๐ง๐ช
cmbplf
2026-06-10 00:31:42
(1 hour ago)
211 requests with url.path *credentials.json
159 requests with url.path *config.json
134 requests ...
show more
211 requests with url.path *credentials.json
159 requests with url.path *config.json
134 requests with url.path *compose.yml
122 requests with url.path *secrets.json
114 requests with url.path *config.yml
show less
Brute-Force
Bad Web Bot
Anonymous
2026-06-10 00:10:12
(1 hour ago)
Bot / seems abusive / Apache connections: 24
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
๐ณ๐ด
jad@
2026-06-09 23:14:24
(2 hours ago)
ThreatFeed automated detection: malicious HTTP scanning / exploit attempts. Signatures: actuator, aw ...
show more
ThreatFeed automated detection: malicious HTTP scanning / exploit attempts. Signatures: actuator, aws_creds, env_probe, config_backup, ssh_keys. Observed by 1 sensor(s); 421 hits.
show less
Hacking
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-06-09 22:03:19
(3 hours ago)
Auto-ban: >3000 req/min op 2026-06-09
Web App Attack
SSH
Hacking
๐ฉ๐ช
onlyops.app
2026-06-09 21:00:04
(4 hours ago)
Web application firewall (ModSecurity) detected malicious traffic | detected by Fail2Ban (plesk-mods ...
show more
Web application firewall (ModSecurity) detected malicious traffic | detected by Fail2Ban (plesk-modsecurity jail) | onlyops.app
show less
Exploited Host
๐ฌ๐ง
Oakley
2026-06-09 20:31:00
(5 hours ago)
(confirmed_bot_sig) Confirmed bot
Hacking
๐ซ๐ท
Octopuce
2026-06-09 17:54:13
(7 hours ago)
Aggressive web search of vulnerable pages: /phpinfo.php /info.php /php.php /test.php /debug.php /php ...
show more
Aggressive web search of vulnerable pages: /phpinfo.php /info.php /php.php /test.php /debug.php /phptest.php /admin/phpinfo.php /api/phpinfo.ph ...
show less
Web App Attack
Anonymous
2026-06-09 17:24:36
(8 hours ago)
(caddyscan) Scanner path probe from 34.185.217.87 (DE/Germany/87.217.185.34.bc.googleusercontent.com ...
show more
(caddyscan) Scanner path probe from 34.185.217.87 (DE/Germany/87.217.185.34.bc.googleusercontent.com): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 34.185.217.87 - - [09/Jun/2026:17:24:31 +0000] "GET /app/actuator/heapdump HTTP/1.1"
[REDACTED] 200 2627 34.185.217.87 - - [09/Jun/2026:17:24:31 +0000] "GET /actuator/trace HTTP/1.1"
[REDACTED] 200 2627 34.185.217.87 - - [09/Jun/2026:17:24:31 +0000] "GET /app/actuator/logfile HTTP/1.1"
[REDACTED] 200 2627 34.185.217.87 - - [09/Jun/2026:17:24:31 +0000] "GET /actuator/heapdump HTTP/1.1"
[REDACTED] 200 2627 34.185.217.87 - - [09/Jun/2026:17:24:31 +0000] "GET /app/actuator/configprops HTTP/1.1"
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-06-09 08:46:42
(16 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.185.217.87 (87.217.185.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.185.217.87 (87.217.185.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 04:46:35.993009 2026] [security2:error] [pid 17590:tid 17590] [client 34.185.217.87:60448] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||dreamingofatlantis.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "dreamingofatlantis.com"] [uri "/.config/gcloud/credentials.db"] [unique_id "aifS6wbWjXOges0Vlt-IOwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 08:23:17
(17 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.185.217.87 (87.217.185.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.185.217.87 (87.217.185.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 04:23:09.368131 2026] [security2:error] [pid 2943:tid 2943] [client 34.185.217.87:45656] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.compu-web.net|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.compu-web.net"] [uri "/.config/gcloud/credentials.db"] [unique_id "aifNbdLwBN_0bM72ngu3RwAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-09 08:20:38
(17 hours ago)
Multiple web server 400 error codes from same source ip
Web App Attack
๐ณ๐ฑ
Site.eu
2026-06-09 07:53:26
(17 hours ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-09 07:48:48
(17 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.185.217.87 (87.217.185.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.185.217.87 (87.217.185.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 03:48:40.693411 2026] [security2:error] [pid 31432:tid 31432] [client 34.185.217.87:59996] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||jessicabaer.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "jessicabaer.com"] [uri "/.config/gcloud/credentials.db"] [unique_id "aifFWL1xF_ogwSVk93EJYAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-09 07:22:03
(18 hours ago)
suspicious behavior
Blog Spam
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2026-06-09 06:07:48
(19 hours ago)
Too many Status 40X (11)
Scanning/Probing (61)
Request Overload (383)
Brute-Force
Web App Attack