
[Mon Aug 31 16:16:59.920580 2026] [proxy_fcgi:error] [pid 153479:tid 153533] [client 34.80.52.196:0] AH01071: Got error 'Primary script unknown'
[Mon Aug 31 16:17:00.125750 2026] [proxy_fcgi:error] [pid 153479:tid 153507] [client 34.80.52.196:0] AH01071: Got error 'Primary script unknown'
[Mon Aug 31 16:17:00.357092 2026] [proxy_fcgi:error] [pid 153477:tid 153492] [client 34.80.52.196:0] AH01071: Got error 'Primary script unknown'
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 12:01:09
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.80.52.196 (196.52.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.52.196 (196.52.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 08:01:04.889855 2026] [security2:error] [pid 26095:tid 26112] [client 34.80.52.196:39526] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "supradig.com"] [uri "/.git/config"] [unique_id "apVtAI3fAnv0IHndOZsadgAAAM0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Octopuce
2026-08-31 11:54:44
(1 day ago)
Aggressive web search of vulnerable pages: /.env /.env.local /app/.env /apps/.env /api/.env ...
Web App Attack
๐ฎ๐น
CoreTech srl
2026-08-31 11:43:56
(1 day ago)
cloudlinux2 fail2ban: 2026-08-31 13:39:03,365 fail2ban.actions [1605]: NOTICE [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-08-31 13:39:03,365 fail2ban.actions [1605]: NOTICE [plesk-modsecurity] Unban 34.19.232.245cloudlinux2 fail2ban: 2026-08-31 13:39:15,433 fail2ban.filter [1605]: INFO [plesk-modsecurity] Found 104.23.225.114 - 2026-08-31 13:39:15cloudlinux2 fail2ban: 2026-08-31 13:39:15,420 fail2ban.filter [1605]: INFO [plesk-modsecurity] Found 104.23.225.115 - 2026-08-31 13:39:15cloudlinux2 fail2ban: 2026-08-31 13:40:51,516 fail2ban.filter [1605]: INFO [recidive] Found 34.80.52.196 - 2026-08-31 13:40:51cloudlinux2 fail2ban: 2026-08-31 13:40:51,481 fail2ban.filter [1605]: INFO [plesk-modsecurity] Found 34.80.52.196 - 2026-08-31 13:40:51cloudlinux2 fail2ban: 2026-08-31 13:40:51,053 fail2ban.filter [1605]: INFO [plesk-modsecurity] Found 34.80.52.196 - 2026-08-31 13:40:51cloudlinux2 fail2ban: 2026-08-31 13:40:50,630 fail2ban.filter [1605]: INFO [plesk-modsecurity] Found 34.80.52.196 - 2026-08-31 13:40:50cloudlinux2 fail2ban: 2026-0
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-31 11:11:56
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.80.52.196 (196.52.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.52.196 (196.52.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 07:11:49.254221 2026] [security2:error] [pid 30559:tid 30559] [client 34.80.52.196:39718] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "supportaretroops.com"] [uri "/.git/config"] [unique_id "apVhdekw0oknYc936xOzPgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-08-31 10:29:53
(1 day ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.git/config (+1 more) | 2026-08-31 10:29 UTC
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 10:14:20
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.80.52.196 (196.52.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.52.196 (196.52.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 06:14:14.110961 2026] [security2:error] [pid 14212:tid 14212] [client 34.80.52.196:42834] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "support.tbvfc.com"] [uri "/.git/config"] [unique_id "apVT9mS4YUK0APwldUnuCwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack