|
๐ฒ๐ฝ
octageeks.com
|
|
Wordpress malicious attack:[octablocked]
|
Web App Attack
|
|
|
๐ช๐ธ
pipeline.es
|
|
Web scanning / probing for vulnerable paths | URL: /dump.sql.gz | Evidence: landingow.aavv.com 34.17 ...
show more
Web scanning / probing for vulnerable paths | URL: /dump.sql.gz | Evidence: landingow.aavv.com 34.176.55.55 - - [27/May/2026:13:13:19 +0200] \"GET /dump.sql.gz HTTP/1.1\" 404 209 \"-\" \"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3833.99 Safari/537.36\" GEOIP_COUNTRY_CODE=CL | ASN: GOOGLE-CLOUD-PLATFORM | Country: CL
show less
|
Port Scan
Web App Attack
|
|
|
๐ฉ๐ช
DEV-DNS
|
|
(mod_security) mod_security triggered on hostname [redacted])
|
SQL Injection
|
|
|
Anonymous
|
|
WAF repeated trigger detected by Fail2Ban
|
Web App Attack
|
|
|
๐ณ๐ฑ
WeCloudit-Anti-Abuse
|
|
SPAM - Bruteforce Attack - DDOS 2
|
Email Spam
Brute-Force
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210730) triggered by 34.176.55.55 (55.55.176.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.176.55.55 (55.55.176.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 27 04:16:59.328226 2026] [security2:error] [pid 5379:tid 5379] [client 34.176.55.55:58380] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.daterapebooks.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.daterapebooks.com"] [uri "/.config/gcloud/credentials.db"] [unique_id "ahaoe50qspv-vKc9CQmwtwAAAAg"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
mnsf
|
|
Too many Status 40X (11)
Scanning/Probing (61)
Request Overload (383)
|
Brute-Force
Web App Attack
|
|
|
๐ซ๐ท
Hippoline
|
|
[Wed May 27 05:11:13.686517 2026] [authz_core:error] [pid 22152] [client 34.176.55.55:39786] AH01630 ...
show more
[Wed May 27 05:11:13.686517 2026] [authz_core:error] [pid 22152] [client 34.176.55.55:39786] AH01630: client denied by server configuration: /var/www/beaufort-online.lu/web/info.php
[Wed May 27 05:11:13.814408 2026] [authz_core:error] [pid 21213] [client 34.176.55.55:39740] AH01630: client denied by server configuration: /var/www/beaufort-online.lu/web/phpinfo.php
[Wed May 27 05:11:14.080116 2026] [authz_core:error] [pid 23966] [client 34.176.55.55:39826] AH01630: client denied by server configuration: /var/www/beaufort-online.lu/web/test.php
[Wed May 27 05:11:14.116754 2026] [authz_core:error] [pid 22152] [client 34.176.55.55:39812] AH01630: client denied by server configuration: /var/www/beaufort-online.lu/web/php.php
[Wed May 27 05:11:14.184431 2026] [authz_core:error] [pid 23968] [client 34.176.55.55:39850] AH01630: client denied by server configuration: /var/www/beaufort-online.lu/web/debug.php
...
show less
|
Brute-Force
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 34.176.55.55 (55.55.176.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.176.55.55 (55.55.176.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 26 21:54:42.314978 2026] [security2:error] [pid 7368:tid 7368] [client 34.176.55.55:50046] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/config/config.yml" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.polar-design.com"] [uri "/config/config.yml"] [unique_id "ahZO4pnDLHVSh9Ipf_zCQgAAABQ"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
Anonymous
|
|
| Blacklisted user agent (known malicious user agent).
|
Web App Attack
Hacking
SQL Injection
|
|
|
๐ณ๐ฑ
e.fierstra
|
|
ModSecurity hits exceeded
|
Bad Web Bot
Web App Attack
|
|
|
๐ฉ๐ช
Hazzard
|
|
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
|
SQL Injection
|
|