๐ณ๐ฑ
Site.eu
2026-10-09 00:00:59
(10 hours ago)
Excessive multi-domain requests
Brute-Force
๐ฉ๐ช
Philister11
2026-10-08 23:59:36
(10 hours ago)
CrowdSec: crowdsecurity/http-sensitive-files (JP/AS396982)
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-08 21:15:48
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.84.42.29 (29.42.84.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.42.29 (29.42.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 17:15:41.734690 2026] [security2:error] [pid 13610:tid 13644] [client 34.84.42.29:37160] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.interludes.info"] [uri "/static../.env"] [unique_id "asgH_fHVS9lQBK_gjDy6PQAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
phoenix1jl96
2026-10-08 21:12:00
(13 hours ago)
2026/10/08 23:11:58 [error] 4800#4800: *56520 open() "/home/user-data/www/default/cgi-bin/php-cgi.ex ...
show more
2026/10/08 23:11:58 [error] 4800#4800: *56520 open() "/home/user-data/www/default/cgi-bin/php-cgi.exe" failed (2: No such file or directory), client: 34.84.42.29, server: autoconfig.epouville.info, request: "POST /cgi-bin/php-cgi.exe?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input HTTP/2.0", host: "autoconfig.epouville.info"
2026/10/08 23:11:59 [error] 4800#4800: *56520 open() "/home/user-data/www/default/cgi-bin/php" failed (2: No such file or directory), client: 34.84.42.29, server: autoconfig.epouville.info, request: "POST /cgi-bin/php?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input HTTP/2.0", host: "autoconfig.epouville.info"
...
show less
DNS Compromise
DNS Poisoning
DDoS Attack
Ping of Death
Web Spam
Email Spam
Blog Spam
Port Scan
Hacking
Brute-Force
Bad Web Bot
SSH
Web App Attack
๐ซ๐ท
Lunix
2026-10-08 20:51:55
(14 hours ago)
Brute-Force
Web App Attack
๐ฑ๐น
damorfati
2026-10-08 19:55:54
(15 hours ago)
ANNA automated report (scanning) | hacking - agent:Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hu ...
show more
ANNA automated report (scanning) | hacking - agent:Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/), body: null, method: GET, url: /api/openapi.json
show less
Web App Attack
Hacking
๐ฉ๐ช
Gwyneth Llewelyn
2026-10-08 19:51:17
(15 hours ago)
2026/10/08 20:51:14 [error] 4060693#4060693: *1286833 access forbidden by rule, client: 34.84.42.29, ...
show more
2026/10/08 20:51:14 [error] 4060693#4060693: *1286833 access forbidden by rule, client: 34.84.42.29, server: api.betatechnologies.info, request: "GET /docker/.env HTTP/2.0", host: "api.betatechnologies.info"
2026/10/08 20:51:15 [error] 4060693#4060693: *1286847 access forbidden by rule, client: 34.84.42.29, server: api.betatechnologies.info, request: "GET /static../.env HTTP/2.0", host: "api.betatechnologies.info"
2026/10/08 20:51:15 [error] 4060693#4060693: *1286833 access forbidden by rule, client: 34.84.42.29, server: api.betatechnologies.info, request: "GET /media../.env HTTP/2.0", host: "api.betatechnologies.info"
show less
Brute-Force
Web App Attack
๐บ๐ธ
n2nguyenn2nguyen
2026-10-08 19:19:32
(15 hours ago)
Blocked by YFC Security on https://1904.brixzly.com โ type: directory_scan_attempts
Web App Attack
Anonymous
2026-10-08 18:50:06
(16 hours ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-10-08 18:31:01
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.84.42.29 (29.42.84.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.42.29 (29.42.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 14:30:57.877556 2026] [security2:error] [pid 29481:tid 29481] [client 34.84.42.29:43790] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vfflag.info"] [uri "/media../.env"] [unique_id "asfhYQKNemc1irmLyDD8pgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-08 18:20:25
(16 hours ago)
$f2bV_matches
Brute-Force
๐ณ๐ฑ
Savvii
2026-10-08 18:18:13
(16 hours ago)
20 attempts against mh-misbehave-ban on pf221116
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-10-08 18:02:51
(16 hours ago)
[Fri Oct 09 05:02:51.023366 2026] [security2:error] [pid 553677] [client 34.84.42.29:47236] [client ...
show more
[Fri Oct 09 05:02:51.023366 2026] [security2:error] [pid 553677] [client 34.84.42.29:47236] [client 34.84.42.29] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "paulshipley.info"] [uri "/.ssh/id_rsa"] [unique_id "asfay0fNkoxcFo--ZnvyDAAAAAo"]
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 18:00:48
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.84.42.29 (29.42.84.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.42.29 (29.42.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 14:00:44.670107 2026] [security2:error] [pid 6261:tid 6261] [client 34.84.42.29:38232] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "paardekooper.info"] [uri "/%2e%2e/.env"] [unique_id "asfaTFQroSNjDwkWB5VEHQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 17:35:10
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.84.42.29 (29.42.84.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.42.29 (29.42.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 13:34:57.978761 2026] [security2:error] [pid 6972:tid 6972] [client 34.84.42.29:42640] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ielts-english.info"] [uri "/.env"] [unique_id "asfUQWMMqdQmKSAg9f5QpAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack