Anonymous
2026-09-30 04:29:31
(14 hours ago)
Blocked by fail2ban on a public web server.
Web App Attack
π©πͺ
paissangroup
2026-09-30 04:14:24
(14 hours ago)
Multiple WAF Violations
Web App Attack
π§πͺ
cmbplf
2026-09-30 03:28:41
(15 hours ago)
886 requests with url.path *.env
358 requests with url.path */@fs/*
100 requests with url.path */ ...
show more
886 requests with url.path *.env
358 requests with url.path */@fs/*
100 requests with url.path */proc/*
show less
Brute-Force
Bad Web Bot
π©πͺ
neckaralb-admin.de
2026-09-30 02:56:37
(16 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
π³π±
Alt255
2026-09-30 02:49:13
(16 hours ago)
[ti-22al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apac ...
show more
[ti-22al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apache-404. Example: 34.90.134.197 - - [30/Sep/2026:04:49:04 +0200] "GET /oql7e356cr5lamoknnov HTTP/2.0" 404 1878 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)"
34.90.134.197 - - [30/Sep/2026:04:49:04 +0200] "GET /z9x8c7v6b5-debug-trigger-download.videodemo.nl HTTP/2.0" 404 1855 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] )"
34.90.134.197 - - [30/Sep/2026:04:49:04 +0200] "GET /x72dc7nmtqkpx2d01zsd HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)"
34.90.134.197 - - [30/Sep/2026:04:49:04 +0200] "POST /graphql HTTP/2.0" 404 1855 "https://download.videodemo.nl" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/5
...
show less
Bad Web Bot
Web App Attack
π©πͺ
raph
2026-09-30 02:16:08
(16 hours ago)
[LIB DIR] crawler /vendor/*, /node_modules/*, /laravel/*, etc.
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-30 02:02:21
(17 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.90.134.197 (197.134.90.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.90.134.197 (197.134.90.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 22:02:13.651681 2026] [security2:error] [pid 4566:tid 4566] [client 34.90.134.197:60162] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||neuromancer.xyz|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "neuromancer.xyz"] [uri "/rclone.conf"] [unique_id "arxtpdjUsd1GT74Zx_vgmQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πͺπΈ
netfactotum
2026-09-30 01:50:13
(17 hours ago)
Hacking
Web App Attack
π©πͺ
Blexyel
2026-09-30 00:47:00
(18 hours ago)
34.90.134.197 - - [30/Sep/2026:02:46:58 +0200] "GET /.git/config HTTP/1.1" 404 14 "-" "Mozilla/5.0 ( ...
show more
34.90.134.197 - - [30/Sep/2026:02:46:58 +0200] "GET /.git/config HTTP/1.1" 404 14 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)"
...
show less
Brute-Force
Web App Attack
π«π·
baphomet
2026-09-30 00:43:37
(18 hours ago)
Probed planted web canary URI (not a real app path).
HTTP request completed against planted URIs (.e ...
show more
Probed planted web canary URI (not a real app path).
HTTP request completed against planted URIs (.env/wp-login/xmlrpc/phpmyadmin/.git).
jail=nginx-canary proto=tcp port=80,443 failures>=2 class=web-app-probe
these paths are not real apps on this host; hit is hostile recon
when=2026-09-30T00:43:37Z sensor=fail2ban role=web-canary
src=34.90.134.197
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-29 22:26:02
(20 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.90.134.197 (197.134.90.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.90.134.197 (197.134.90.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 18:25:56.859895 2026] [security2:error] [pid 3132:tid 3132] [client 34.90.134.197:58952] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||netcastcorp.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "netcastcorp.com"] [uri "/z9x8c7v6b5-debug-trigger-netcastcorp.com"] [unique_id "arw69P9lv7IdjRKjbKJxBQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-29 21:55:06
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.90.134.197 (197.134.90.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.90.134.197 (197.134.90.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 17:54:59.188084 2026] [security2:error] [pid 15306:tid 15306] [client 34.90.134.197:39078] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "network.ic1.biz"] [uri "/.env"] [unique_id "arwzs859ItQmaPORTMLdqgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
ger-stg-sifi1
2026-09-29 21:17:15
(21 hours ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-29 21:15:05
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.90.134.197 (197.134.90.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.90.134.197 (197.134.90.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 17:14:59.345338 2026] [security2:error] [pid 22299:tid 22299] [client 34.90.134.197:42356] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "net-gal.com"] [uri "/.env.development"] [unique_id "arwqU5iqJJt_i2fT3KsRUAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
bigscoots.com
2026-09-29 20:12:55
(23 hours ago)
(PERMBLOCK) 34.90.134.197 (US/United States/197.134.90.34.bc.googleusercontent.com) has had more tha ...
show more
(PERMBLOCK) 34.90.134.197 (US/United States/197.134.90.34.bc.googleusercontent.com) has had more than 4 temp blocks in the last 86400 secs; Ports: *; Direction: 1; Trigger: LF_PERMBLOCK_COUNT; Logs:
show less
Brute-Force
SSH