๐ฉ๐ช
kkw
2026-09-02 12:40:21
(12 hours ago)
[REDACTED] 34.88.145.129 - - [02/Sep/2026:14:40:21 +0200] "GET /.git/config HTTP/1.1" 404 561 "-" "M ...
show more
[REDACTED] 34.88.145.129 - - [02/Sep/2026:14:40:21 +0200] "GET /.git/config HTTP/1.1" 404 561 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
... (mode: searching http-sensitive-files)
show less
Bad Web Bot
Web App Attack
๐ญ๐ฐ
nayumi
2026-09-02 12:38:11
(12 hours ago)
CrowdSec detection: crowdsecurity/http-sensitive-files | Service: http, http, http, http, http
Web App Attack
๐ซ๐ฎ
000rosiu
2026-09-02 12:24:41
(13 hours ago)
Triggered Cloudflare WAF (firewallManaged) from FI.
Action: BLOCK | Protocol: HTTP/1.1 (POST) | Endp ...
show more
Triggered Cloudflare WAF (firewallManaged) from FI.
Action: BLOCK | Protocol: HTTP/1.1 (POST) | Endpoint: / | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 โข Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ซ๐ท
masterguru
2026-09-02 12:17:28
(13 hours ago)
Remote Command Execution: Unix Command Injection (command without evasion). Pattern match "(?i)(?:b ...
show more
Remote Command Execution: Unix Command Injection (command without evasion). Pattern match "(?i)(?:b (932235-195)
show less
Hacking
Anonymous
2026-09-02 12:08:14
(13 hours ago)
Automated report from fail2ban.
Detected: automated probing for vulnerable/administrative endpoints ...
show more
Automated report from fail2ban.
Detected: automated probing for vulnerable/administrative endpoints (e.g. wp-login.php, phpMyAdmin) consistent with bot scanning.
Jail: nginx-botsearch
Failed attempts recorded: 2
Report time: 2026-09-02 12:08:14 UTC
This IP has been automatically and permanently blocked at our network perimeter.
Evidence (most recent matched log lines, redacted):
$f2bV_matches
show less
Hacking
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-02 09:31:26
(15 hours ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
etu brutus
2026-09-02 08:24:13
(17 hours ago)
34.88.145.129 has been banned for [WebApp Attack]
...
Hacking
Bad Web Bot
Web App Attack
Anonymous
2026-09-02 07:57:35
(17 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-09-02 07:50:13
(17 hours ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ฉ๐ช
yitzhaq
2026-09-02 07:39:31
(17 hours ago)
34.88.145.129 - - [02/Sep/2026:09:39:29 +0200] "GET /.env~ HTTP/1.1" 404 508 "-" "Mozilla/5.0 (X11; ...
show more
34.88.145.129 - - [02/Sep/2026:09:39:29 +0200] "GET /.env~ HTTP/1.1" 404 508 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.88.145.129 - - [02/Sep/2026:09:39:29 +0200] "GET /.env1 HTTP/1.1" 404 508 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.88.145.129 - - [02/Sep/2026:09:39:29 +0200] "GET /.env2 HTTP/1.1" 404 508 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.88.145.129 - - [02/Sep/2026:09:39:29 +0200] "GET /.env_copy HTTP/1.1" 404 508 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.88.145.129 - - [02/Sep/2026:09:39:29 +0200] "GET /.env.txt HTTP/1.1" 404 508 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.88.145.129 - - [02/Sep/2026:09:39:29 +0200] "GET /.env.json HTTP/
show less
Web App Attack
Hacking
๐ซ๐ท
Octopuce
2026-09-02 07:29:08
(18 hours ago)
Aggressive web search of vulnerable pages: /.env /.env.local /app/.env /apps/.env /api/.env ...
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 06:43:25
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.88.145.129 (129.145.88.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.145.129 (129.145.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 02:43:18.291486 2026] [security2:error] [pid 24922:tid 24922] [client 34.88.145.129:52742] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "torahorah.com"] [uri "/.git/config"] [unique_id "apfFhsAKykPbW0TIqQrqYAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
alferez
2026-09-02 06:22:56
(19 hours ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack
Anonymous
2026-09-02 05:27:56
(20 hours ago)
34.88.145.129 - - [02/Sep/2026:02:27:55 -0300] "GET /.git/config HTTP/1.1" 444 0 "-" "Mozilla/5.0 (M ...
show more
34.88.145.129 - - [02/Sep/2026:02:27:55 -0300] "GET /.git/config HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Port Scan
Hacking
SQL Injection
Brute-Force
Bad Web Bot
Exploited Host
๐ฉ๐ช
FD-IX
2026-09-02 04:27:40
(21 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack