πΊπΈ
rdpguard.com
2026-08-27 15:46:23
(53 minutes ago)
RdpGuard detected brute-force attempt on HTTP
Brute-Force
π΅π±
tomkolp
2026-08-27 15:00:50
(1 hour ago)
CrowdSec - Scenario: crowdsecurity/http-probing. Duration: 4h.
Port Scan
Web App Attack
π§πͺ
voormedia
2026-08-27 14:50:51
(1 hour ago)
Accessed trap at '/.bashrc'
Web App Attack
Anonymous
2026-08-27 13:22:22
(3 hours ago)
π₯ Web application attack detected. Vulnerability scanning and exploitation attempts identified.
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-27 13:20:31
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 3.147.59.15 (ec2-3-147-59-15.us-east-2.compute. ...
show more
(mod_security) mod_security (id:210492) triggered by 3.147.59.15 (ec2-3-147-59-15.us-east-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 09:20:27.756220 2026] [security2:error] [pid 23827:tid 23827] [client 3.147.59.15:44684] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.wildlifetaxidermy.com"] [uri "/.git/HEAD"] [unique_id "apA5m5L8MoUPpprcx87THwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
dynamix
2026-08-27 12:35:34
(4 hours ago)
Multiple WAF Violations
Web App Attack
πΈπ¬
Cloudkul Cloudkul
2026-08-27 11:21:32
(5 hours ago)
Attempted Not Found (404 status code) requests on our application, more than 30% of their total requ ...
show more
Attempted Not Found (404 status code) requests on our application, more than 30% of their total requests.
show less
Brute-Force
Web App Attack
π¬π§
consul.to
2026-08-27 11:14:25
(5 hours ago)
Web attack/malicious scanning detected
Web App Attack
πΊπΈ
mnsf
2026-08-27 11:05:25
(5 hours ago)
Abuse Detected (10)
Brute-Force
Web App Attack
π§πͺ
taivas.nl
2026-08-27 11:02:13
(5 hours ago)
Site scraper
Web App Attack
πͺπΈ
el-brujo
2026-08-27 10:53:42
(5 hours ago)
Cloudflare WAF: Request Path: /portal/.env Request Query: Host: api.elhacker.net userAgent: Mozilla ...
show more
Cloudflare WAF: Request Path: /portal/.env Request Query: Host: api.elhacker.net userAgent: Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/bot) Action: block Source: firewallManaged ASN Description: Amazon.com, Inc. Country: US Method: GET Timestamp: 2026-08-27T10:53:42Z ruleId: 23548ee2b36547a1be09bb2c0550c529. Report generated by Cloudflare-WAF-to-AbuseIPDB.
show less
Hacking
SQL Injection
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-27 10:24:14
(6 hours ago)
(mod_security) mod_security (id:210730) triggered by 3.147.59.15 (ec2-3-147-59-15.us-east-2.compute. ...
show more
(mod_security) mod_security (id:210730) triggered by 3.147.59.15 (ec2-3-147-59-15.us-east-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 06:24:10.812147 2026] [security2:error] [pid 15240:tid 15240] [client 3.147.59.15:36764] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.dmasoftlab.com|F|2"] [data ".dmasoftlab.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.dmasoftlab.com"] [uri "/z9x8c7v6b5-debug-trigger-www.dmasoftlab.com"] [unique_id "apAQSmNU1lvqqOspHv5tjQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-27 10:08:59
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 3.147.59.15 (ec2-3-147-59-15.us-east-2.compute. ...
show more
(mod_security) mod_security (id:210492) triggered by 3.147.59.15 (ec2-3-147-59-15.us-east-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 06:08:55.709568 2026] [security2:error] [pid 16097:tid 16097] [client 3.147.59.15:36060] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "petiteplaisanceconservationfund.org"] [uri "/@fs/var/task/.env"] [unique_id "apAMt1d_56bk4ubSpCzWtQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΈπͺ
vaia.cloud
2026-08-27 10:05:06
(6 hours ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-27 09:41:42
(6 hours ago)
(mod_security) mod_security (id:210730) triggered by 3.147.59.15 (ec2-3-147-59-15.us-east-2.compute. ...
show more
(mod_security) mod_security (id:210730) triggered by 3.147.59.15 (ec2-3-147-59-15.us-east-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 05:41:37.443636 2026] [security2:error] [pid 15252:tid 15252] [client 3.147.59.15:45748] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bentonflybox.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bentonflybox.com"] [uri "/z9x8c7v6b5-debug-trigger-bentonflybox.com"] [unique_id "apAGUcH0NRI8vriLf3-JOwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack