🇩🇪
23p02732
2026-09-07 02:16:47
(58 minutes ago)
Automated web scanning and malicious probing
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 02:07:22
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 34.140.247.105 (105.247.140.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.140.247.105 (105.247.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 22:07:18.581940 2026] [security2:error] [pid 23161:tid 23161] [client 34.140.247.105:58132] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.kbalan.com|F|2"] [data ".kbalan.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.kbalan.com"] [uri "/z9x8c7v6b5-debug-trigger-www.kbalan.com"] [unique_id "ap4cVnc7BqkelaxDJheJvwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇷🇴
clauss
2026-09-07 01:48:27
(1 hour ago)
34.140.247.105 - - [07/Sep/2026:04:48:24 +0300] "GET /rclone.conf HTTP/2.0" 403 146 "-" "Mozilla/5.0 ...
show more
34.140.247.105 - - [07/Sep/2026:04:48:24 +0300] "GET /rclone.conf HTTP/2.0" 403 146 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)"
34.140.247.105 - - [07/Sep/2026:04:48:26 +0300] "GET /api/.env/public/.env HTTP/2.0" 403 146 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)"
...
show less
Web App Attack
🇬🇧
cybersteve99
2026-09-07 00:47:05
(2 hours ago)
Too many 4xx Requests -
Brute-Force
Web App Attack
🇬🇧
Aetherweb Ark
2026-09-07 00:38:19
(2 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.140.247.105 (BE/Belgium/105.247.140.34.bc.go ...
show more
(mod_security) mod_security (id:949110) triggered by 34.140.247.105 (BE/Belgium/105.247.140.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
🇬🇧
venus.launch.bz
2026-09-06 23:25:30
(3 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.140.247.105 (BE/Belgium/105.247.140. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.140.247.105 (BE/Belgium/105.247.140.34.bc.googleusercontent.com)
show less
SQL Injection
🇵🇱
Budyn
2026-09-06 22:47:12
(4 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: admin.budyn.ovh | URI: /.git/HEAD | UA: Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/) | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
🇺🇸
brightenfield
2026-09-06 22:38:07
(4 hours ago)
Web App Attack
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 21:15:24
(6 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.140.247.105 (105.247.140.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.140.247.105 (105.247.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 17:15:15.504862 2026] [security2:error] [pid 1894:tid 1894] [client 34.140.247.105:50018] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||test.orientaltd.com|F|2"] [data ".orientaltd.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "test.orientaltd.com"] [uri "/z9x8c7v6b5-debug-trigger-test.orientaltd.com"] [unique_id "ap3X45yQhd6Y7zxMa7ZnPwAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Savvii
2026-09-06 18:44:09
(8 hours ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
CoreTech srl
2026-09-06 18:33:56
(8 hours ago)
cloudlinux2 fail2ban: 2026-09-06 20:29:05,500 fail2ban.filter [2048]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-09-06 20:29:05,500 fail2ban.filter [2048]: INFO [plesk-wordpress] Found 45.92.229.6 - 2026-09-06 20:29:03cloudlinux2 fail2ban: 2026-09-06 20:29:20,163 fail2ban.filter [2048]: INFO [plesk-modsecurity] Found 117.211.64.149 - 2026-09-06 20:29:19cloudlinux2 fail2ban: 2026-09-06 20:29:40,348 fail2ban.actions [2048]: NOTICE [plesk-modsecurity] Unban 35.244.44.198cloudlinux2 fail2ban: 2026-09-06 20:29:51,967 fail2ban.filter [2048]: INFO [plesk-modsecurity] Found 117.211.64.149 - 2026-09-06 20:29:51cloudlinux2 fail2ban: 2026-09-06 20:29:51,206 fail2ban.filter [2048]: INFO [plesk-wordpress] Found 92.119.36.148 - 2026-09-06 20:29:51cloudlinux2 fail2ban: 2026-09-06 20:30:33,123 fail2ban.filter [2048]: INFO [plesk-modsecurity] Found 34.140.247.105 - 2026-09-06 20:30:33cloudlinux2 fail2ban: 2026-09-06 20:30:33,131 fail2ban.filter [2048]: INFO [plesk-modsecurity] Found 34.140.247.105 - 2026-09-06 20:30:33cloudlinux2 fail2ba
show less
Web App Attack
🇸🇬
Cloudkul Cloudkul
2026-09-06 16:41:05
(10 hours ago)
Attempted Not Found (404 status code) requests on our application, more than 30% of their total requ ...
show more
Attempted Not Found (404 status code) requests on our application, more than 30% of their total requests.
show less
Brute-Force
Web App Attack
🇬🇧
consul.to
2026-09-06 16:33:38
(10 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 16:26:50
(10 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.140.247.105 (105.247.140.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.140.247.105 (105.247.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 12:26:44.257979 2026] [security2:error] [pid 17906:tid 17906] [client 34.140.247.105:59610] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ironsightsarmory.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ironsightsarmory.com"] [uri "/z9x8c7v6b5-debug-trigger-ironsightsarmory.com"] [unique_id "ap2UREH397z5H4u0nj73AgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Savvii
2026-09-06 15:54:48
(11 hours ago)
20 attempts against mh-misbehave-ban on solar
Brute-Force
Bad Web Bot
Web App Attack