๐ฉ๐ช
macrob
2026-10-05 08:22:22
(1 minute ago)
2026/10/05 08:22:21 [error] 3618035#3618035: *18080622 access forbidden by rule, client: 34.146.69.1 ...
show more
2026/10/05 08:22:21 [error] 3618035#3618035: *18080622 access forbidden by rule, client: 34.146.69.104, server: fn.binixo.es, request: "GET /z9x8c7v6b5-debug-trigger-administrator.smoozy.org HTTP/2.0", host: "administrator.smoozy.org"
2026/10/05 08:22:21 [error] 3618035#3618035: *18080626 access forbidden by rule, client: 34.146.69.104, server: fn.binixo.es, request: "GET /dist/.vite/manifest.json HTTP/2.0", host: "administrator.smoozy.org"
2026/10/05 08:22:21 [error] 3618035#3618035: *18080627 access forbidden by rule, client: 34.146.69.104, server: fn.binixo.es, request: "GET /.vite/manifest.json HTTP/2.0", host: "administrator.smoozy.org"
...
show less
Web App Attack
๐ฆ๐ฒ
arm osint
2026-10-05 06:24:02
(2 hours ago)
Automated web vulnerability scanning: 167 HTTP 4xx probes for sensitive paths (/graphql, /%2Fapi/con ...
show more
Automated web vulnerability scanning: 167 HTTP 4xx probes for sensitive paths (/graphql, /%2Fapi/config, /%2Fdashboard, /%2Fsettings). Detected by Wazuh HIDS rule 31151 on a self-hosted web server.
show less
Web App Attack
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-10-05 06:11:40
(2 hours ago)
(mod_security) mod_security (id:210580) triggered by 34.146.69.104 (104.69.146.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210580) triggered by 34.146.69.104 (104.69.146.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 02:11:36.527697 2026] [security2:error] [pid 23875:tid 23875] [client 34.146.69.104:41282] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at ARGS:path. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||watongacommunitycats.org|F|2"] [data "Matched Data: proc/self/environ found within ARGS:path: ../../../../proc/self/environ"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "watongacommunitycats.org"] [uri "/userfiles/x"] [unique_id "asM_mPvebyINp_EXSwlncQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Gwyneth Llewelyn
2026-10-05 06:10:09
(2 hours ago)
2026/10/05 07:10:03 [error] 3069275#3069275: *155921 access forbidden by rule, client: 34.146.69.104 ...
show more
2026/10/05 07:10:03 [error] 3069275#3069275: *155921 access forbidden by rule, client: 34.146.69.104, server: vp-arc.org, request: "GET /cache/original/%2e%2e/.env HTTP/2.0", host: "vp-arc.org"
2026/10/05 07:10:03 [error] 3069275#3069275: *155921 access forbidden by rule, client: 34.146.69.104, server: vp-arc.org, request: "GET /cache/original/%2e%2e/%2e%2e/.env HTTP/2.0", host: "vp-arc.org"
2026/10/05 07:10:08 [error] 3069275#3069275: *155921 access forbidden by rule, client: 34.146.69.104, server: vp-arc.org, request: "GET /dist../.env HTTP/2.0", host: "vp-arc.org"
show less
Brute-Force
Web App Attack
Anonymous
2026-10-05 06:07:32
(2 hours ago)
[abuseipdb-autoban] 2026-10-05 06:07:32, Client: 34.146.69.104, Protocol: 6 (TCP), Service: HTTP, Ac ...
show more
[abuseipdb-autoban] 2026-10-05 06:07:32, Client: 34.146.69.104, Protocol: 6 (TCP), Service: HTTP, Activity: auto-banned after exceeding AbuseIPDB score threshold on visit to /, likely unclassified automated client, AbuseIPDB score at ban time: 100% (48 prior reports)
show less
Bad Web Bot
Web App Attack
Anonymous
2026-10-05 05:58:28
(2 hours ago)
Sensitive file access attempt
Hacking
Anonymous
2026-10-05 05:55:43
(2 hours ago)
Fail2Ban apache-noscript
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-05 05:31:04
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.146.69.104 (104.69.146.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.146.69.104 (104.69.146.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 01:30:59.464808 2026] [security2:error] [pid 11079:tid 11079] [client 34.146.69.104:36610] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "soudertonbigred.org"] [uri "/api/fs/read"] [unique_id "asM2E5Pd_9D_e2hjNxvHZgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-10-05 05:14:47
(3 hours ago)
BAD BOT - Detected and Blocked.. Matched phrase "bytespider" at REQUEST_HEADERS:User-Agent. (1100000 ...
show more
BAD BOT - Detected and Blocked.. Matched phrase "bytespider" at REQUEST_HEADERS:User-Agent. (1100000-193)
show less
Bad Web Bot
๐ฉ๐ช
macrob
2026-10-05 05:08:23
(3 hours ago)
2026/10/05 05:08:22 [error] 3447619#3447619: *17564524 access forbidden by rule, client: 34.146.69.1 ...
show more
2026/10/05 05:08:22 [error] 3447619#3447619: *17564524 access forbidden by rule, client: 34.146.69.104, server: fn.binixo.es, request: "GET /.vite/manifest.json HTTP/2.0", host: "smoozy.org"
2026/10/05 05:08:22 [error] 3447619#3447619: *17564526 access forbidden by rule, client: 34.146.69.104, server: fn.binixo.es, request: "GET /dist/.vite/manifest.json HTTP/2.0", host: "smoozy.org"
2026/10/05 05:08:22 [error] 3447619#3447619: *17564521 access forbidden by rule, client: 34.146.69.104, server: fn.binixo.es, request: "GET /.htpasswd HTTP/2.0", host: "smoozy.org"
...
show less
Web App Attack
๐ฉ๐ช
netman
2026-10-05 05:03:11
(3 hours ago)
HTTP: 34.146.69.104 blocked because of 100 failures
...
DDoS Attack
Web App Attack
๐บ๐ธ
factor1
2026-10-05 04:06:33
(4 hours ago)
CrowdSec at saturn Reports Abuse
Web App Attack
๐ง๐ช
cmbplf
2026-10-05 03:35:03
(4 hours ago)
588 requests with url.path */@fs/*
214 requests with url.path */proc/*
124 requests with url.path ...
show more
588 requests with url.path */@fs/*
214 requests with url.path */proc/*
124 requests with url.path *.aws/*
111 requests with url.path *.ssh/*
show less
Brute-Force
Bad Web Bot
๐บ๐ธ
1cyb3rpunk
2026-10-05 03:21:04
(5 hours ago)
Honeypot interaction [EXPLOIT]: php_webshell_probe on /lib/terminal-xhr.php. MITRE: T1204 (User Exec ...
show more
Honeypot interaction [EXPLOIT]: php_webshell_probe on /lib/terminal-xhr.php. MITRE: T1204 (User Execution). UA: Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot). Observed on sectrace.org honeypot surface โ automated scanner/attacker activity.
show less
Exploited Host
Hacking
๐ฉ๐ช
Teufel100
2026-10-05 03:20:29
(5 hours ago)
ModSecurity rejected a query
Brute-Force
Hacking
Web App Attack