Anonymous
2026-10-07 19:17:58
(2 minutes ago)
Fail2Ban apache-noscript
Bad Web Bot
Anonymous
2026-10-07 19:11:55
(8 minutes ago)
Web Probe / Attack
Web App Attack
๐ฉ๐ฐ
HostingGroup
2026-10-07 19:06:54
(13 minutes ago)
Automated malicious activity (Honeypot Trap) detected and blocked at the CDN edge by NordicCDN Shiel ...
show more
Automated malicious activity (Honeypot Trap) detected and blocked at the CDN edge by NordicCDN Shield. Offenses: 5. First blocked: 2026-10-07.
show less
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-10-07 18:44:08
(36 minutes ago)
Multiple WAF Violations
Web App Attack
๐ณ๐ฑ
Eric
2026-10-07 18:43:23
(37 minutes ago)
[Wed Oct 07 18:43:20.529035 2026] [security2:error] [pid 153054:tid 153054] [client 34.180.91.4:0] [ ...
show more
[Wed Oct 07 18:43:20.529035 2026] [security2:error] [pid 153054:tid 153054] [client 34.180.91.4:0] [client 34.180.91.4] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "pop-the-slots.com"] [uri "/z9x8c7v6b5-debug-trigger-pop-the-slots.com"] [unique_id "asaSyESYfPCrGu9Z5eYQEgAAABE"]
[Wed Oct 07 18:43:22.821178 2026] [security2:error] [pid 157520:tid 157520] [client 34.180.91.4:0] [client 34.180.91.4] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (
...
show less
Hacking
Web App Attack
๐บ๐ธ
ph
2026-10-07 18:34:04
(46 minutes ago)
Bad web bot attempting to run wp-json on non-WP site
Hacking
Bad Web Bot
Web App Attack
๐ณ๐ฑ
MyGlobalFlowers
2026-10-07 17:44:58
(1 hour ago)
Multiple WAF Violations
Web App Attack
๐ฌ๐ง
consul.to
2026-10-07 17:33:47
(1 hour ago)
Web attack/malicious scanning detected
Web App Attack
๐ซ๐ฎ
oh.mg
2026-10-07 17:32:06
(1 hour ago)
[Wed Oct 07 19:31:49.118891 2026] [security2:error] [pid 201072:tid 201079] [client 34.180.91.4:0] [ ...
show more
[Wed Oct 07 19:31:49.118891 2026] [security2:error] [pid 201072:tid 201079] [client 34.180.91.4:0] [client 34.180.91.4] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 25)"] [ver "OWASP_CRS/4.10.0-dev"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "mmn.cat"] [uri "/index.php"] [unique_id "asaCBdyILye5Lyb6FIGoYQAAAMU"]
[Wed Oct 07 19:32:05.671037 2026] [security2:error] [pid 201072:tid 201097] [client 34.180.91.4:0] [client 34.180.91.4] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 25)"] [ver "OWASP_CRS/4.10.0-dev"] [tag "anomaly-evaluation"
...
show less
Web App Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-07 17:19:44
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.180.91.4 (4.91.180.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.180.91.4 (4.91.180.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 13:19:38.616379 2026] [security2:error] [pid 20879:tid 20879] [client 34.180.91.4:58998] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||medioskreativos.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "medioskreativos.com"] [uri "/z9x8c7v6b5-debug-trigger-medioskreativos.com"] [unique_id "asZ_KpeNR34ZjL_3f8gjnAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-10-07 17:04:03
(2 hours ago)
20 attempts against mh-misbehave-ban on pyrus
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Lee Daniel
2026-10-07 16:20:49
(2 hours ago)
34.180.91.4 - - [07/Oct/2026:12:20:48 -0400] "GET /.htpasswd HTTP/1.1" 403 377 "-" "Mozilla/5.0 (com ...
show more
34.180.91.4 - - [07/Oct/2026:12:20:48 -0400] "GET /.htpasswd HTTP/1.1" 403 377 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)"
...
show less
DDoS Attack
Web Spam
Email Spam
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Sรฉfora Srl
2026-10-07 15:36:30
(3 hours ago)
crowdsecurity/http-probing detected by CrowdSec
Web App Attack
๐บ๐ธ
Mundo Bueno
2026-10-07 14:36:11
(4 hours ago)
[ISILIA Protection v2.3] Tentative d'accรจs: /@fs/..%252f..%252f..%252f..%252f..%252froot/.env [RATE ...
show more
[ISILIA Protection v2.3] Tentative d'accรจs: /@fs/..%252f..%252f..%252f..%252f..%252froot/.env [RATE LIMITED - 1800s quarantine] | Pays: JP | UA: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexit
show less
Hacking
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-10-07 14:34:54
(4 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1248
Exploited Host
Web App Attack