๐ธ๐ฌ
Cloudkul Cloudkul
2026-10-11 03:54:26
(16 minutes ago)
Attempted Brute Force on our application
Brute-Force
Web App Attack
๐ช๐ธ
robotstxt
2026-10-11 03:06:04
(1 hour ago)
34.185.154.29 - - [11/Oct/2026:03:05:13 +0000] "GET /z9x8c7v6b5-debug-trigger-alicante.monteroespino ...
show more
34.185.154.29 - - [11/Oct/2026:03:05:13 +0000] "GET /z9x8c7v6b5-debug-trigger-alicante.monteroespinosaonline.com HTTP/2.0" 403 21228 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot" "-" edge="34.185.154.29"
34.185.154.29 - - [11/Oct/2026:03:05:13 +0000] "GET /.vite/manifest.json HTTP/2.0" 403 20643 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "-" edge="34.185.154.29"
34.185.154.29 - - [11/Oct/2026:03:05:13 +0000] "GET /wp-content/plugins/userswp/assets/js/users-wp.min.js?ver=1.2.77 HTTP/2.0" 403 20583 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "-" edge="34.185.154.29"
34.185.154.29 - - [11/Oct/2026:03:05:13 +0000] "GET /p68q1doyrvc81tczkltg/ HTTP/2.0" 403 21230 "https://alicante.monteroespinosaonline.com/p68q1doyrvc81tczkltg" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; c
...
show less
Web App Attack
๐ฉ๐ช
Sรฉfora Srl
2026-10-11 02:36:24
(1 hour ago)
crowdsecurity/http-sensitive-files detected by CrowdSec
Web App Attack
๐ฉ๐ช
XICTRON
2026-10-11 01:55:07
(2 hours ago)
ModSecurity rule violation detected by Fail2Ban
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-11 01:37:45
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.185.154.29 (29.154.185.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.185.154.29 (29.154.185.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 21:37:40.234526 2026] [security2:error] [pid 10313:tid 10313] [client 34.185.154.29:38254] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||aivosminerals.soviaenterprises.com|F|2"] [data ".soviaenterprises.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "aivosminerals.soviaenterprises.com"] [uri "/z9x8c7v6b5-debug-trigger-aivosminerals.soviaenterprises.com"] [unique_id "asroZLCdxw3ipXFRoYWGBAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Quarks Solutions
2026-10-11 01:27:13
(2 hours ago)
crowdsecurity/appsec-vpatch
Web App Attack
Anonymous
2026-10-11 00:57:36
(3 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-10-11 00:39:58
(3 hours ago)
excessive HTTP 404 errors
Bad Web Bot
๐ช๐ธ
robotstxt
2026-10-11 00:35:46
(3 hours ago)
34.185.154.29 - - [11/Oct/2026:00:35:44 +0000] "GET /public/plugins/text/../../../../../../../../pro ...
show more
34.185.154.29 - - [11/Oct/2026:00:35:44 +0000] "GET /public/plugins/text/../../../../../../../../proc/self/environ HTTP/1.1" 400 193 "-" "-" "-" edge="34.185.154.29"
34.185.154.29 - - [11/Oct/2026:00:35:45 +0000] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fproc/self/environ HTTP/1.1" 400 193 "-" "-" "-" edge="34.185.154.29"
34.185.154.29 - - [11/Oct/2026:00:35:45 +0000] "GET /icons/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/proc/self/environ HTTP/1.1" 400 193 "-" "-" "-" edge="34.185.154.29"
34.185.154.29 - - [11/Oct/2026:00:35:45 +0000] "GET /..%2f.env HTTP/1.1" 400 193 "-" "-" "-" edge="34.185.154.29"
34.185.154.29 - - [11/Oct/2026:00:35:45 +0000] "GET /uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f.env HTTP/1.1" 400 193 "-" "-" "-" edge="34.185.154.29"
...
show less
Web Spam
Web App Attack
Anonymous
2026-10-11 00:18:02
(3 hours ago)
34.185.154.29 - - [11/Oct/2026:02:17:48 +0200] "GET /cache/original/%2e%2e/%2e%2e/.env HTTP/2.0" 403 ...
show more
34.185.154.29 - - [11/Oct/2026:02:17:48 +0200] "GET /cache/original/%2e%2e/%2e%2e/.env HTTP/2.0" 403 272 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)"
show less
Web Spam
Blog Spam
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-11 00:00:36
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.185.154.29 (29.154.185.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.185.154.29 (29.154.185.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 20:00:28.743301 2026] [security2:error] [pid 12873:tid 12873] [client 34.185.154.29:43382] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||steinrauffamilylaw.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "steinrauffamilylaw.com"] [uri "/z9x8c7v6b5-debug-trigger-steinrauffamilylaw.com"] [unique_id "asrRnPPkS3xyjlx19bBBcAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐พ
Rizzy
2026-10-10 23:52:04
(4 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
Anonymous
2026-10-10 23:40:07
(4 hours ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection
๐ณ๐ฑ
Alt255
2026-10-10 23:26:17
(4 hours ago)
[ti-05al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-05al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.185.154.29 - - [11/Oct/2026:01:26:06 +0200] "GET /.env.prod HTTP/2.0" 403 346 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-10 23:22:42
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.185.154.29 (29.154.185.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.185.154.29 (29.154.185.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 19:22:37.371792 2026] [security2:error] [pid 21248:tid 21248] [client 34.185.154.29:46074] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||lobibilisim.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "lobibilisim.com"] [uri "/z9x8c7v6b5-debug-trigger-lobibilisim.com"] [unique_id "asrIvbIslHClNUu7m-Aa2AAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack