π©πͺ
jack252
2026-10-08 23:00:00
(32 minutes ago)
2026/10/09 00:59:58 [error] 1331#1331: *129302 open() "/etc/nginx/html/cgi-bin/php-cgi.exe" failed ( ...
show more
2026/10/09 00:59:58 [error] 1331#1331: *129302 open() "/etc/nginx/html/cgi-bin/php-cgi.exe" failed (2: No such file or directory), client: 136.70.5.89, server: smarthomeklar.de, request: "POST /cgi-bin/php-cgi.exe?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input HTTP/2.0", host: "smarthomeklar.de"
2026/10/09 00:59:59 [error] 1331#1331: *129302 open() "/etc/nginx/html/cgi-bin/php" failed (2: No such file or directory), client: 136.70.5.89, server: smarthomeklar.de, request: "POST /cgi-bin/php?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input HTTP/2.0", host: "smarthomeklar.de"
2026/10/09 00:59:59 [error] 1331#1331: *129302 open() "/etc/nginx/html/cgi-bin/php-cgi" failed (2: No such file or directory), client: 136.70.5.89, server: smarthomeklar.de, request: "POST /cgi-bin/php-cgi?-d+allow_url_include%3don+-d+auto_prepend_file%3dphp://input HTTP/2.0", host: "smarthomeklar.de"
...
show less
Brute-Force
Bad Web Bot
π©πͺ
ger-stg-sifi1
2026-10-08 22:43:04
(48 minutes ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
π³π±
debestelapp
2026-10-08 22:35:08
(56 minutes ago)
Web App Attack
π§πΎ
lns.bz
2026-10-08 22:04:38
(1 hour ago)
Too many 404 requests [BY]
Web App Attack
π³π±
homeshowdomain.nl
2026-10-08 22:00:01
(1 hour ago)
Auto-ban: >3000 req/min op 2026-10-08
Web App Attack
SSH
Hacking
πΏπ¦
conure.sh
2026-10-08 21:51:20
(1 hour ago)
csagent: score 19.6: 404 noise floor x28, php 404 x2, secrets grab x1; 2 domain(s) in 11s
Web App Attack
π―π΅
bokumin.org
2026-10-08 21:42:54
(1 hour ago)
[id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [uri "/"] [id "949110"] [msg " ...
show more
[id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [uri "/"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"]
show less
Web App Attack
π³π±
Alt255
2026-10-08 21:36:49
(1 hour ago)
[ti-11al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-11al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 136.70.5.89 - - [08/Oct/2026:23:36:38 +0200] "GET /.ssh/id_rsa HTTP/2.0" 301 289 "-" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)"
...
show less
Bad Web Bot
Web App Attack
π©πͺ
konseptit
2026-10-08 21:30:44
(2 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 136.70.5.89 (US/United States/89.5.70.1 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 136.70.5.89 (US/United States/89.5.70.136.bc.googleusercontent.com)
show less
SQL Injection
πΊπΈ
TPI-Abuse
2026-10-08 21:29:07
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 136.70.5.89 (89.5.70.136.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 136.70.5.89 (89.5.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 17:29:02.778909 2026] [security2:error] [pid 14877:tid 14877] [client 136.70.5.89:57396] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||slusarczyk.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "slusarczyk.com"] [uri "/z9x8c7v6b5-debug-trigger-slusarczyk.com"] [unique_id "asgLHoOosP6RrUmqk0Ct1gAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
consul.to
2026-10-08 21:23:21
(2 hours ago)
Web attack/malicious scanning detected
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-08 21:08:10
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 136.70.5.89 (89.5.70.136.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 136.70.5.89 (89.5.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 17:08:05.766378 2026] [security2:error] [pid 30708:tid 30708] [client 136.70.5.89:56488] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||slovenia-boat-registration.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "slovenia-boat-registration.com"] [uri "/z9x8c7v6b5-debug-trigger-slovenia-boat-registration.com"] [unique_id "asgGNaaBaHfEXuoQdLwVqQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
mnsf
2026-10-08 20:05:29
(3 hours ago)
Too many Status 40X (17)
Brute-Force
Web App Attack
Anonymous
2026-10-08 19:56:52
(3 hours ago)
Portscan: TCP/8080 (7x), TCP/8443 (7x), TCP/443, TCP/80
Port Scan
πΊπΈ
TPI-Abuse
2026-10-08 19:46:15
(3 hours ago)
(mod_security) mod_security (id:210580) triggered by 136.70.5.89 (89.5.70.136.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210580) triggered by 136.70.5.89 (89.5.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 15:46:10.370807 2026] [security2:error] [pid 11173:tid 11173] [client 136.70.5.89:44868] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at ARGS:apis. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||slmd.me|F|2"] [data "Matched Data: proc/self/environ found within ARGS:apis: ../../../../../../proc/self/environ"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "slmd.me"] [uri "/api/console/api_server"] [unique_id "asfzAlUPZFtmryu2gorV-AAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack