๐จ๐ฑ
Fernando Soto
2026-10-01 03:05:23
(1 day ago)
WAF propio vps1 (CL): 404x26,sensx149 score 22 en 1h. sondeo rutas sensibles, barrido 404.
Port Scan
Web App Attack
๐ง๐ท
radardatelecom
2026-09-30 22:26:03
(1 day ago)
Blocked by Radar da Telecom firewall โ abuseipdb
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-09-30 22:01:39
(1 day ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-29.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-30 05:00:22
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.140.90.150 (150.90.140.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.140.90.150 (150.90.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 01:00:17.892305 2026] [security2:error] [pid 19373:tid 19386] [client 34.140.90.150:43056] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.exedesalesteam.exede-sales.com|F|2"] [data ".exedesalesteam.exede-sales.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.exedesalesteam.exede-sales.com"] [uri "/z9x8c7v6b5-debug-trigger-www.exedesalesteam.exede-sales.com"] [unique_id "aryXYZqz7n9sPUFyL5aseAAAAUo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
TheDjRider
2026-09-30 03:29:00
(2 days ago)
CrowdSec detected Web application reconnaissance. Scenario: crowdsecurity/http-probing. Automatic ba ...
show more
CrowdSec detected Web application reconnaissance. Scenario: crowdsecurity/http-probing. Automatic ban triggered. Detection time (UTC): 2026-09-30T03:28:58.403429235Z. Context: http_status=404
show less
Web App Attack
๐ช๐ธ
robotstxt
2026-09-30 01:26:14
(2 days ago)
34.140.90.150 - - [30/Sep/2026:01:26:12 +0000] "GET /%2E%2E/%2E%2E/%2E%2E/%2E%2E/proc/self/environ H ...
show more
34.140.90.150 - - [30/Sep/2026:01:26:12 +0000] "GET /%2E%2E/%2E%2E/%2E%2E/%2E%2E/proc/self/environ HTTP/1.1" 400 193 "-" "-" "-" edge="34.140.90.150"
34.140.90.150 - - [30/Sep/2026:01:26:12 +0000] "GET /%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env HTTP/1.1" 400 193 "-" "-" "-" edge="34.140.90.150"
34.140.90.150 - - [30/Sep/2026:01:26:12 +0000] "GET /icons/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/proc/self/environ HTTP/1.1" 400 193 "-" "-" "-" edge="34.140.90.150"
34.140.90.150 - - [30/Sep/2026:01:26:12 +0000] "GET /appearance/../../.env HTTP/1.1" 400 193 "-" "-" "-" edge="34.140.90.150"
34.140.90.150 - - [30/Sep/2026:01:26:12 +0000] "GET /appearance/../../proc/self/environ HTTP/1.1" 400 193 "-" "-" "-" edge="34.140.90.150"
...
show less
Web Spam
Web App Attack
๐ฉ๐ช
altenglaner
2026-09-30 01:04:13
(2 days ago)
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show more
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
Hacking
Web App Attack
๐ฒ๐พ
Rizzy
2026-09-30 00:35:12
(2 days ago)
Multiple WAF Violations
Brute-Force
Web App Attack
Anonymous
2026-09-29 23:30:03
(2 days ago)
CrowdSec decision: crowdsecurity/http-bad-user-agent (origin: crowdsec)
Port Scan
๐บ๐ธ
TPI-Abuse
2026-09-29 23:11:51
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.140.90.150 (150.90.140.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.140.90.150 (150.90.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 19:11:45.742111 2026] [security2:error] [pid 31691:tid 31691] [client 34.140.90.150:49066] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.emmpftp.tremulant.com|F|2"] [data ".emmpftp.tremulant.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.emmpftp.tremulant.com"] [uri "/z9x8c7v6b5-debug-trigger-www.emmpftp.tremulant.com"] [unique_id "arxFsUAP-oB_2jO6ydjOfgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-09-29 23:04:56
(2 days ago)
9.533 requests from abuseipdb.com blacklisted IP (1yr10mos3w)
Brute-Force
Bad Web Bot
๐ฌ๐ท
setupgr
2026-09-29 22:55:36
(2 days ago)
(mod_security) mod_security (id:11000010) triggered by 34.140.90.150 (BE/Belgium/Brussels Capital/Br ...
show more
(mod_security) mod_security (id:11000010) triggered by 34.140.90.150 (BE/Belgium/Brussels Capital/Brussels/-/[AS396982 Google LLC]): 1 in the last 86400 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Wed Sep 30 01:55:32.491677 2026] [security2:error] [pid 1755425:tid 1755475] [remote 34.140.90.150:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "+claudebot" at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "114"] [id "11000010"] [msg "BLOCKED BOT: +claudebot on www.endoscope.center"] [severity "ALERT"] [hostname "www.endoscope.center"] [uri "/if27n5pd6bb4uh6l70mj"] [unique_id "arxB5AZ8NGJpGx9NdCgdPgACEQQ"]
show less
Port Scan
๐จ๐ฑ
Fernando Soto
2026-09-29 22:45:02
(2 days ago)
WAF propio vps1 (CL): 404x26,sensx149 score 22 en 1h. sondeo rutas sensibles, barrido 404.
Port Scan
Web App Attack
๐ฎ๐น
VHosting
2026-09-29 21:25:03
(2 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-29 20:58:43
(2 days ago)
[ti-30al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-30al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.140.90.150 - - [29/Sep/2026:22:58:25 +0200] "GET /wp/.env HTTP/2.0" 404 2004 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36"
...
show less
Bad Web Bot
Web App Attack