๐ฉ๐ช
Bedios GmbH
2026-09-11 19:36:57
(49 minutes ago)
Wordpress hacking attempt
Web App Attack
Anonymous
2026-09-11 19:30:02
(56 minutes ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection
๐ณ๐ฑ
middelkoopcc
2026-09-11 19:14:00
(1 hour ago)
2026-09-11 21:12:10 GET /@fs/app/.env?import&raw?? [404] && 2026-09-11 21:12:10 GET /@fs/app/.env.pr ...
show more
2026-09-11 21:12:10 GET /@fs/app/.env?import&raw?? [404] && 2026-09-11 21:12:10 GET /@fs/app/.env.production?import&raw?? [404] && 2026-09-11 21:12:10 GET /@fs/app/.env.local?import&raw?? [404] && 192 more within 20 minutes
show less
Web App Attack
๐ซ๐ท
dynamix
2026-09-11 19:04:32
(1 hour ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-11 18:54:25
(1 hour ago)
(mod_security) mod_security (id:210580) triggered by 34.140.95.226 (226.95.140.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210580) triggered by 34.140.95.226 (226.95.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 14:54:19.770705 2026] [security2:error] [pid 24037:tid 24037] [client 34.140.95.226:56992] ModSecurity: Access denied with code 403 (phase 2). Matched phrase ".ssh/id_rsa" at ARGS:filename. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||dolphin-view.com|F|2"] [data "Matched Data: .ssh/id_rsa found within ARGS:filename: file:/root/.ssh/id_rsa"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "dolphin-view.com"] [uri "/__vite_rsc_findSourceMapURL"] [unique_id "aqROW2QJVYul-QknjdxpXQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-09-11 18:50:09
(1 hour ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ซ๐ท
regishoussin
2026-09-11 18:46:46
(1 hour ago)
Automated web scanning detected by Wazuh (rule 100180): repeated 400/404 errors from mass probing of ...
show more
Automated web scanning detected by Wazuh (rule 100180): repeated 400/404 errors from mass probing of admin/backdoor paths (e.g. wp-login.php, known CMS shell filenames) on an Apache web server, on 2026-09-11 18:46 UTC.
show less
Bad Web Bot
Web App Attack
๐ฎ๐น
CoreTech srl
2026-09-11 18:43:57
(1 hour ago)
cloudlinux2 fail2ban: 2026-09-11 20:39:12,194 fail2ban.actions [1606]: NOTICE [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-11 20:39:12,194 fail2ban.actions [1606]: NOTICE [plesk-modsecurity] Unban 136.65.82.2cloudlinux2 fail2ban: 2026-09-11 20:39:23,624 fail2ban.filter [1606]: INFO [plesk-modsecurity] Found 34.140.95.226 - 2026-09-11 20:39:23cloudlinux2 fail2ban: 2026-09-11 20:39:19,414 fail2ban.actions [1606]: NOTICE [plesk-modsecurity] Ban 35.192.244.63cloudlinux2 fail2ban: 2026-09-11 20:39:18,356 fail2ban.filter [1606]: INFO [plesk-modsecurity] Found 35.192.244.63 - 2026-09-11 20:39:18cloudlinux2 fail2ban: 2026-09-11 20:39:19,126 fail2ban.filter [1606]: INFO [plesk-modsecurity] Found 35.192.244.63 - 2026-09-11 20:39:19cloudlinux2 fail2ban: 2026-09-11 20:39:23,634 fail2ban.filter [1606]: INFO [plesk-modsecurity] Found 34.140.95.226 - 2026-09-11 20:39:23cloudlinux2 fail2ban: 2026-09-11 20:39:23,854 fail2ban.filter [1606]: INFO [plesk-modsecurity] Found 34.140.95.226 - 2026-09-11 20:39:23cloudlinux2 fail2ban: 2026-09-11 20:39:19,3
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-11 18:38:12
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 34.140.95.226 (226.95.140.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.140.95.226 (226.95.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 14:38:08.558660 2026] [security2:error] [pid 29208:tid 29208] [client 34.140.95.226:60516] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||dojoonthego.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "dojoonthego.com"] [uri "/z9x8c7v6b5-debug-trigger-dojoonthego.com"] [unique_id "aqRKkBho0hBCmGPVwFep9wAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
yitzhaq
2026-09-11 18:32:57
(1 hour ago)
34.140.95.226 - - [11/Sep/2026:20:32:54 +0200] "GET /actuator HTTP/2.0" 404 23547 "-" "Mozilla/5.0 ( ...
show more
34.140.95.226 - - [11/Sep/2026:20:32:54 +0200] "GET /actuator HTTP/2.0" 404 23547 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)"
34.140.95.226 - - [11/Sep/2026:20:32:54 +0200] "GET /id_dsa HTTP/2.0" 404 23541 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)"
34.140.95.226 - - [11/Sep/2026:20:32:54 +0200] "GET /pi.php HTTP/2.0" 404 23563 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ChatGPT-User/1.0; +https://openai.com/bot)"
34.140.95.226 - - [11/Sep/2026:20:32:54 +0200] "GET /server.key HTTP/2.0" 404 23552 "-" "Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)"
34.140.95.226 - - [11/Sep/2026:20:32:54 +0200] "GET /test.php HTTP/2.0" 404 23546 "-" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)"
34.140.95.226 - - [11/Sep/2026:20:32:54 +0200] "GET /id_ecdsa HTTP/2.0" 404 23570 "-" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)"
34.140.95.226 - - [11/Sep/2026:20:
show less
Bad Web Bot
Anonymous
2026-09-11 18:12:12
(2 hours ago)
34.140.95.226 - - [11/Sep/2026:20:11:59 +0200] "GET /__vite_rsc_findSourceMapURL?filename=file:///pr ...
show more
34.140.95.226 - - [11/Sep/2026:20:11:59 +0200] "GET /__vite_rsc_findSourceMapURL?filename=file:///proc/self/environ&environmentName=rsc HTTP/2.0" 403 272 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)"
show less
Web Spam
Blog Spam
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-11 18:06:42
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.140.95.226 (226.95.140.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.140.95.226 (226.95.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 14:06:39.004421 2026] [security2:error] [pid 4726:tid 4726] [client 34.140.95.226:51770] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||dodgersboosterclub.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "dodgersboosterclub.com"] [uri "/z9x8c7v6b5-debug-trigger-dodgersboosterclub.com"] [unique_id "aqRDLzN3PgPvfLctlAqqogAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-09-11 18:02:32
(2 hours ago)
Declared crawler ignoring robots.txt and the refusals it is given | ua: Mozilla/5.0 (compatible; Ama ...
show more
Declared crawler ignoring robots.txt and the refusals it is given | ua: Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot) | path: /@fs/var/run/secrets/kubernetes.io/serviceaccount/token (+3 more) | 2026-09-11 18:02 UTC
show less
Bad Web Bot
๐ซ๐ท
masterguru
2026-09-11 17:52:39
(2 hours ago)
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encod ...
show more
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encoding/ /proxy/ /lock-token/ /content-range/ /if/ /x-http-method-override/ /x-http-method/ /x-method-override/ /x-middleware-subrequest/ /expect/" at TX:header_name_920450_x-middleware-subrequest. (920450-197)
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-11 17:45:14
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.140.95.226 (226.95.140.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.140.95.226 (226.95.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 13:45:10.078358 2026] [security2:error] [pid 10670:tid 10670] [client 34.140.95.226:59550] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||dockrockukiah.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "dockrockukiah.com"] [uri "/rclone.conf"] [unique_id "aqQ-JoaRaMmyGJtQlUURmwAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack