Anonymous
2026-10-03 14:03:57
(2 days ago)
Blocked by fail2ban on a public web server.
Web App Attack
π©πͺ
MBombeck
2026-10-02 05:39:35
(3 days ago)
Fail2Ban/traefik-botsearch on apps-01: banned after 5 failures
Web App Attack
π¦πΊ
paulshipley.com.au
2026-10-02 05:30:38
(3 days ago)
[Fri Oct 02 15:30:37.363101 2026] [security2:error] [pid 575984] [client 34.81.113.73:45866] [client ...
show more
[Fri Oct 02 15:30:37.363101 2026] [security2:error] [pid 575984] [client 34.81.113.73:45866] [client 34.81.113.73] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "talentaymerch.com.au"] [uri "/.ssh/config"] [unique_id "ar9BfQwiNCIi9qkBAqI_owAAAAQ"]
...
show less
Web App Attack
π¬π§
openstrike.co.uk
2026-10-02 05:13:43
(3 days ago)
145 attacks on directory traversals, env grabbing URLs, env grabbing URLs (type 2), shell probes, pa ...
show more
145 attacks on directory traversals, env grabbing URLs, env grabbing URLs (type 2), shell probes, password/key grabbing URLs, PHP URLs, config grabbing URLs (type 2):
GET /..%2f..%2f.env HTTP/1.1
GET /static/../../../a/../../../../.env HTTP/1.1
GET /api/fs/read?allowOutsideWorkspace=true&path=/proc/self/environ HTTP/1.1
POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1
GET /id_rsa HTTP/1.1
POST /index.php?-d+allow_url_include%3don+-d+auto_prepend_file%3dphp://input HTTP/1.1
GET /src/amplifyconfiguration.json HTTP/1.1
show less
Hacking
Web App Attack
π«π·
masterguru
2026-10-02 04:43:29
(3 days ago)
BAD BOT - Detected and Blocked.. Matched phrase "bytespider" at REQUEST_HEADERS:User-Agent. (1100000 ...
show more
BAD BOT - Detected and Blocked.. Matched phrase "bytespider" at REQUEST_HEADERS:User-Agent. (1100000-196)
show less
Bad Web Bot
Anonymous
2026-10-02 04:32:53
(3 days ago)
Fail2Ban apache-noscript
Bad Web Bot
π²π½
octageeks.com
2026-10-02 04:24:16
(3 days ago)
Wordpress malicious attack:[octablocked]
Web App Attack
Anonymous
2026-10-02 03:29:34
(3 days ago)
34.81.113.73 - - [02/Oct/2026:05:29:31 +0200] "GET /appearance/../../proc/self/environ HTTP/2.0" 400 ...
show more
34.81.113.73 - - [02/Oct/2026:05:29:31 +0200] "GET /appearance/../../proc/self/environ HTTP/2.0" 400 295 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36; compatible; OAI-SearchBot/1.4; +https://openai.com/searchbot"
34.81.113.73 - - [02/Oct/2026:05:29:32 +0200] "GET /api/attachments/img/avatar/..%2F..%2F..%2F..%2F..%2F.env HTTP/2.0" 404 265 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] )"
34.81.113.73 - - [02/Oct/2026:05:29:32 +0200] "GET /api/attachments/img/avatar/..%2F..%2F..%2F..%2F..%2Fproc%2Fself%2Fenviron HTTP/2.0" 404 265 "-" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)"
34.81.113.73 - - [02/Oct/2026:05:29:33 +0200] "GET /..%2f.env HTTP/2.0" 404 265 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.4; +https://openai.com/gptbot"
34.81.113.73 - - [02/Oct/2026:05:29:34 +0200] "GET /%2e%2e/
...
show less
Brute-Force
SSH
πΊπΈ
TPI-Abuse
2026-10-02 03:07:41
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.81.113.73 (73.113.81.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.113.73 (73.113.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 23:07:34.553183 2026] [security2:error] [pid 22803:tid 22803] [client 34.81.113.73:39966] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "forms.kanata.ws"] [uri "/js../.env"] [unique_id "ar8f9uj4jLtNmclyY7He3QAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
SiyCah
2026-10-02 03:00:03
(3 days ago)
IP banned by fail2ban; banned in jail apache-modsecurity. Report generated by fail2abuseipdb.
Hacking
Brute-Force
Web App Attack
Anonymous
2026-10-02 00:30:26
(3 days ago)
Automated attack pattern on WordPress installation
Bad Web Bot
Web App Attack
π©πͺ
tall1oN
2026-10-01 23:49:14
(3 days ago)
34.81.113.73 - - [02/Oct/2026:01:49:13 +0200] "POST /graphql HTTP/2.0" 405 559 "https://tallion.de" ...
show more
34.81.113.73 - - [02/Oct/2026:01:49:13 +0200] "POST /graphql HTTP/2.0" 405 559 "https://tallion.de" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Mobile Safari/537.36" "tallion.de"
34.81.113.73 - - [02/Oct/2026:01:49:14 +0200] "POST /api/graphql HTTP/2.0" 405 559 "https://tallion.de" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Mobile Safari/537.36" "tallion.de"
...
show less
Web App Attack
Port Scan
Hacking
π§πͺ
cmbplf
2026-10-01 23:17:27
(3 days ago)
3.134 requests from abuseipdb.com blacklisted IP (3mos2w6d)
Brute-Force
Bad Web Bot
π§π·
Sabrina Soto
2026-10-01 22:42:15
(3 days ago)
Probe for vulnerabilities. Path attempted: /.env.production
Web App Attack
π©πͺ
Marcel Bachmann
2026-10-01 22:29:52
(3 days ago)
Automated web scanner detected by HAProxy Security Center. Node: HA03. Reason: Fail2ban HAProxy Scan ...
show more
Automated web scanner detected by HAProxy Security Center. Node: HA03. Reason: Fail2ban HAProxy Scanner
show less
Web App Attack