Anonymous
2026-10-07 19:51:44
(59 minutes ago)
(mod_security) mod_security triggered on hostname [redacted] 34.158.48.122 (SG/Singapore/122.48.158. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.158.48.122 (SG/Singapore/122.48.158.34.bc.googleusercontent.com)
show less
SQL Injection
๐ฎ๐ช
RoboSOC
2026-10-07 19:49:05
(1 hour ago)
PHP CGI Argument Injection Vulnerability, PTR: 122.48.158.34.bc.googleusercontent.com.
Hacking
๐บ๐ธ
CDO
2026-10-07 19:39:42
(1 hour ago)
URL Injection attempt detected. Automated web attack.
Hacking
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-10-07 19:24:41
(1 hour ago)
20 attempts against mh-misbehave-ban on ethyl
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Phenix Info
2026-10-07 19:06:24
(1 hour ago)
SmallGuard.fr - Forbidden Ext.
Web App Attack
๐บ๐ธ
masterguru
2026-10-07 18:34:06
(2 hours ago)
BAD BOT - Detected and Blocked.. Matched phrase "baidu" at REQUEST_HEADERS:user-agent. (1100000-169)
Bad Web Bot
๐ฉ๐ช
LRob
2026-10-07 18:33:34
(2 hours ago)
Wordlist path sweep | method: GET, POST | path: /build/manifest.json, /dist/.vite/manifest.json, /li ...
show more
Wordlist path sweep | method: GET, POST | path: /build/manifest.json, /dist/.vite/manifest.json, /lib/terminal-xhr.php (+3 more) | ua: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36 EdgA/152.0.0.0, Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/), Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)
show less
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 18:32:40
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.158.48.122 (122.48.158.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.158.48.122 (122.48.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 14:32:32.527267 2026] [security2:error] [pid 10433:tid 10433] [client 34.158.48.122:54008] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||primemanagementmn.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "primemanagementmn.com"] [uri "/z9x8c7v6b5-debug-trigger-primemanagementmn.com"] [unique_id "asaQQKdmWn4lQsEWOdraaQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-10-07 18:27:03
(2 hours ago)
Try to access /.ssh/id_rsa
Web App Attack
๐น๐ญ
MWA SOC
2026-10-07 17:36:57
(3 hours ago)
Hacking
๐ณ๐ฑ
MyGlobalFlowers
2026-10-07 17:35:25
(3 hours ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
Sรฉfora Srl
2026-10-07 17:33:00
(3 hours ago)
crowdsecurity/http-probing detected by CrowdSec
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 16:38:09
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.158.48.122 (122.48.158.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.158.48.122 (122.48.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 12:38:02.497062 2026] [security2:error] [pid 13671:tid 13671] [client 34.158.48.122:52220] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||landjudging.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "landjudging.com"] [uri "/z9x8c7v6b5-debug-trigger-landjudging.com"] [unique_id "asZ1an86o_gcjRIrCe4pFQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-07 16:34:02
(4 hours ago)
Bot / scanning and/or hacking attempts: [133/133] read: stream 0, , POST /api/v1/node-load-method/c ...
show more
Bot / scanning and/or hacking attempts: [133/133] read: stream 0, , POST /api/v1/node-load-method/customMCP HTTP/2.0, POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e
show less
Hacking
Web App Attack
๐บ๐ธ
helios.live
2026-10-07 16:28:44
(4 hours ago)
2026/10/07 16:28:41 [error] 4069920#4069920: *109071 FastCGI sent in stderr: "Primary script unknown ...
show more
2026/10/07 16:28:41 [error] 4069920#4069920: *109071 FastCGI sent in stderr: "Primary script unknown" while reading response header from upstream, client: 34.158.48.122, server: kocerroxy.com, request: "POST /lib/terminal-xhr.php HTTP/1.1", upstream: "fastcgi://unix:/var/run/php/php8.4-fpm-betakocerroxycom.sock:", host: "kocerroxy.com"
34.158.48.122 - - [07/Oct/2026:16:28:41 +0000] "POST /lib/terminal-xhr.php HTTP/1.1" 404 47 "-" "Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)"
2026/10/07 16:28:43 [error] 4069920#4069920: *109071 FastCGI sent in stderr: "Primary script unknown" while reading response header from upstream, client: 34.158.48.122, server: kocerroxy.com, request: "POST /icecoder/lib/terminal-xhr.php HTTP/1.1", upstream: "fastcgi://unix:/var/run/php/php8.4-fpm-betakocerroxycom.sock:", host: "kocerroxy.com"
34.158.48.122 - - [07/Oct/2026:16:28:43 +0000] "POST /icecoder/lib/terminal-xhr.php HTTP/1.1" 404 47 "-" "Mozilla/5.0 (compatible; cohere-ai;
...
show less
Web App Attack