🇩🇪
bazter.pro
2026-09-04 14:44:43
(7 hours ago)
Fail2Ban: plesk-bot-aggressive - 15 failures
Port Scan
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 14:05:03
(8 hours ago)
suspicious request in access.log
Web App Attack
🇳🇱
e.fierstra
2026-09-04 13:43:17
(8 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 13:25:33
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.88.158.191 (191.158.88.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.158.191 (191.158.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 09:25:26.195433 2026] [security2:error] [pid 32029:tid 32029] [client 34.88.158.191:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "smtp1.perl-photo.com"] [uri "/.env.example"] [unique_id "aprGxpfxoaTj-MaZz-jBjAAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
hidemail.app
2026-09-04 12:37:14
(9 hours ago)
Automated scan for exposed config/secret files and known web exploits (e.g. /.env, RCE probes); auto ...
show more
Automated scan for exposed config/secret files and known web exploits (e.g. /.env, RCE probes); auto-banned by fail2ban.
show less
Web App Attack
Hacking
🇬🇧
consul.to
2026-09-04 11:34:50
(10 hours ago)
Web attack/malicious scanning detected
Web App Attack
Anonymous
2026-09-04 10:20:13
(12 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
🇫🇷
masterguru
2026-09-04 10:19:58
(12 hours ago)
Attempt to access a backup or working file. Pattern match "\\\\. (920500-193)
Hacking
🇫🇷
Zundapper
2026-09-02 04:52:58
(2 days ago)
34.88.158.191 - - [02/Sep/2026:06:52:57 +0200] "GET /api/config.php HTTP/1.1" 404 27 "-" "Mozilla/5. ...
show more
34.88.158.191 - - [02/Sep/2026:06:52:57 +0200] "GET /api/config.php HTTP/1.1" 404 27 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36"
34.88.158.191 - - [02/Sep/2026:06:52:57 +0200] "GET /api/admin/phpinfo.php HTTP/1.1" 404 27 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36"
34.88.158.191 - - [02/Sep/2026:06:52:57 +0200] "GET /admin/phpinfo.php HTTP/1.1" 404 27 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36"
34.88.158.191 - - [02/Sep/2026:06:52:57 +0200] "GET /Admin/phpinfo.php HTTP/1.1" 404 27 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36"
34.88.158.191 - - [02/Sep/2026:06:52:57 +0200] "GET /api/database.php HTTP/1.1" 404 27 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36"
...
show less
Web App Attack
Port Scan
🇳🇱
Cloud86 B.V.
2026-09-01 23:26:05
(2 days ago)
categories: DDoS Attack
DDoS Attack
🇺🇸
TPI-Abuse
2026-09-01 12:49:01
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.88.158.191 (191.158.88.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.158.191 (191.158.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 08:48:53.890918 2026] [security2:error] [pid 29713:tid 29713] [client 34.88.158.191:38902] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pjv.us.pjvcds.com"] [uri "/.env.save"] [unique_id "apbJtWT-ug0822SVCrKmRAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Little Iguana
2026-09-01 11:20:18
(3 days ago)
Attempt to hack Wordpress Login, XMLRPC or other login
Hacking
🇺🇸
TPI-Abuse
2026-09-01 10:56:08
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.88.158.191 (191.158.88.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.158.191 (191.158.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 06:56:02.446083 2026] [security2:error] [pid 30269:tid 30269] [client 34.88.158.191:36608] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.hanabritgermanshepherds.com"] [uri "/.env.old"] [unique_id "apavQktw9H3Hjf2dkDkZJAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-01 10:44:51
(3 days ago)
Web application attack detected.
Web App Attack
🇫🇷
masterguru
2026-09-01 10:00:42
(3 days ago)
Attempt to access a backup or working file. Pattern match "\\\\. (920500-193)
Hacking