๐ซ๐ฎ
Christopher Hughes
2026-10-09 05:54:39
(10 hours ago)
.env scan
Web App Attack
๐ธ๐ฌ
Cloudkul Cloudkul
2026-10-09 05:21:50
(11 hours ago)
Attempted Not Found (404 status code) requests on our application, more than 30% of their total requ ...
show more
Attempted Not Found (404 status code) requests on our application, more than 30% of their total requests.
show less
Brute-Force
Web App Attack
Anonymous
2026-10-09 05:07:04
(11 hours ago)
Automated web scanner. Requested suspicious paths: /.vite/manifest.json. UTC: 2026-10-09 04:36:44.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 05:01:37
(11 hours ago)
(mod_security) mod_security (id:210730) triggered by 104.155.238.107 (107.238.155.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210730) triggered by 104.155.238.107 (107.238.155.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 01:01:31.538964 2026] [security2:error] [pid 17645:tid 17645] [client 104.155.238.107:33918] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||twilighthackers.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "twilighthackers.com"] [uri "/z9x8c7v6b5-debug-trigger-twilighthackers.com"] [unique_id "ash1K96EoSc1485iOR-XpQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
ismailk
2026-10-09 05:00:04
(11 hours ago)
WordPress attack on tuncayozkan.com (auto-detected): tur=imza ulke=TW puan=100 nginx=14 wf=11 cf=11 ...
show more
WordPress attack on tuncayozkan.com (auto-detected): tur=imza ulke=TW puan=100 nginx=14 wf=11 cf=11 hiz=98 404cesit=79 gizliyol=7. Blocked by adaptive firewall.
show less
Web App Attack
Bad Web Bot
๐ณ๐ฑ
Alt255
2026-10-09 04:49:48
(11 hours ago)
[ti-tinov] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 10 ...
show more
[ti-tinov] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 104.155.238.107 - - \[09/Oct/2026:06:49:28 +0200\] "GET /api/fs/read\?allowOutsideWorkspace=true\&path=/app/.env HTTP/1.1" 404 6011 "-" "Mozilla/5.0 \(compatible\; YouBot/1.0\; +https://you.com/bot\)"
...
show less
Bad Web Bot
Web App Attack
๐ง๐ช
taivas.nl
2026-10-09 04:32:47
(12 hours ago)
Many_bad_calls
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 04:23:41
(12 hours ago)
(mod_security) mod_security (id:210730) triggered by 104.155.238.107 (107.238.155.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210730) triggered by 104.155.238.107 (107.238.155.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 00:23:38.287514 2026] [security2:error] [pid 5687:tid 5687] [client 104.155.238.107:40270] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||thecrimsonpirate.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "thecrimsonpirate.com"] [uri "/z9x8c7v6b5-debug-trigger-thecrimsonpirate.com"] [unique_id "ashsSlFMzQkk-M_rMN-gDAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
MatCat
2026-10-09 04:05:09
(12 hours ago)
Banned by fail2ban: apache-noscript, apache-webprobe
Port Scan
Hacking
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-10-09 03:38:44
(13 hours ago)
excessive HTTP 404 errors
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-09 03:26:06
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.155.238.107 (107.238.155.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.155.238.107 (107.238.155.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 23:25:59.962450 2026] [security2:error] [pid 23031:tid 23031] [client 104.155.238.107:35564] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thechoiceint.com"] [uri "/files../.env"] [unique_id "ashex2hT2YA--kpkCFIPvAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Apache
2026-10-09 03:12:23
(13 hours ago)
(mod_security) mod_security (id:218420) triggered by 104.155.238.107 (TW/Taiwan/107.238.155.104.bc.g ...
show more
(mod_security) mod_security (id:218420) triggered by 104.155.238.107 (TW/Taiwan/107.238.155.104.bc.googleusercontent.com): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
๐บ๐ธ
antlac1
2026-10-09 03:05:21
(13 hours ago)
crowdsecurity/http-path-traversal-probing
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 02:42:55
(13 hours ago)
(mod_security) mod_security (id:210730) triggered by 104.155.238.107 (107.238.155.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210730) triggered by 104.155.238.107 (107.238.155.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 22:42:47.893093 2026] [security2:error] [pid 17907:tid 17907] [client 104.155.238.107:48454] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||theburiednews.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "theburiednews.com"] [uri "/z9x8c7v6b5-debug-trigger-theburiednews.com"] [unique_id "ashUp7OYXJJQJvrPZD0bgwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dwmp
2026-10-09 02:31:38
(14 hours ago)
[09/Oct/2026:04:31:36.960612 +0200] ashSCPdR1JviDRE8dy7PvAAAARA 104.155.238.107 56192 38.242.227.117 ...
show more
[09/Oct/2026:04:31:36.960612 +0200] ashSCPdR1JviDRE8dy7PvAAAARA 104.155.238.107 56192 38.242.227.117 7081
[09/Oct/2026:04:31:36.969182 +0200] ashSCF1sEOs-bbZSK2tcowAAAAU 104.155.238.107 56206 38.242.227.117 7081
[09/Oct/2026:04:31:37.510148 +0200] ashSCfdR1JviDRE8dy7PwQAAARE 104.155.238.107 56268 38.242.227.117 7081
...
show less
Brute-Force
SSH