🇫🇷
Little Iguana
2026-08-30 23:25:09
(3 hours ago)
trying to access non-authorized port
Port Scan
Anonymous
2026-08-30 23:16:27
(3 hours ago)
94.26.229.187 - - [31/Aug/2026:04:16:23 +0500] "GET /wp-config.php HTTP/1.1" 301 162 "-" "Mozilla/5. ...
show more
94.26.229.187 - - [31/Aug/2026:04:16:23 +0500] "GET /wp-config.php HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:125.0) Gecko/20100101 Firefox/125.0"
94.26.229.187 - - [31/Aug/2026:04:16:23 +0500] "GET /wp-config.php.bak HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14.4; rv:125.0) Gecko/20100101 Firefox/125.0"
94.26.229.187 - - [31/Aug/2026:04:16:24 +0500] "GET /phpinfo.php HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36 Edg/124.0.0.0"
94.26.229.187 - - [31/Aug/2026:04:16:25 +0500] "GET /info.php HTTP/1.1" 301 162 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
94.26.229.187 - - [31/Aug/2026:04:16:26 +0500] "GET /config.php HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14.4; rv:125.0) Gecko/20100101 Firefox/125.0"
94.26.229.187 - - [31/Aug/2026:04:16:26 +0500] "GET /config/config.php HTTP/1.1" 301 162 "-" "Mozilla/5
...
show less
Brute-Force
🇮🇪
AutosOnShow
2026-08-30 22:53:05
(3 hours ago)
blocked for webapp attack | path requested: /.env | seen at 2026-08-30 22:52:18.361 |
Web App Attack
🇳🇱
Jos Moonen
2026-08-30 22:35:52
(4 hours ago)
94.26.229.187 - - [31/Aug/2026:00:35:49 +0200] "GET /.env HTTP/1.1" 200 3 "-" "Mozilla/5.0 (Macintos ...
show more
94.26.229.187 - - [31/Aug/2026:00:35:49 +0200] "GET /.env HTTP/1.1" 200 3 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14.4; rv:125.0) Gecko/20100101 Firefox/125.0"
94.26.229.187 - - [31/Aug/2026:00:35:51 +0200] "GET /wp-config.php HTTP/1.1" 200 3 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
...
show less
Web App Attack
Brute-Force
🇳🇱
Selckie
2026-08-30 22:22:11
(4 hours ago)
fail2ban: NGINX unusual impact
Web App Attack
🇩🇪
XICTRON
2026-08-30 22:15:05
(4 hours ago)
ModSecurity rule violation detected by Fail2Ban
Web App Attack
🇩🇪
Uwe Sarpe
2026-08-30 22:03:13
(4 hours ago)
[Mon Aug 31 00:03:12.974585 2026] [access_compat:error] [pid 60497:tid 60497] [client 94.26.229.187: ...
show more
[Mon Aug 31 00:03:12.974585 2026] [access_compat:error] [pid 60497:tid 60497] [client 94.26.229.187:40322] AH01797: client denied by server configuration: /var/www/.git
[Mon Aug 31 00:03:13.111886 2026] [access_compat:error] [pid 60500:tid 60500] [client 94.26.229.187:40328] AH01797: client denied by server configuration: /var/www/.git
[Mon Aug 31 00:03:13.239086 2026] [access_compat:error] [pid 60499:tid 60499] [client 94.26.229.187:40340] AH01797: client denied by server configuration: /var/www/.git
[Mon Aug 31 00:03:13.373714 2026] [access_compat:error] [pid 60501:tid 60501] [client 94.26.229.187:40344] AH01797: client denied by server configuration: /var/www/.git
[Mon Aug 31 00:03:13.501589 2026] [access_compat:error] [pid 60498:tid 60498] [client 94.26.229.187:40350] AH01797: client denied by server configuration: /var/www/.git
...
show less
Brute-Force
Web App Attack
🇪🇸
alferez
2026-08-30 21:53:00
(4 hours ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-08-30 21:43:52
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 94.26.229.187 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 94.26.229.187 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 17:43:46.262594 2026] [security2:error] [pid 24857:tid 24872] [client 94.26.229.187:52426] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.135"] [uri "/.git/HEAD"] [unique_id "apSkEtaoor72ze8vT9T2EgAAAY0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇪🇸
tg_de
2026-08-30 18:27:05
(8 hours ago)
48 attempts since 30.08.2026 18:26:49 UTC - last search for: /terraform.tfstate.backup
Web App Attack
Anonymous
2026-08-30 18:05:06
(8 hours ago)
WAF repeated trigger detected by Fail2Ban
Web App Attack
🇸🇬
Starburst SysOp Team
2026-08-30 17:51:08
(8 hours ago)
Host header is a numeric IP address. Pattern match "(?:^( (920350-sin2-2)
Hacking
Bad Web Bot
🇺🇸
TPI-Abuse
2026-08-30 17:46:38
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 94.26.229.187 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 94.26.229.187 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 13:46:33.917662 2026] [security2:error] [pid 22681:tid 22681] [client 94.26.229.187:38174] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.155"] [uri "/.git/HEAD"] [unique_id "apRsee6GVAJfR-qHf-U8RAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
MPL
2026-08-30 16:57:01
(9 hours ago)
tcp port scan (12 or more attempts)
Port Scan
🇺🇸
MPL
2026-08-30 16:57:01
(9 hours ago)
tcp port scan (24 or more attempts)
Port Scan