๐น๐ท
pashait
2026-10-06 21:32:22
(4 hours ago)
Auto-blocked by Seczar SecureOps โ IPS Web Attack Signature (1 events in 5min) at 2026-10-06 21:32
Web App Attack
Bad Web Bot
Anonymous
2026-10-06 18:12:12
(7 hours ago)
SIEM ALERT AUTO REPORT
Email Spam
๐บ๐ธ
TPI-Abuse
2026-10-06 18:01:20
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.12.255.220 (220.255.12.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.12.255.220 (220.255.12.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 14:01:15.005026 2026] [security2:error] [pid 19608:tid 19608] [client 34.12.255.220:57306] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.hisim.com.tr"] [uri "/.htpasswd"] [unique_id "asU3a1O4SjbHCgumEC1GwQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐ฑ
router.al
2026-10-06 16:56:16
(9 hours ago)
10/06/2026-16:56:16.582314 34.12.255.220 Protocol: 6 ET WEB_SERVER Next.js Middleware Authorization ...
show more
10/06/2026-16:56:16.582314 34.12.255.220 Protocol: 6 ET WEB_SERVER Next.js Middleware Authorization Bypass (CVE-2025-29927)
show less
Hacking
๐น๐ท
eryilmaz
2026-10-06 16:34:41
(9 hours ago)
Automated attack blocked by eryilmaz WAF/defense engine (level 1, source: auto, path: /qrwmpj4ocyquz ...
show more
Automated attack blocked by eryilmaz WAF/defense engine (level 1, source: auto, path: /qrwmpj4ocyquzne4vbbm)
show less
Web App Attack
Hacking
๐ฉ๐ช
kkw
2026-10-06 16:17:37
(9 hours ago)
[REDACTED] 34.12.255.220 - - [06/Oct/2026:18:17:36 +0200] "GET /.ssh/id_rsa HTTP/2.0" 301 393 "-" "M ...
show more
[REDACTED] 34.12.255.220 - - [06/Oct/2026:18:17:36 +0200] "GET /.ssh/id_rsa HTTP/2.0" 301 393 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)"
... (mode: searching http-sensitive-files)
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
zumbo.net
2026-10-06 11:45:40
(14 hours ago)
[Tue Oct 06 14:45:39.071505 2026] [proxy_fcgi:error] [pid 972327:tid 972341] [client 34.12.255.220:0 ...
show more
[Tue Oct 06 14:45:39.071505 2026] [proxy_fcgi:error] [pid 972327:tid 972341] [client 34.12.255.220:0] AH01071: Got error 'Primary script unknown'
[Tue Oct 06 14:45:39.214732 2026] [proxy_fcgi:error] [pid 972326:tid 972337] [client 34.12.255.220:0] AH01071: Got error 'Primary script unknown'
[Tue Oct 06 14:45:39.233737 2026] [proxy_fcgi:error] [pid 972327:tid 972348] [client 34.12.255.220:0] AH01071: Got error 'Primary script unknown'
[Tue Oct 06 14:45:39.237411 2026] [proxy_fcgi:error] [pid 972327:tid 972372] [client 34.12.255.220:0] AH01071: Got error 'Primary script unknown'
[Tue Oct 06 14:45:39.587310 2026] [proxy_fcgi:error] [pid 972326:tid 972381] [client 34.12.255.220:0] AH01071: Got error 'Primary script unknown'
...
show less
Brute-Force
Web App Attack
๐ฎ๐น
VHosting
2026-10-06 10:40:04
(15 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ต๐ฑ
TaKeN
2026-10-06 10:25:37
(15 hours ago)
Automated Wazuh observation. Wazuh rule 31151 lvl=10 detected repeated HTTP web application probing ...
show more
Automated Wazuh observation. Wazuh rule 31151 lvl=10 detected repeated HTTP web application probing from this source IP. Observed 2 matching Wazuh alert(s) between 2026-10-06T12:25:37+02:00 and 2026-10-06T12:25:37+02:00.
show less
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-06 10:18:54
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.12.255.220 (220.255.12.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.12.255.220 (220.255.12.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 06:18:47.562964 2026] [security2:error] [pid 17833:tid 17833] [client 34.12.255.220:57888] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pist.org.tr"] [uri "/userfiles"] [unique_id "asTLB_ueT4HIZJDX5ic7WQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-10-06 10:08:43
(15 hours ago)
Excessive multi-domain requests
Brute-Force
Anonymous
2026-10-06 10:04:52
(15 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
๐ง๐ช
voormedia
2026-10-06 10:03:36
(15 hours ago)
Accessed trap at '/.npmrc'
Web App Attack
๐น๐ท
ycoskun41
2026-10-06 09:53:10
(16 hours ago)
fail2ban: plesk-modsecurity jail on genckocaeli.com
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 09:28:31
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.12.255.220 (220.255.12.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.12.255.220 (220.255.12.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 05:28:25.569366 2026] [security2:error] [pid 7398:tid 7398] [client 34.12.255.220:54530] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mazzaro.com.tr"] [uri "/files../.env"] [unique_id "asS_OVfUk5j3Zfg_WdWRbQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack