🇫🇷
dynamix
2026-09-10 05:02:48
(8 hours ago)
Multiple WAF Violations
Web App Attack
🇿🇦
conure.sh
2026-09-10 03:00:19
(10 hours ago)
csagent: score 20.4: secrets grab x2, 404 noise floor x2; 1 domain(s) in 5s
Web App Attack
🇩🇪
SwinT
2026-09-10 02:00:04
(11 hours ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
🇺🇸
TPI-Abuse
2026-09-10 00:28:17
(12 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.106.233.251 (251.233.106.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.106.233.251 (251.233.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 20:28:12.685458 2026] [security2:error] [pid 6888:tid 6888] [client 34.106.233.251:53478] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||swinjury.co|F|2"] [data ".env.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "swinjury.co"] [uri "/.env.bak"] [unique_id "aqH5nKxpbRvfqHKsWo8QNQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Savvii
2026-09-09 18:53:13
(18 hours ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
helios.live
2026-09-09 18:07:37
(19 hours ago)
2026/09/09 18:07:36 [error] 73274#73274: *2665331 access forbidden by rule, client: 34.106.233.251, ...
show more
2026/09/09 18:07:36 [error] 73274#73274: *2665331 access forbidden by rule, client: 34.106.233.251, server: kocerroxy.com, request: "GET /.env.local HTTP/1.1", host: "kocerroxy.com"
2026/09/09 18:07:36 [error] 73274#73274: *2665331 access forbidden by rule, client: 34.106.233.251, server: kocerroxy.com, request: "GET /.env.production HTTP/1.1", host: "kocerroxy.com"
2026/09/09 18:07:36 [error] 73274#73274: *2665331 access forbidden by rule, client: 34.106.233.251, server: kocerroxy.com, request: "GET /.env.staging HTTP/1.1", host: "kocerroxy.com"
2026/09/09 18:07:36 [error] 73274#73274: *2665331 access forbidden by rule, client: 34.106.233.251, server: kocerroxy.com, request: "GET /.env.development HTTP/1.1", host: "kocerroxy.com"
2026/09/09 18:07:36 [error] 73274#73274: *2665331 access forbidden by rule, client: 34.106.233.251, server: kocerroxy.com, request: "GET /.env.test HTTP/1.1", host: "kocerroxy.com"
...
show less
Web App Attack
🇬🇧
consul.to
2026-09-09 17:41:55
(19 hours ago)
Web attack/malicious scanning detected
Web App Attack
Anonymous
2026-09-09 17:31:37
(19 hours ago)
34.106.233.251 - - [09/Sep/2026:19:31:35 +0200] "GET / HTTP/1.1" 404 4515 "-" "Mozilla/5.0 (Windows ...
show more
34.106.233.251 - - [09/Sep/2026:19:31:35 +0200] "GET / HTTP/1.1" 404 4515 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.106.233.251 - - [09/Sep/2026:19:31:35 +0200] "POST / HTTP/1.1" 404 503 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.106.233.251 - - [09/Sep/2026:19:31:35 +0200] "POST / HTTP/1.1" 404 503 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.106.233.251 - - [09/Sep/2026:19:31:36 +0200] "POST / HTTP/1.1" 404 503 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.106.233.251 - - [09/Sep/2026:19:31:36 +0200] "GET /.git/config HTTP/1.1" 404 503 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Brute-Force
SSH
🇹🇷
ycoskun41
2026-09-09 14:56:10
(22 hours ago)
fail2ban: plesk-modsecurity jail on genckocaeli.com
Web App Attack
Anonymous
2026-09-09 14:02:26
(23 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 12:10:58
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.106.233.251 (251.233.106.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.233.251 (251.233.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 08:10:52.546277 2026] [security2:error] [pid 9841:tid 9841] [client 34.106.233.251:52052] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kobraagencies.com"] [uri "/.git/config"] [unique_id "aqFMzN5gljTM11bvdyWDnAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-09-09 11:00:05
(1 day ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 10:44:37
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.106.233.251 (251.233.106.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.233.251 (251.233.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 06:44:32.912806 2026] [security2:error] [pid 31943:tid 31943] [client 34.106.233.251:42856] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nsdorganogram.org"] [uri "/.git/config"] [unique_id "aqE4kKkT3v1She4ZYwac7gAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇦
mitsurugi
2022-01-10 07:05:47
(4 years ago)
WordPress xmlrpc attack.
Brute-Force
Web App Attack
🇬🇧
lgirvin
2022-01-10 05:18:45
(4 years ago)
Jan 10 10:18:43 mercury wordpress(www.learnargentinianspanish.com)[318993]: XML-RPC authentication f ...
show more
Jan 10 10:18:43 mercury wordpress(www.learnargentinianspanish.com)[318993]: XML-RPC authentication failure for josh from 34.106.233.251
...
show less
Hacking
Web App Attack