๐ฎ๐ช
AutosOnShow
2026-09-02 04:12:04
(1 hour ago)
blocked for webapp attack | path requested: /.git/config | seen at 2026-09-02 04:11:11.704 |
Web App Attack
๐ฉ๐ช
onlyops.app
2026-09-01 19:00:06
(10 hours ago)
Web application firewall (ModSecurity) detected malicious traffic | detected by Fail2Ban (plesk-mods ...
show more
Web application firewall (ModSecurity) detected malicious traffic | detected by Fail2Ban (plesk-modsecurity jail) | onlyops.app
show less
Exploited Host
๐ณ๐ฟ
Antinson
2026-08-31 01:27:37
(2 days ago)
Requests to unauthorized or suspicious endpoints (.git, .well-known, .php, etc.)
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-31 00:08:49
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.96.36.19 (19.36.96.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.96.36.19 (19.36.96.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 20:08:44.781405 2026] [security2:error] [pid 13361:tid 13361] [client 34.96.36.19:25702] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.10"] [uri "/config/.env"] [unique_id "apTGDA8MXi7xWlA0eTaymQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
swiszczu
2026-08-30 23:56:42
(2 days ago)
Fail2Ban automatic report:
Multiple forbidden requests in short amount of time:
34.96.36.19 - - [31/ ...
show more
Fail2Ban automatic report:
Multiple forbidden requests in short amount of time:
34.96.36.19 - - [31/Aug/2026:01:56:36 +0200] "HEAD / HTTP/1.1" 403 0 "-" "Python-urllib/3.14" "-"
34.96.36.19 - - [31/Aug/2026:01:56:39 +0200] "GET / HTTP/1.1" 403 153 "-" "Mozilla/5.0" "-"
34.96.36.19 - - [31/Aug/2026:01:56:40 +0200] "GET / HTTP/1.1" 403 153 "-" "feroxbuster/2.13.1" "-"
34.96.36.19 - - [31/Aug/2026:01:56:41 +0200] "GET /robots.txt HTTP/1.1" 403 153 "-" "feroxbuster/2.13.1" "-"
34.96.36.19 - - [31/Aug/2026:01:56:41 +0200] "GET / HTTP/1.1" 403 153 "-" "feroxbuster/2.13.1" "-"
34.96.36.19 - - [31/Aug/2026:01:56:41 +0200] "GET /6747fd2b118e4079aaa02f4f1dfb9efa HTTP/1.1" 403 153 "-" "feroxbuster/2.13.1" "-"
34.96.36.19 - - [31/Aug/2026:01:56:41 +0200] "GET /68a6b6bc5b9240e2b1988531a9ee17da301cce1a652b4fc1a126bd01ecf318c22eaf2a80973544bc9ed5a7f7e
show less
Hacking
Web App Attack
๐ณ๐ฑ
Savvii
2026-08-30 03:31:49
(3 days ago)
20 attempts against mh-misbehave-ban on grape
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-30 02:29:11
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.96.36.19 (19.36.96.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.96.36.19 (19.36.96.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 22:29:06.883495 2026] [security2:error] [pid 17352:tid 17352] [client 34.96.36.19:26465] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.250"] [uri "/.htaccess8fbaa9f3052e45d5b587be44e07b8deb"] [unique_id "apOVco1DSG0EHaHaC9zfswAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
sid3windr
2026-08-28 00:07:39
(5 days ago)
GET /.git/config (Tarpitted for 1d15h8m29s, wasted 8.06MB)
Web App Attack
๐ซ๐ท
SSH-Admin
2026-08-27 23:00:42
(5 days ago)
Probing for Exploits
Exploited Host
Web App Attack
๐ซ๐ท
GabrielJST
2026-08-27 10:15:56
(5 days ago)
(mod_security) mod_security triggered on hostname [redacted] 34.96.36.19 (US/United States/19.36.96. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.96.36.19 (US/United States/19.36.96.34.bc.googleusercontent.com): (CF_ENABLE)
show less
SQL Injection
๐ซ๐ท
dynamix
2026-08-26 22:47:48
(6 days ago)
Multiple WAF Violations
Web App Attack
๐ณ๐ฟ
Antinson
2026-08-26 20:54:10
(6 days ago)
Requests to unauthorized or suspicious endpoints (.git, .well-known, .php, etc.)
Bad Web Bot
๐บ๐ธ
jormaster3k
2026-08-26 20:52:56
(6 days ago)
Attack against Apache (too many 404s)
Web App Attack
๐ต๐ฑ
Budyn
2026-08-26 16:09:40
(6 days ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: 51.83.237.XX | URI: / | UA: feroxbuster/2.13.1 | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 12:55:21
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 34.96.36.19 (19.36.96.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.96.36.19 (19.36.96.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 08:55:14.297311 2026] [security2:error] [pid 9721:tid 9721] [client 34.96.36.19:61395] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.96"] [uri "/.htaccess3b058d23e4cb4fe5aad6c982d9ab3702857d5553397348c991940ecf403009dfa4ceee80d994450a861c54e1ffb2e01b"] [unique_id "ao7iMvVU1hKpB2kYP_G93QAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack