๐ช๐ธ
masterguru
2026-10-06 10:46:35
(52 seconds ago)
COMODO WAF: URL file extension is restricted by policy. Match of "pmFromFile userdata_wl_extensions" ...
show more
COMODO WAF: URL file extension is restricted by policy. Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. (210730-178)
show less
Hacking
๐ฌ๐ง
masterguru
2026-10-06 10:29:51
(17 minutes ago)
Fake Claudebot fetcher UA from non-Claude IP. Match of "ipMatchFromFile /etc/modsecurity/crs/plugins ...
show more
Fake Claudebot fetcher UA from non-Claude IP. Match of "ipMatchFromFile /etc/modsecurity/crs/plugins/claudebot_fetchers.txt" against "REMOTE_ADDR" required. (200112-185)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-06 10:24:31
(22 minutes ago)
(mod_security) mod_security (id:210730) triggered by 34.152.45.40 (40.45.152.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.152.45.40 (40.45.152.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 06:24:23.330263 2026] [security2:error] [pid 10404:tid 10404] [client 34.152.45.40:43618] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||giganticmediallc.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "giganticmediallc.com"] [uri "/z9x8c7v6b5-debug-trigger-giganticmediallc.com"] [unique_id "asTMV8CoGDDiCzRGj2RwMAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
bazter.pro
2026-10-06 10:21:40
(25 minutes ago)
Fail2Ban: plesk-bot-aggressive - 15 failures
Port Scan
Bad Web Bot
Web App Attack
๐ซ๐ท
ELYAZ
2026-10-06 09:46:42
(1 hour ago)
(y3) Failed access -byebye- from 34.152.45.40 (CA/Canada/40.45.152.34.bc.googleusercontent.com): (C ...
show more
(y3) Failed access -byebye- from 34.152.45.40 (CA/Canada/40.45.152.34.bc.googleusercontent.com): (CF_ENABLE)
show less
Hacking
๐จ๐ฆ
SSH-Admin
2026-10-06 09:41:02
(1 hour ago)
Probing for Exploits on ns124
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 09:40:20
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.152.45.40 (40.45.152.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.152.45.40 (40.45.152.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 05:40:13.385079 2026] [security2:error] [pid 6642:tid 6642] [client 34.152.45.40:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "echelonts.com"] [uri "/cache/original/%2e%2e/%2e%2e/.env"] [unique_id "asTB_YlhcJTg2ARbbd2h_gAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
D3monite
2026-10-06 09:40:07
(1 hour ago)
Attempted Brute Force (APIService)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-10-06 09:22:36
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 34.152.45.40 (40.45.152.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.152.45.40 (40.45.152.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 05:22:31.815141 2026] [security2:error] [pid 4232:tid 4232] [client 34.152.45.40:60354] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||deniz-bilgisayar.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "deniz-bilgisayar.com"] [uri "/z9x8c7v6b5-debug-trigger-deniz-bilgisayar.com"] [unique_id "asS9133PGi81mZntnSLa_AAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-10-06 09:21:33
(1 hour ago)
This IP was detected by CrowdSec triggering crowdsecurity/grafana-cve-2021-43798
Web App Attack
Hacking
Anonymous
2026-10-06 08:35:38
(2 hours ago)
git/env leak probe
Web App Attack
๐ณ๐ฑ
Site.eu
2026-10-06 08:04:32
(2 hours ago)
Excessive 404/403 errors
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-10-06 07:50:12
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.152.45.40 (40.45.152.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.152.45.40 (40.45.152.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 03:50:08.619923 2026] [security2:error] [pid 14795:tid 14795] [client 34.152.45.40:39004] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||alccontractorsllc.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "alccontractorsllc.com"] [uri "/z9x8c7v6b5-debug-trigger-alccontractorsllc.com"] [unique_id "asSoMNEBLRsycKW_HxrQjgAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
pipeline.es
2026-10-06 07:31:38
(3 hours ago)
Web scanning / probing for vulnerable paths | URL: /docker-compose.yaml | Evidence: 3tbooking.com 34 ...
show more
Web scanning / probing for vulnerable paths | URL: /docker-compose.yaml | Evidence: 3tbooking.com 34.152.45.40 - - [06/Oct/2026:09:31:06 +0200] \"GET /docker-compose.yaml HTTP/2.0\" 404 27629 \"-\" \"Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email])\" GEOIP_COUNTRY_CODE=CA 24646 | ASN: GOOGLE-CLOUD-PLATFORM | Country: CA
show less
Port Scan
Web App Attack
๐บ๐ธ
sandra361
2026-10-06 05:32:50
(5 hours ago)
Port scan detected: 7 attempts across 4 ports (80, 443, 8080, 8443). | Evidence: GHOST_SCAN: IN=enp1 ...
show more
Port scan detected: 7 attempts across 4 ports (80, 443, 8080, 8443). | Evidence: GHOST_SCAN: IN=enp1s0 SRC=34.152.45.40 LEN=60 TOS=0x00 PREC=0x00 TTL=58 ID=2604 DF PROTO=TCP SPT=44430 DPT=8443 WINDOW=65320 RES=0x00 SYN URGP=0
show less
Port Scan