๐ง๐ท
radardatelecom
2026-09-30 22:26:04
(2 days ago)
Blocked by Radar da Telecom firewall โ abuseipdb
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-09-30 21:59:34
(2 days ago)
Auto-ban: >3000 req/min op 2026-09-30
Web App Attack
SSH
Hacking
๐จ๐ฆ
Anytech
2026-09-30 03:59:43
(2 days ago)
Blocked by Conn-Monitor: env-probing
Web App Attack
Hacking
Anonymous
2026-09-30 03:33:04
(2 days ago)
146.148.17.105 - - [30/Sep/2026:05:33:04 +0200] "GET /userfiles?path=../../.env HTTP/2.0" 301 169 "- ...
show more
146.148.17.105 - - [30/Sep/2026:05:33:04 +0200] "GET /userfiles?path=../../.env HTTP/2.0" 301 169 "-" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https:///)"
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 02:39:19
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 146.148.17.105 (105.17.148.146.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 146.148.17.105 (105.17.148.146.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 22:39:13.560254 2026] [security2:error] [pid 17387:tid 17387] [client 146.148.17.105:52652] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bigkevsperformance.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bigkevsperformance.com"] [uri "/z9x8c7v6b5-debug-trigger-bigkevsperformance.com"] [unique_id "arx2UaONnKxkpI9f25nWUAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-09-30 01:13:50
(2 days ago)
Wordlist path sweep | method: POST, GET | path: /lib/terminal-xhr.php, /assets/manifest.json, /8ttbp ...
show more
Wordlist path sweep | method: POST, GET | path: /lib/terminal-xhr.php, /assets/manifest.json, /8ttbp0z6d6fd4k7g1nk0 (+3 more) | ua: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.4; +https://openai.com/gptbot, Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36, Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )
show less
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 01:10:17
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 146.148.17.105 (105.17.148.146.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 146.148.17.105 (105.17.148.146.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 21:10:11.653288 2026] [security2:error] [pid 4939:tid 4939] [client 146.148.17.105:43946] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||biff0.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "biff0.com"] [uri "/z9x8c7v6b5-debug-trigger-biff0.com"] [unique_id "arxhc3Gq5qZZV6mnjH8SbQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-09-30 01:05:56
(2 days ago)
Too many Status 40X (16)
Brute-Force
Web App Attack
๐ฌ๐ง
andypiper
2026-09-30 01:02:49
(2 days ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 00:11:26
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 146.148.17.105 (105.17.148.146.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 146.148.17.105 (105.17.148.146.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 20:11:20.609771 2026] [security2:error] [pid 20693:tid 20693] [client 146.148.17.105:42536] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||boardingatthewedge.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "boardingatthewedge.com"] [uri "/z9x8c7v6b5-debug-trigger-boardingatthewedge.com"] [unique_id "arxTqBTRKv5veQVoSEJgmQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-09-29 23:03:13
(3 days ago)
4.751 requests from abuseipdb.com blacklisted IP (10mos3w4d)
Brute-Force
Bad Web Bot
๐ฉ๐ช
Hazzard
2026-09-29 21:44:13
(3 days ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
๐บ๐ธ
agenciahypelab.com.br
2026-09-29 20:25:30
(3 days ago)
WordPress login brute-force detectado e bloqueado pelo CSF/LFD. Trigger: LF_TRIGGER
Brute-Force
SSH
Anonymous
2026-09-29 20:02:24
(3 days ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-29 19:46:39
(3 days ago)
Excessive multi-domain requests
Brute-Force