๐ธ๐ฌ
Cloudkul Cloudkul
2026-09-21 08:19:33
(3 days ago)
Attempted Not Found (404 status code) requests on our application, more than 30% of their total requ ...
show more
Attempted Not Found (404 status code) requests on our application, more than 30% of their total requests.
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 21:13:06
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 34.165.204.2 (2.204.165.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.165.204.2 (2.204.165.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 17:12:59.351320 2026] [security2:error] [pid 8764:tid 8764] [client 34.165.204.2:33838] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.gundiahgazette.g-h2o.com|F|2"] [data ".env.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.gundiahgazette.g-h2o.com"] [uri "/.env.bak"] [unique_id "arBMWwi-RuKWFHNFslpwSwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-20 18:15:02
(4 days ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
๐จ๐ฆ
polycoda
2026-09-20 10:18:50
(4 days ago)
AutoBlock: ๐ฏ Vulnerability Scanner (Non Decay-Based) - โ๏ธ Configuration File Access (Non Decay-Based ...
show more
AutoBlock: ๐ฏ Vulnerability Scanner (Non Decay-Based) - โ๏ธ Configuration File Access (Non Decay-Based)
show less
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
dot.mg
2026-09-20 10:12:11
(4 days ago)
Scan of vulnerable files
Web App Attack
๐ฎ๐น
VHosting
2026-09-20 08:55:04
(4 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 04:33:37
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 34.165.204.2 (2.204.165.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.165.204.2 (2.204.165.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 00:33:30.995749 2026] [security2:error] [pid 17812:tid 17812] [client 34.165.204.2:37418] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/config/config.yml" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "frontlinefirestop.com"] [uri "/config/config.yml"] [unique_id "ai-AmjVvjLzLwqyqdZ3JaQAAAF0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
excill
2026-06-15 03:02:21
(3 months ago)
Honeypot mesh observed 6422 attack events in 24h โ cowrie/dionaea/heralding/suricata
Port Scan
Hacking
Brute-Force
SSH
๐ฌ๐ง
consul.to
2026-06-15 01:22:44
(3 months ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 00:31:44
(3 months ago)
(mod_security) mod_security (id:210831) triggered by 34.165.204.2 (2.204.165.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210831) triggered by 34.165.204.2 (2.204.165.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 20:31:40.598834 2026] [security2:error] [pid 18486:tid 18486] [client 34.165.204.2:45090] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||sportfabrics.com|F|4"] [data "Web Downloader"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "sportfabrics.com"] [uri "/private/credentials.json"] [unique_id "ai9H7HKe8BeI-M041vGPlgAAAFo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 23:52:42
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 34.165.204.2 (2.204.165.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.165.204.2 (2.204.165.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 19:52:35.430759 2026] [security2:error] [pid 4882:tid 4882] [client 34.165.204.2:55810] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||motherlyhomecare.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "motherlyhomecare.com"] [uri "/.config/gcloud/credentials.db"] [unique_id "ai8-wyBpsdU79mMuvplhWAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-14 17:07:48
(3 months ago)
Scenarios: http-bad-user-agent, http-crawl-non_statics, http-probing, http-sensitive-files
Total req ...
show more
Scenarios: http-bad-user-agent, http-crawl-non_statics, http-probing, http-sensitive-files
Total requests: 427
[14/Jun/2026:17:07:42 +0000] [Client: 34.165.204.2] GET [400] "/actuator/heapdump" User-Agent: "Mozilla/5.0 (Linux; Android 8.1.0; LM-Q925S) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.111 Mobile Safari/537.36"
[14/Jun/2026:17:07:42 +0000] [Client: 34.165.204.2] GET [400] "/actuator/env" User-Agent: "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.78 Safari/537.36"
[14/Jun/2026:17:07:42 +0000] [Client: 34.165.204.2] GET [400] "/actuator/configprops" User-Agent: "HTC-ST7377/1.59.502.3 (67150) Opera/9.50 (Windows NT 5.1; U; en) UP.Link/6.3.1.17.0"
[14/Jun/2026:17:07:42 +0000] [Client: 34.165.204.2] GET [400] "/actuator/logfile" User-Agent: "Mozilla/5.0 (Linux; Android 9; G8343 Build/47.2.A.10.107; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/76.0.3809.111 Mobile Safari/537.36 [FB_IAB/Orca-Android;FBAV/229.1.0.17.118;]"
show less
Web App Attack
๐ซ๐ท
HerrWolf
2026-06-14 15:45:03
(3 months ago)
CrowdSec Detection: crowdsecurity/http-sensitive-files
Web App Attack
๐ง๐พ
lns.bz
2026-06-14 07:10:50
(3 months ago)
Too many 404 requests [BY]
Web App Attack
๐ฎ๐น
VHosting
2026-06-14 06:45:03
(3 months ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack