๐ฉ๐ช
dbmwebdesign
2026-06-15 04:10:25
(1 day ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
๐ฌ๐ง
OptimusGO
2026-06-15 03:35:26
(2 days ago)
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show more
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-06-15 04:35:26 UTC
Log evidence:
06/15/2026-04:35:25.446854 [wDrop] [**] [1:7000500:1] FINSERV CRITICAL: Aggressive Port Scan [**] [Classification: Attempted Information Leak] [Priority: 2] {TCP} 34.174.218.240:36486 -> 185.127.18.66:443
06/15/2026-04:35:25.446854 [**] [1:9000060:2] AUTONOMOUS Long-term Reconnaissance [**] [Classification: (null)] [Priority: 2] {TCP} 34.174.218.240:36486 -> 185.127.18.66:443
show less
Port Scan
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-15 03:19:20
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.174.218.240 (240.218.174.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.174.218.240 (240.218.174.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 23:19:17.007397 2026] [security2:error] [pid 29456:tid 29456] [client 34.174.218.240:51936] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mdivietnam.com"] [uri "/app/.git/config"] [unique_id "ai9vNe3Q4ccpjn1lEQZxvgAAACk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
excill
2026-06-15 03:09:50
(2 days ago)
Honeypot mesh observed 775 attack events in 24h โ cowrie/dionaea/heralding/suricata
Port Scan
Hacking
Brute-Force
SSH
๐ซ๐ท
masterguru
2026-06-15 02:42:20
(2 days ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-196)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 02:11:27
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.174.218.240 (240.218.174.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.174.218.240 (240.218.174.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 22:11:19.836090 2026] [security2:error] [pid 5651:tid 5651] [client 34.174.218.240:54712] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.jpsa.org"] [uri "/.git/config"] [unique_id "ai9fR1YqYj6VoKUHRN8hiwAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 01:42:54
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.174.218.240 (240.218.174.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.174.218.240 (240.218.174.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 21:42:50.981235 2026] [security2:error] [pid 6434:tid 6434] [client 34.174.218.240:46688] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "n6nz.net"] [uri "/v3/.git/config"] [unique_id "ai9YmipnzcYfnhNkUNsiogAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-06-15 01:28:30
(2 days ago)
20 attempts against mh-misbehave-ban on ficus
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 01:05:25
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.174.218.240 (240.218.174.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.174.218.240 (240.218.174.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 21:05:21.133452 2026] [security2:error] [pid 27630:tid 27630] [client 34.174.218.240:44154] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.agreyhawkcampaign.net.bandsolution.net"] [uri "/app/.git/config"] [unique_id "ai9P0U1d0qphNtjWHA_npwAAAGo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
DEV-DNS
2026-06-15 00:44:27
(2 days ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
Anonymous
2026-06-15 00:30:05
(2 days ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
mnsf
2026-06-15 00:19:54
(2 days ago)
Scanning/Probing (30)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 22:48:07
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.174.218.240 (240.218.174.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.174.218.240 (240.218.174.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 18:48:03.737068 2026] [security2:error] [pid 1430:tid 1430] [client 34.174.218.240:36736] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.underraided.lmffl.com"] [uri "/.git/config"] [unique_id "ai8vow6yoMrTj56LpPgEwQAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
pipeline.es
2026-06-14 22:31:57
(2 days ago)
Web scanning / probing for vulnerable paths | URL: /public/.git/config | Evidence: 3tbooking.com 34. ...
show more
Web scanning / probing for vulnerable paths | URL: /public/.git/config | Evidence: 3tbooking.com 34.174.218.240 - - [15/Jun/2026:00:31:37 +0200] \"GET /public/.git/config HTTP/1.1\" 404 27626 \"-\" \"Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.89 Safari/537.36\" GEOIP_COUNTRY_CODE=US | ASN: GOOGLE-CLOUD-PLATFORM | Country: US
show less
Port Scan
Web App Attack
๐ช๐ธ
matatunos
2026-06-14 22:30:17
(2 days ago)
Honeypot favala.es: 30 peticiones web a rutas de ataque (/wp-login, /.env, etc.) en 24h. Reporte aut ...
show more
Honeypot favala.es: 30 peticiones web a rutas de ataque (/wp-login, /.env, etc.) en 24h. Reporte automรกtico.
show less
Web App Attack
Bad Web Bot