๐ณ๐ฑ
Hans Renses
2026-10-03 08:12:15
(3 days ago)
Web app attack: 6 requests for known vulnerable paths (.env, xmlrpc.php, web shells, config backups) ...
show more
Web app attack: 6 requests for known vulnerable paths (.env, xmlrpc.php, web shells, config backups) within one hour. Reported automatically by BotZoom.
show less
Web App Attack
Hacking
๐บ๐ธ
magnetosphere-tarpit
2026-10-03 06:53:24
(3 days ago)
Automated web scanner: repeatedly probed for .env, .git, wp-admin and PHP webshell paths that do not ...
show more
Automated web scanner: repeatedly probed for .env, .git, wp-admin and PHP webshell paths that do not exist on this host. Tarpitted, then banned: 10 requests within 24h0m0s
show less
Port Scan
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-03 03:18:38
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 34.159.54.116 (116.54.159.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.159.54.116 (116.54.159.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 23:18:34.888009 2026] [security2:error] [pid 28544:tid 28544] [client 34.159.54.116:33864] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.madronabluff.com|F|2"] [data ".madronabluff.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.madronabluff.com"] [uri "/z9x8c7v6b5-debug-trigger-www.madronabluff.com"] [unique_id "asB0CjlxIoNQS1O-6qCp0wAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐น
penguin-solutions.at
2026-10-03 03:05:34
(3 days ago)
Excessive 403/404 errors
...
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-03 01:53:51
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.159.54.116 (116.54.159.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.159.54.116 (116.54.159.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 21:53:47.633194 2026] [security2:error] [pid 27046:tid 27046] [client 34.159.54.116:34902] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/Web.config" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.maffiniandbearce.com"] [uri "/web.config"] [unique_id "asBgK2wTmblP2HwbnVop5wAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-10-03 01:40:03
(3 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ฌ๐ง
andypiper
2026-10-03 01:01:57
(3 days ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
๐ฉ๐ช
Philister11
2026-10-03 00:13:45
(3 days ago)
CrowdSec: crowdsecurity/http-sensitive-files (DE/AS396982)
Web App Attack
Hacking
๐บ๐ธ
dot.mg
2026-10-02 23:40:02
(3 days ago)
Scan of vulnerable files
Web App Attack
๐ฌ๐ง
Celtic
2026-10-02 22:46:10
(3 days ago)
Blocked by Fail2Ban with Jail (plesk-modsecurity)
Brute-Force
SSH
๐ฉ๐ช
yvoictra
2026-10-02 21:27:37
(3 days ago)
Bloqueado automรกticamente por CrowdSec. Escenario: crowdsecurity/http-probing
Web App Attack
๐ฌ๐ง
thetomtaylor.co.uk
2026-10-02 19:08:02
(3 days ago)
Fail2Ban - [WAF]ModSecurity OWASP CRS rule violation on nginx-modsecurity ... [ice01,ice02,wa01,wa02 ...
show more
Fail2Ban - [WAF]ModSecurity OWASP CRS rule violation on nginx-modsecurity ... [ice01,ice02,wa01,wa02]
show less
Hacking
SQL Injection
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 16:17:05
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 34.159.54.116 (116.54.159.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.159.54.116 (116.54.159.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 12:17:00.660171 2026] [security2:error] [pid 32417:tid 32417] [client 34.159.54.116:58006] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.magnoliahillproductions.com|F|2"] [data ".magnoliahillproductions.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.magnoliahillproductions.com"] [uri "/z9x8c7v6b5-debug-trigger-www.magnoliahillproductions.com"] [unique_id "ar_Y_G_ru5X5LFE-e6IFEQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
agenciahypelab.com.br
2026-10-02 15:57:34
(4 days ago)
WordPress login brute-force detectado e bloqueado pelo CSF/LFD. Trigger: LF_TRIGGER
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-10-02 15:44:05
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 34.159.54.116 (116.54.159.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.159.54.116 (116.54.159.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 11:43:59.939877 2026] [security2:error] [pid 3535:tid 3535] [client 34.159.54.116:36126] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||madisonjazzorchestra.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "madisonjazzorchestra.com"] [uri "/z9x8c7v6b5-debug-trigger-madisonjazzorchestra.com"] [unique_id "ar_RPz2sjfx5r4CPkML9yQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack