Anonymous
2026-10-03 02:11:02
(20 minutes ago)
Malicious activity detected
Hacking
Web App Attack
π΅π±
strefapi_com
2026-10-03 01:30:43
(1 hour ago)
Brute-force, web
...
Hacking
Brute-Force
Web App Attack
π¨π
zynex
2026-10-02 23:12:35
(3 hours ago)
URL Probing: /static/app/.env
Web App Attack
π©πͺ
itsolon
2026-10-02 21:41:44
(4 hours ago)
[02/Oct/2026:23:41:42 +0200] 179097730235.035202 34.104.152.153 49198 217.154.7.177 443
[02/Oct/2026 ...
show more
[02/Oct/2026:23:41:42 +0200] 179097730235.035202 34.104.152.153 49198 217.154.7.177 443
[02/Oct/2026:23:41:43 +0200] 179097730342.709902 34.104.152.153 49198 217.154.7.177 443
[02/Oct/2026:23:41:43 +0200] 179097730395.649087 34.104.152.153 49198 217.154.7.177 443
[02/Oct/2026:23:41:43 +0200] 179097730392.014426 34.104.152.153 49198 217.154.7.177 443
[02/Oct/2026:23:41:43 +0200] 179097730326.408046 34.104.152.153 49198 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
πΊπΈ
legionMCCXV
2026-10-02 21:32:09
(4 hours ago)
Non-HTTP protocol data (e.g. MQTT/TLS handshake bytes) sent to HTTP(S) port.
Port Scan
Hacking
πΊπΈ
TPI-Abuse
2026-10-02 19:42:43
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.104.152.153 (153.152.104.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.104.152.153 (153.152.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 15:42:38.741587 2026] [security2:error] [pid 1550987:tid 1550987] [client 34.104.152.153:55528] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.andrsn.com"] [uri "/@fs/app/.env"] [unique_id "asAJLm_TMbzKROrQwV5UzQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¨π¦
TechnoSolutions CL
2026-10-02 18:42:27
(7 hours ago)
34.104.152.153 - - [02/Oct/2026:18:40:50 +0000] "GET /.git/config HTTP/2.0" 444 0 "-" "Mozilla/5.0 ( ...
show more
34.104.152.153 - - [02/Oct/2026:18:40:50 +0000] "GET /.git/config HTTP/2.0" 444 0 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
34.104.152.153 - - [02/Oct/2026:18:42:27 +0000] "POST /cgi-bin/php-cgi.exe?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input HTTP/2.0" 405 150 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)"
...
show less
Hacking
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-02 18:22:55
(8 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.104.152.153 (153.152.104.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.104.152.153 (153.152.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 14:22:51.284318 2026] [security2:error] [pid 18672:tid 18672] [client 34.104.152.153:41626] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||encoremtmorris.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "encoremtmorris.com"] [uri "/z9x8c7v6b5-debug-trigger-encoremtmorris.com"] [unique_id "ar_2e6JBBvckEY2rx_I3qAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
abivia
2026-10-02 17:37:24
(8 hours ago)
Abivia WAF trigger: Rule scriptKiddies: Credential probing uri: /dist/manifest.json
Hacking
πΊπΈ
TPI-Abuse
2026-10-02 17:17:27
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.104.152.153 (153.152.104.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.104.152.153 (153.152.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 13:17:22.464288 2026] [security2:error] [pid 18954:tid 18954] [client 34.104.152.153:56918] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "summercampregistration.wholesalelivelobsters.com"] [uri "/.htpasswd"] [unique_id "ar_nIo7zkGiljeMasYFjVQAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-02 16:40:37
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.104.152.153 (153.152.104.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.104.152.153 (153.152.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 12:40:32.967662 2026] [security2:error] [pid 26714:tid 26714] [client 34.104.152.153:44386] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.diegolaje.com"] [uri "/.htpasswd"] [unique_id "ar_egEUSpyBFzQ-7DPxBMwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-02 15:24:42
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.104.152.153 (153.152.104.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.104.152.153 (153.152.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 11:24:38.611996 2026] [security2:error] [pid 29740:tid 29740] [client 34.104.152.153:58002] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.providencesilverco.com"] [uri "/.htpasswd"] [unique_id "ar_MtsHdteEExOeFkkHWegAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
BlueWire Hosting
2026-10-02 15:09:04
(11 hours ago)
Aggressive scanning resulting into 404
Bad Web Bot
πΊπΈ
Mundo Bueno
2026-10-02 15:02:43
(11 hours ago)
[ISILIA Protection v2.3] Tentative d'accès: /@fs/home/ubuntu/.aws/credentials [RATE LIMITED - 1800s ...
show more
[ISILIA Protection v2.3] Tentative d'accès: /@fs/home/ubuntu/.aws/credentials [RATE LIMITED - 1800s quarantine] | Pays: JP | UA: Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)
show less
Hacking
Web App Attack
π©πͺ
itsolon
2026-10-02 14:09:31
(12 hours ago)
[02/Oct/2026:16:09:30 +0200] 179095017075.656305 34.104.152.153 33750 217.154.7.177 443
[02/Oct/2026 ...
show more
[02/Oct/2026:16:09:30 +0200] 179095017075.656305 34.104.152.153 33750 217.154.7.177 443
[02/Oct/2026:16:09:30 +0200] 179095017010.575434 34.104.152.153 33758 217.154.7.177 443
[02/Oct/2026:16:09:30 +0200] 179095017076.491884 34.104.152.153 33758 217.154.7.177 443
[02/Oct/2026:16:09:30 +0200] 179095017097.166851 34.104.152.153 33758 217.154.7.177 443
[02/Oct/2026:16:09:30 +0200] 179095017022.346153 34.104.152.153 33758 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack