๐ฟ๐ฆ
conure.sh
2026-10-05 12:05:36
(1 day ago)
csagent: score 19.6: 404 noise floor x39, secrets grab x1; 1 domain(s) in 5s
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-04 22:00:00
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.104.205.30 (30.205.104.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.104.205.30 (30.205.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 17:59:56.845907 2026] [security2:error] [pid 9419:tid 9444] [client 34.104.205.30:42804] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aqutar.com"] [uri "/.htpasswd"] [unique_id "asLMXODIypFDXDhTw3LQRQAAANY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-10-04 21:56:29
(1 day ago)
Wordlist path sweep | method: POST, GET | path: /lib/terminal-xhr.php, /assets/manifest.json, /asset ...
show more
Wordlist path sweep | method: POST, GET | path: /lib/terminal-xhr.php, /assets/manifest.json, /asset-manifest.json (+3 more) | ua: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] ), Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36
show less
Port Scan
Web App Attack
๐ฎ๐น
VHosting
2026-10-04 21:35:04
(1 day ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-04 21:28:30
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.104.205.30 (30.205.104.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.104.205.30 (30.205.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 17:28:27.106990 2026] [security2:error] [pid 28240:tid 28240] [client 34.104.205.30:34276] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||aprilparks.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "aprilparks.com"] [uri "/z9x8c7v6b5-debug-trigger-aprilparks.com"] [unique_id "asLE-0LtVL7YKySIEW7EHgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
IndigoRidge
2026-10-04 21:28:07
(1 day ago)
34.104.205.30 - - [04/Oct/2026:17:28:04 -0400] "GET /.ssh/id_rsa HTTP/1.1" 404 40237 "https://aprilk ...
show more
34.104.205.30 - - [04/Oct/2026:17:28:04 -0400] "GET /.ssh/id_rsa HTTP/1.1" 404 40237 "https://aprilkayrealestate.com/.ssh/id_rsa" "Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)"
34.104.205.30 - - [04/Oct/2026:17:28:05 -0400] "GET /@fs/app/.env?raw?? HTTP/1.1" 404 40237 "https://aprilkayrealestate.com/@fs/app/.env?raw??" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.4; +https://openai.com/gptbot"
34.104.205.30 - - [04/Oct/2026:17:28:06 -0400] "GET /@fs/src/.env?raw?? HTTP/1.1" 403 4980 "https://aprilkayrealestate.com/@fs/src/.env?raw??" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)"
...
show less
Web App Attack
๐ฌ๐ง
consul.to
2026-10-04 21:27:52
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
๐ซ๐ท
masterguru
2026-10-04 21:24:51
(1 day ago)
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encod ...
show more
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encoding/ /proxy/ /lock-token/ /content-range/ /if/ /x-http-method-override/ /x-http-method/ /x-method-override/ /x-middleware-subrequest/ /expect/" at TX:header_name_920450_x-middleware-subrequest. (920450-197)
show less
Bad Web Bot
๐ซ๐ท
dynamix
2026-10-04 21:14:22
(1 day ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-04 21:04:33
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.104.205.30 (30.205.104.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.104.205.30 (30.205.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 17:04:28.266060 2026] [security2:error] [pid 31492:tid 31492] [client 34.104.205.30:37870] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||aguasolar.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "aguasolar.com"] [uri "/z9x8c7v6b5-debug-trigger-aguasolar.com"] [unique_id "asK_XP_rsFGh1GflP9xQ8wAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
polycoda
2026-10-04 20:42:52
(1 day ago)
AutoBlock: ๐ก Port Scan (Non Decay-Based)
Port Scan
๐บ๐ธ
nasset
2026-09-19 17:01:42
(2 weeks ago)
34.104.205.30 - - [19/Sep/2026:10:01:41 -0700] "GET /home/.codex/auth.json HTTP/1.1" 403 6366 "-" "c ...
show more
34.104.205.30 - - [19/Sep/2026:10:01:41 -0700] "GET /home/.codex/auth.json HTTP/1.1" 403 6366 "-" "crusader-worker/1.0"
34.104.205.30 - - [19/Sep/2026:10:01:41 -0700] "GET /web/.codex/auth.json HTTP/1.1" 403 6366 "-" "crusader-worker/1.0"
34.104.205.30 - - [19/Sep/2026:10:01:41 -0700] "GET /srv/.codex/auth.json HTTP/1.1" 403 6366 "-" "crusader-worker/1.0"
34.104.205.30 - - [19/Sep/2026:10:01:41 -0700] "GET /opt/.codex/auth.json HTTP/1.1" 403 6366 "-" "crusader-worker/1.0"
34.104.205.30 - - [19/Sep/2026:10:01:41 -0700] "GET /www/.codex/auth.json HTTP/1.1" 403 6366 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
Web App Attack