๐ณ๐ฑ
homeshowdomain.nl
2026-10-01 21:59:23
(1 day ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-30.
show less
Web App Attack
SSH
Hacking
๐ฎ๐น
paoloartone
2026-10-01 05:00:29
(2 days ago)
Reverse proxy TCO: 693 richieste malevole bloccate (scan/exploit/brute-force WordPress) il 30/09/202 ...
show more
Reverse proxy TCO: 693 richieste malevole bloccate (scan/exploit/brute-force WordPress) il 30/09/2026.
show less
Web App Attack
Hacking
Port Scan
Anonymous
2026-09-30 13:45:08
(2 days ago)
Observed scanned 9 known-sensitive endpoint(s), e.g.: /.bashrc, /.env, /@fs/.env, /@fs/app/.env, /ad ...
show more
Observed scanned 9 known-sensitive endpoint(s), e.g.: /.bashrc, /.env, /@fs/.env, /@fs/app/.env, /admin/.env, /api/events
show less
Bad Web Bot
Web App Attack
๐ฎ๐น
paoloartone
2026-09-30 05:00:31
(3 days ago)
Reverse proxy TCO: 924 richieste malevole bloccate (scan/exploit/brute-force WordPress) il 29/09/202 ...
show more
Reverse proxy TCO: 924 richieste malevole bloccate (scan/exploit/brute-force WordPress) il 29/09/2026.
show less
Web App Attack
Hacking
Port Scan
๐ฉ๐ช
reznekcs
2026-09-30 05:00:18
(3 days ago)
Blocked by UFW firewall
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-30 04:52:56
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 104.199.69.4 (4.69.199.104.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 104.199.69.4 (4.69.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 00:52:48.518139 2026] [security2:error] [pid 16764:tid 16764] [client 104.199.69.4:33404] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bawaselcenter.iahksa.com|F|2"] [data ".iahksa.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bawaselcenter.iahksa.com"] [uri "/z9x8c7v6b5-debug-trigger-bawaselcenter.iahksa.com"] [unique_id "aryVoF632gX6PDNotgi7GAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 03:42:18
(3 days ago)
(mod_security) mod_security (id:218420) triggered by 104.199.69.4 (4.69.199.104.bc.googleusercontent ...
show more
(mod_security) mod_security (id:218420) triggered by 104.199.69.4 (4.69.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 23:42:12.858346 2026] [security2:error] [pid 16623:tid 16623] [client 104.199.69.4:49932] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i)php://(std(in|out|err)|(in|out)put|fd|memory|temp|filter)" at ARGS_NAMES:\\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/21_PHP_PHPGen.conf"] [line "22"] [id "218420"] [rev "2"] [msg "COMODO WAF: PHP Injection Attack: I/O Stream Found||basse.me|F|2"] [data "Matched Data: php://input found within ARGS_NAMES:\\x5cxadd allow_url_include=1 \\x5cxadd auto_prepend_file=php://input: \\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input"] [severity "CRITICAL"] [tag "CWAF"] [tag "PHPGen"] [hostname "basse.me"] [uri "/index.php"] [unique_id "aryFFNWYoBuVoZJ01LIPEAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐น๐ท
ycoskun41
2026-09-30 02:54:57
(3 days ago)
fail2ban: plesk-modsecurity jail on genckocaeli.com
Web App Attack
Anonymous
2026-09-30 02:16:18
(3 days ago)
Observed scanned 1 known-sensitive endpoint(s), e.g.: /secrets.json
Bad Web Bot
Web App Attack
๐ฉ๐ช
Hazzard
2026-09-30 01:52:37
(3 days ago)
(PERMBLOCK) 104.199.69.4 (BE/Belgium/Brussels Capital/Brussels/4.69.199.104.bc.googleusercontent.com ...
show more
(PERMBLOCK) 104.199.69.4 (BE/Belgium/Brussels Capital/Brussels/4.69.199.104.bc.googleusercontent.com/[redacted]) has had more than 4 temp blocks
show less
Hacking
๐ฉ๐ช
Philister11
2026-09-30 01:14:47
(3 days ago)
CrowdSec: crowdsecurity/http-probing (BE/AS396982)
Web App Attack
Hacking
๐ฉ๐ช
sdos.es
2026-09-30 01:01:53
(3 days ago)
"URL file extension is restricted by policy - .com"
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 01:00:20
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 104.199.69.4 (4.69.199.104.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 104.199.69.4 (4.69.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 21:00:15.847521 2026] [security2:error] [pid 5789:tid 5789] [client 104.199.69.4:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||barryherbach.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "barryherbach.com"] [uri "/z9x8c7v6b5-debug-trigger-barryherbach.com"] [unique_id "arxfH72ci28xuvTTZo8MWQAAADI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-30 00:57:39
(3 days ago)
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encod ...
show more
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encoding/ /proxy/ /lock-token/ /content-range/ /if/ /x-http-method-override/ /x-http-method/ /x-method-override/ /x-middleware-subrequest/ /expect/" at TX:header_name_920450_x-middleware-subrequest. (920450-197)
show less
Bad Web Bot
๐ฉ๐ช
LRob
2026-09-30 00:55:22
(3 days ago)
Crawler ignoring refusals | ua: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perpl ...
show more
Crawler ignoring refusals | ua: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot), Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36; compatibl, Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/) (+13 more) | path: /docker-compose.yml, /api/.env, /.env.prod (+17 more)
show less
Bad Web Bot