🇩🇪
big-cloud.nl
2026-09-10 23:05:47
(4 minutes ago)
Try to access /.env
Web App Attack
Anonymous
2026-09-10 22:52:25
(17 minutes ago)
apache vulnerability scan
Web App Attack
🇺🇸
TPI-Abuse
2026-09-10 22:43:35
(26 minutes ago)
(mod_security) mod_security (id:210730) triggered by 34.179.205.142 (142.205.179.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.179.205.142 (142.205.179.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 18:43:28.198155 2026] [security2:error] [pid 14146:tid 14146] [client 34.179.205.142:55620] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||cosplayculture.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "cosplayculture.com"] [uri "/z9x8c7v6b5-debug-trigger-cosplayculture.com"] [unique_id "aqMykNqLtnHuE79NVdjdCQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-10 22:34:00
(36 minutes ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /rclone.conf | 2026-09-10 22:34 UTC
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-10 22:25:24
(44 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.179.205.142 (142.205.179.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.179.205.142 (142.205.179.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 18:25:20.647698 2026] [security2:error] [pid 15162:tid 15162] [client 34.179.205.142:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cloudex.link"] [uri "/.git/config"] [unique_id "aqMuUE773h_qw2WsNaDrBgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇹🇷
cagatayakinci.com
2026-09-10 21:40:40
(1 hour ago)
34.179.205.142 - - [11/Sep/2026:00:40:27 +0300] "POST /graphql HTTP/1.1" 404 12305 "https://cagataya ...
show more
34.179.205.142 - - [11/Sep/2026:00:40:27 +0300] "POST /graphql HTTP/1.1" 404 12305 "https://cagatayakinci.com" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36"
34.179.205.142 - - [11/Sep/2026:00:40:29 +0300] "POST /api/graphql HTTP/1.1" 404 12305 "https://cagatayakinci.com" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36"
34.179.205.142 - - [11/Sep/2026:00:40:30 +0300] "POST /v1/graphql HTTP/1.1" 404 12305 "https://cagatayakinci.com" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36"
34.179.205.142 - - [11/Sep/2026:00:40:36 +0300] "GET /id_ed25519 HTTP/1.1" 404 12305 "-" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)"
34.179.205.142 - - [11/Sep/2026:00:40:37 +0300] "GET /id_ecdsa HTTP/1.1" 404 12305 "-" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)"
34.179.205
...
show less
Web App Attack
Port Scan
🇩🇪
bryth
2026-09-10 21:31:20
(1 hour ago)
Wordpress login/xmlrpc abuse (Thu Sep 10 09:13:33 PM UTC 2026)
Hacking
Web App Attack
🇺🇸
robotstxt
2026-09-10 21:14:26
(1 hour ago)
34.179.205.142 - - [10/Sep/2026:21:13:21 +0000] "GET /.aws/config HTTP/2.0" 403 36155 "-" "Mozilla/5 ...
show more
34.179.205.142 - - [10/Sep/2026:21:13:21 +0000] "GET /.aws/config HTTP/2.0" 403 36155 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )" "34.179.205.142" edge="172.70.242.204"
34.179.205.142 - - [10/Sep/2026:21:13:21 +0000] "GET /dist/.vite/manifest.json HTTP/2.0" 403 36155 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36" "34.179.205.142" edge="162.159.106.123"
34.179.205.142 - - [10/Sep/2026:21:13:21 +0000] "GET /.vite/manifest.json HTTP/2.0" 403 36155 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36" "34.179.205.142" edge="162.159.106.182"
34.179.205.142 - - [10/Sep/2026:21:13:24 +0000] "GET /.gitlab-ci.yml HTTP/2.0" 403 2 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)" "34.179.205.142" edge="172.70.242.204"
...
show less
Web App Attack
Anonymous
2026-09-10 20:55:00
(2 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-10 20:41:35
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.179.205.142 (142.205.179.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.179.205.142 (142.205.179.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 16:41:29.761366 2026] [security2:error] [pid 25279:tid 25279] [client 34.179.205.142:51694] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||backstore.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "backstore.com"] [uri "/z9x8c7v6b5-debug-trigger-backstore.com"] [unique_id "aqMV-WptttqqnehdU7ArmAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Savvii
2026-09-10 20:40:13
(2 hours ago)
20 attempts against mh-misbehave-ban on boron
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-10 20:32:29
(2 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.179.205.142 (DE/Germany/142.205.179. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.179.205.142 (DE/Germany/142.205.179.34.bc.googleusercontent.com)
show less
SQL Injection
🇸🇪
vaia.cloud
2026-09-10 20:20:01
(2 hours ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
🇮🇹
VHosting
2026-09-10 20:05:03
(3 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇫🇷
regishoussin
2026-09-10 19:46:42
(3 hours ago)
Automated web scanning detected by Wazuh (rule 100180): repeated 400/404 errors from mass probing of ...
show more
Automated web scanning detected by Wazuh (rule 100180): repeated 400/404 errors from mass probing of admin/backdoor paths (e.g. wp-login.php, known CMS shell filenames) on an Apache web server, on 2026-09-10 19:46 UTC.
show less
Bad Web Bot
Web App Attack