🇵🇱
sledzik1984
2026-09-08 01:24:13
(7 minutes ago)
34.92.133.247 - - [08/Sep/2026:03:24:12 +0200] "GET /admin/phpinfo.php HTTP/1.1" 404 188 "-" "Mozill ...
show more
34.92.133.247 - - [08/Sep/2026:03:24:12 +0200] "GET /admin/phpinfo.php HTTP/1.1" 404 188 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.92.133.247 - - [08/Sep/2026:03:24:12 +0200] "GET /test/phpinfo.php HTTP/1.1" 404 188 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.92.133.247 - - [08/Sep/2026:03:24:12 +0200] "GET /dev/phpinfo.php HTTP/1.1" 404 188 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Web App Attack
🇫🇷
YF
2026-09-08 01:01:18
(30 minutes ago)
Attaque distribuée subnet
DDoS Attack
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 20:41:20
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.92.133.247 (247.133.92.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.92.133.247 (247.133.92.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 16:41:15.452355 2026] [security2:error] [pid 10040:tid 10040] [client 34.92.133.247:36392] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vmbinc.com"] [uri "/.git/config"] [unique_id "ap8ha3CPJDmKp7-CiMuYQAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
blik2108
2026-09-07 18:40:54
(6 hours ago)
vm20.blacknell.co.uk:443 34.92.133.247 - - [07/Sep/2026:19:40:47 +0100] "POST / HTTP/1.1" 404 561 "- ...
show more
vm20.blacknell.co.uk:443 34.92.133.247 - - [07/Sep/2026:19:40:47 +0100] "POST / HTTP/1.1" 404 561 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
vm20.blacknell.co.uk:443 34.92.133.247 - - [07/Sep/2026:19:40:47 +0100] "POST / HTTP/1.1" 404 561 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
vm20.blacknell.co.uk:443 34.92.133.247 - - [07/Sep/2026:19:40:47 +0100] "POST / HTTP/1.1" 404 561 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
vm20.blacknell.co.uk:443 34.92.133.247 - - [07/Sep/2026:19:40:48 +0100] "GET /.git/config HTTP/1.1" 404 561 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
vm20.blacknell.co.uk:443 34.92.133.247 - - [07/Sep/2026:19:40:48 +0100] "POST / HTTP/1.1" 404 561 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like
...
show less
Brute-Force
🇳🇱
Site.eu
2026-09-07 18:40:20
(6 hours ago)
Excessive 404/403 errors
Brute-Force
🇫🇮
oh.mg
2026-09-07 18:26:57
(7 hours ago)
[Mon Sep 07 20:26:55.987977 2026] [security2:error] [pid 2681733:tid 2681745] [client 34.92.133.247: ...
show more
[Mon Sep 07 20:26:55.987977 2026] [security2:error] [pid 2681733:tid 2681745] [client 34.92.133.247:0] [client 34.92.133.247] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.10.0-dev"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "vm109.sup.coop"] [uri "/.env.txt"] [unique_id "ap8B74HWRKlFQIwFkoE3zAAAAME"]
[Mon Sep 07 20:26:56.287384 2026] [security2:error] [pid 2681733:tid 2681768] [client 34.92.133.247:0] [client 34.92.133.247] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.10.0-dev"] [tag "ano
...
show less
Web App Attack
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-07 17:47:04
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.92.133.247 (247.133.92.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.92.133.247 (247.133.92.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 13:46:58.719183 2026] [security2:error] [pid 26423:tid 26423] [client 34.92.133.247:39402] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vm.ostborg.com"] [uri "/.git/config"] [unique_id "ap74kvO9S5LR4lB0vvwPSgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Progetto1
2026-09-07 17:40:01
(7 hours ago)
Detected via HAProxyScanner at 2026-09-07 17:40:01 UTC on destination port WEB (80/443). Repeated sc ...
show more
Detected via HAProxyScanner at 2026-09-07 17:40:01 UTC on destination port WEB (80/443). Repeated scan / connection.
show less
Port Scan
Hacking
Brute-Force
🇺🇸
TPI-Abuse
2026-09-07 17:11:19
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.92.133.247 (247.133.92.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.92.133.247 (247.133.92.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 13:11:15.872333 2026] [security2:error] [pid 19574:tid 19574] [client 34.92.133.247:44380] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vm-srl.com"] [uri "/.git/config"] [unique_id "ap7wMyrHP7W31T1RgSkfvwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-07 16:30:02
(9 hours ago)
CrowdSec decision: crowdsecurity/http-sensitive-files (origin: crowdsec)
Web App Attack
🇩🇪
FeG Deutschland
2026-09-07 14:46:25
(10 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 27
Exploited Host
Web App Attack
🇳🇱
e.fierstra
2026-09-07 12:54:41
(12 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇳🇱
middelkoopcc
2026-09-07 12:46:01
(12 hours ago)
2026-09-07 14:44:03 GET /.git/config [404] && 2026-09-07 14:44:03 GET /.env [404] && 2026-09-07 14:4 ...
show more
2026-09-07 14:44:03 GET /.git/config [404] && 2026-09-07 14:44:03 GET /.env [404] && 2026-09-07 14:44:13 GET /app/.env [404] && 151 more within 20 minutes
show less
Web App Attack
🇳🇱
debestelapp
2026-09-07 12:45:12
(12 hours ago)
Web App Attack
🇩🇪
BlueWire Hosting
2026-09-07 09:33:50
(15 hours ago)
High-confidence malicious configuration/VCS probe
Web App Attack