๐ฉ๐ช
s@ch@
2026-10-10 17:15:01
(2 minutes ago)
Jail: plesk-modsecurity | Web application attack (Plesk ModSecurity)
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2026-10-10 17:08:33
(9 minutes ago)
High-confidence malicious configuration/VCS probe
Web App Attack
๐บ๐ธ
slay3r9903
2026-10-10 17:07:54
(9 minutes ago)
IP address blocked by Cloudflare security rules due to suspicious activity and security violations.
Hacking
Bad Web Bot
๐บ๐ธ
Starburst SysOp Team
2026-10-10 17:03:57
(13 minutes ago)
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encod ...
show more
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encoding/ /proxy/ /lock-token/ /content-range/ /if/ /x-http-method-override/ /x-http-method/ /x-method-override/ /x-middleware-subrequest/ /expect/" at TX:header_name_920450_x-middleware-subrequest. (920450-mnz6-1)
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-10 17:00:30
(17 minutes ago)
(mod_security) mod_security (id:210730) triggered by 34.138.218.249 (249.218.138.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.138.218.249 (249.218.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 13:00:24.446244 2026] [security2:error] [pid 31153:tid 31153] [client 34.138.218.249:60986] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ramabahama.net|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ramabahama.net"] [uri "/rclone.conf"] [unique_id "aspvKAzuHiZMwJuKMrNsFQAAAEE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
robotstxt
2026-10-10 16:45:52
(31 minutes ago)
34.138.218.249 - - [10/Oct/2026:16:45:11 +0000] "GET /wp-includes/js/dist/hooks.min.js?ver=f0f188028 ...
show more
34.138.218.249 - - [10/Oct/2026:16:45:11 +0000] "GET /wp-includes/js/dist/hooks.min.js?ver=f0f188028580e8dc1255 HTTP/2.0" 403 13138 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "-" edge="34.138.218.249"
34.138.218.249 - - [10/Oct/2026:16:45:12 +0000] "GET /dist/manifest.json HTTP/2.0" 403 13138 "https://durcal.net/dist/manifest.json" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "-" edge="34.138.218.249"
34.138.218.249 - - [10/Oct/2026:16:45:12 +0000] "GET /dist/.vite/manifest.json HTTP/2.0" 403 13103 "https://durcal.net/dist/.vite/manifest.json" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "-" edge="34.138.218.249"
34.138.218.249 - - [10/Oct/2026:16:45:12 +0000] "GET /build/manifest.json HTTP/2.0" 403 13103 "https://durcal.net/build/manifest.json" "Mozilla/5.0 (Windows NT 10.0;
...
show less
Web App Attack
๐ช๐ธ
el-brujo
2026-10-10 16:45:43
(31 minutes ago)
34.138.218.249 - - [10/Oct/2026:18:45:43 +0200] "GET /z9x8c7v6b5-debug-trigger-elhacker.net HTTP/2.0 ...
show more
34.138.218.249 - - [10/Oct/2026:18:45:43 +0200] "GET /z9x8c7v6b5-debug-trigger-elhacker.net HTTP/2.0" 404 15908 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; OAI-SearchBot/1.0; +https://openai.com/searchbot"
34.138.218.249 - - [10/Oct/2026:18:45:43 +0200] "GET /67bf5m4g0pj80nuott4k HTTP/2.0" 404 15908 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)"
34.138.218.249 - - [10/Oct/2026:18:45:43 +0200] "GET /81lnwh6x1z6vm07xgy6v HTTP/2.0" 404 15908 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.4; +https://openai.com/gptbot"
34.138.218.249 - - [10/Oct/2026:18:45:43 +0200] "GET /.vite/manifest.json HTTP/2.0" 404 15908 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 Edg/153.0.0.0"
...
show less
Web App Attack
Hacking
๐ณ๐ฑ
Savvii
2026-10-10 16:44:20
(33 minutes ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
bensmithurst
2026-10-10 16:40:02
(37 minutes ago)
34.138.218.249 - - [10/Oct/2026:16:40:01 +0000] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2fproc/se ...
show more
34.138.218.249 - - [10/Oct/2026:16:40:01 +0000] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2fproc/self/environ HTTP/1.1" 400 150 "-" "-"
34.138.218.249 - - [10/Oct/2026:16:40:01 +0000] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f.env HTTP/1.1" 400 150 "-" "-"
34.138.218.249 - - [10/Oct/2026:16:40:01 +0000] "GET /appearance/../../.env HTTP/1.1" 400 150 "-" "-"
34.138.218.249 - - [10/Oct/2026:16:40:01 +0000] "GET /%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env HTTP/1.1" 400 150 "-" "-"
34.138.218.249 - - [10/Oct/2026:16:40:01 +0000] "GET /appearance/../../proc/self/environ HTTP/1.1" 400 150 "-" "-"
... [host=LAN***]
show less
Web App Attack
๐ฌ๐ง
consul.to
2026-10-10 16:37:40
(39 minutes ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-10 16:35:57
(41 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.138.218.249 (249.218.138.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.138.218.249 (249.218.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 12:35:53.808928 2026] [security2:error] [pid 14319:tid 14319] [client 34.138.218.249:38946] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "anus.net"] [uri "/@fs/src/.env"] [unique_id "asppac82cLKnFObAzwyUVQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-10 16:27:04
(50 minutes ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐ฎ๐น
VHosting
2026-10-10 16:25:03
(52 minutes ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐จ๐ฆ
Mediashaker
2026-10-10 16:20:57
(56 minutes ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 34.138.218.249 (US/U ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 34.138.218.249 (US/United States/249.218.138.34.bc.googleusercontent.com)
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-10 16:20:01
(57 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.138.218.249 (249.218.138.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.138.218.249 (249.218.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 12:19:58.189505 2026] [security2:error] [pid 2574:tid 2653] [client 34.138.218.249:35408] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "alred.net"] [uri "/.htpasswd"] [unique_id "asplrk83ilK9mVE_zcczQgAAAdE"]
show less
Brute-Force
Bad Web Bot
Web App Attack