🇩🇪
Starburst SysOp Team
2026-09-06 07:19:18
(1 day ago)
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .back/ .b ...
show more
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .back/ .backup/ .bak/ .bck/ .bk/ .bkp/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .cnf/ .com/ .compositefont/ .config/ .conf/ .copy/ .crt/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dist/ .dll/ .dos/ .dpkg-dist/ .drv/ .gadget/ .hta/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .inf/ .ini/ .jks/ .jse/ .key/ .licx/ .lnk/ .log/ .mdb/ .msc/ .ocx/ .old/ .pass/ .pdb/ .pfx/ .pif/ .pem/ .pol/ .prf/ .printer/ .pwd/ .rdb/ .rdp/ .reg/ .resources/ .resx/ .sav/ .save/ .scr/ .sct/ .sh/ .shs/ .sql/ .sqlite/ .sqlite3/ .swap/ .swo/ .swp/ .sys/ .temp/ .tfstate/ .tlb/ .tmp/ .vb/ .vbe/ .vbs/ .vbproj/ .vsdisco/ .vxd/ .webinfo/ .ws/ .wsc/ .wsf/ .wsh/ .xsd/ .xsx/" at TX:extension. (920440-nue6-2)
show less
Hacking
Anonymous
2026-09-06 06:22:02
(1 day ago)
Bot / scanning and/or hacking attempts: GET /_ignition/health-check HTTP/1.1, GET /.env.example HTTP ...
show more
Bot / scanning and/or hacking attempts: GET /_ignition/health-check HTTP/1.1, GET /.env.example HTTP/1.1
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:49:36
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.88.99.87 (87.99.88.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.99.87 (87.99.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:49:33.066963 2026] [security2:error] [pid 3717825:tid 3717825] [client 34.88.99.87:35798] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.mordesign1.com"] [uri "/wp-config.php.bak"] [unique_id "apzizWIvjHv6n0nwZJRQiQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-06 03:36:51
(1 day ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇮🇹
Inartis
2026-09-06 03:36:34
(1 day ago)
34.88.99.87 - - [06/Sep/2026:05:36:33 +0200] "GET /.env.local HTTP/1.1" 403 5027 "-" "crusader-worke ...
show more
34.88.99.87 - - [06/Sep/2026:05:36:33 +0200] "GET /.env.local HTTP/1.1" 403 5027 "-" "crusader-worker/1.0"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:32:02
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.88.99.87 (87.99.88.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.99.87 (87.99.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:31:57.776313 2026] [security2:error] [pid 11466:tid 11466] [client 34.88.99.87:45696] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cielocr.com"] [uri "/.env"] [unique_id "apzerReX1RgQQnQD6xv2VwAAACk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 02:26:39
(1 day ago)
Multiple web server 400 error codes from same source ip
Web App Attack
🇸🇪
SkyDancer
2026-09-06 02:11:28
(1 day ago)
Multiple unauthorized attempts to access using wrong credentials. Attack automatically blocked by Sk ...
show more
Multiple unauthorized attempts to access using wrong credentials. Attack automatically blocked by SkyDancer Ai. EXT-SYS-Vx
show less
Hacking
Brute-Force
SSH
🇦🇺
FireGuard Server
2026-09-06 01:35:05
(1 day ago)
Blocked by os-abuseipdb; 76 hits, proto=tcp, ports=443
Port Scan
Hacking
🇫🇷
dynamix
2026-09-06 01:30:30
(1 day ago)
Multiple WAF Violations
Web App Attack
🇫🇮
YF
2026-09-06 00:31:18
(1 day ago)
WordPress config file probe
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 00:16:29
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.88.99.87 (87.99.88.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.99.87 (87.99.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:16:25.671819 2026] [security2:error] [pid 30640:tid 30640] [client 34.88.99.87:52930] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "alecmcatee.com"] [uri "/.env"] [unique_id "apyw2XEzkPs6FaIOyur2cQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 23:52:07
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.88.99.87 (87.99.88.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.99.87 (87.99.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:52:02.791697 2026] [security2:error] [pid 22722:tid 22722] [client 34.88.99.87:49052] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nolenelam.com"] [uri "/.env"] [unique_id "apyrIuN5P05u6fMB1t3v5gAAADw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-05 22:57:34
(1 day ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇮🇹
clamehost.it
2026-09-05 22:39:56
(1 day ago)
Automatic report - Brute Force attack using this IP address
Brute-Force