๐บ๐ธ
wbsouza
2026-10-06 03:33:17
(4 days ago)
CrowdSec: infra/appsec-challenge-requested-log โ automated firewall drops on self-hosted IDS sensor
Hacking
๐ซ๐ฎ
buhbbl
2026-10-05 19:51:22
(4 days ago)
nginx-forceful-browsing
Web Spam
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 12:52:28
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 34.19.223.238 (238.223.19.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.19.223.238 (238.223.19.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 08:52:21.202906 2026] [security2:error] [pid 23815:tid 23815] [client 34.19.223.238:34204] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||academicaic.com.ltscatering.com|F|2"] [data ".com.ltscatering.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "academicaic.com.ltscatering.com"] [uri "/z9x8c7v6b5-debug-trigger-academicaic.com.ltscatering.com"] [unique_id "asOdhXEaX54gUbi70kJCXgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 12:06:31
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 34.19.223.238 (238.223.19.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.19.223.238 (238.223.19.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 08:06:26.617080 2026] [security2:error] [pid 13464:tid 13464] [client 34.19.223.238:39856] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||abs.grabnerconsulting.com|F|2"] [data ".grabnerconsulting.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "abs.grabnerconsulting.com"] [uri "/z9x8c7v6b5-debug-trigger-abs.grabnerconsulting.com"] [unique_id "asOSwloCxUirHfqZKpEz_gAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
webanyone
2026-10-05 11:07:15
(4 days ago)
Crawler ignoring refusals | ua: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perpl ...
show more
Crawler ignoring refusals | ua: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot) | path: /z9x8c7v6b5-debug-trigger-abcis.automaktion.com
show less
Bad Web Bot
๐บ๐ธ
WizardsToolkit
2026-10-05 09:04:58
(4 days ago)
tried to access forbidden files; attempted to access /static//app/.env
Web App Attack
๐ณ๐ฑ
Savvii
2026-10-05 08:55:06
(4 days ago)
20 attempts against mh-misbehave-ban on frost
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-10-05 08:00:44
(4 days ago)
20 attempts against mh-misbehave-ban on ethyl
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 07:58:20
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 34.19.223.238 (238.223.19.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.19.223.238 (238.223.19.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 03:58:14.267827 2026] [security2:error] [pid 3897204:tid 3897263] [client 34.19.223.238:59764] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||richardleeweatherman.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "richardleeweatherman.com"] [uri "/z9x8c7v6b5-debug-trigger-richardleeweatherman.com"] [unique_id "asNYltHbT6d53RTGC4W1AAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Baking333
2026-10-05 07:38:05
(4 days ago)
[redacted] 34.19.223.238 - - [05/Oct/2026:08:38:01 +0100] "GET /.dockerenv HTTP/2.0" 301 52 "-" "Moz ...
show more
[redacted] 34.19.223.238 - - [05/Oct/2026:08:38:01 +0100] "GET /.dockerenv HTTP/2.0" 301 52 "-" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://[redacted]/search/[redacted])" [redacted] 34.19.223.238 - - [05/Oct/2026:08:38:02 +0100] "GET /api/fs/read?allowOutsideWorkspace=true&path=/app/.env HTTP/2.0" 301 83 "-" "CCBot/2.0 (https://[redacted]/faq/)"
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
RLDD
2026-10-05 07:36:02
(4 days ago)
WP probing for vulnerabilities -nov
Web App Attack
Anonymous
2026-10-05 06:17:19
(5 days ago)
2026/10/05 06:17:18 [error] 3693534#3693534: *32462 [client 34.19.223.238] ModSecurity: Access denie ...
show more
2026/10/05 06:17:18 [error] 3693534#3693534: *32462 [client 34.19.223.238] ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Ge' with parameter `5' against variable `TX:BLOCKING_INBOUND_ANOMALY_SCORE' (Value: `40' ) [file "/usr/local/owasp-modsecurity-crs-4.11.0/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "222"] [id "949110"] [rev ""] [msg "Inbound Anomaly Score Exceeded (Total Score: 40)"] [data ""] [severity "0"] [ver "OWASP_CRS/4.30.0"] [maturity "0"] [accuracy "0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "ingeltechgh.com"] [uri "/"] [unique_id "179118103844.992945"] [ref ""], client: 34.19.223.238, server: ingeltechgh.com, request: "POST / HTTP/2.0", host: "ingeltechgh.com"
2026/10/05 06:17:18 [error] 3693534#3693534: *32462 [client 34.19.223.238] ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Ge' with parameter `5' against variable `TX:BLOCKING_INBOUND_ANOMALY_SCORE' (Value: `40' ) [file "/usr/local/owasp-modsecurity-crs
...
show less
Brute-Force
๐ฌ๐ง
consul.to
2026-10-05 06:07:18
(5 days ago)
Web attack/malicious scanning detected
Web App Attack
๐ณ๐ฑ
Savvii
2026-10-05 05:38:26
(5 days ago)
20 attempts against mh-misbehave-ban on mars
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-10-05 05:25:43
(5 days ago)
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .back/ .b ...
show more
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .back/ .backup/ .bak/ .bck/ .bk/ .bkp/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .cnf/ .com/ .compositefont/ .config/ .conf/ .copy/ .crt/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dist/ .dll/ .dos/ .dpkg-dist/ .drv/ .gadget/ .hta/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .inf/ .ini/ .jks/ .jse/ .key/ .licx/ .lnk/ .log/ .mdb/ .msc/ .ocx/ .old/ .pass/ .pdb/ .pfx/ .pif/ .pem/ .pol/ .prf/ .printer/ .pwd/ .rdb/ .rdp/ .reg/ .resources/ .resx/ .sav/ .save/ .scr/ .sct/ .sh/ .shs/ .sql/ .sqlite/ .sqlite3/ .swap/ .swo/ .swp/ .sys/ .temp/ .tfstate/ .tlb/ .tmp/ .vb/ .vbe/ .vbs/ .vbproj/ .vsdisco/ .vxd/ .webinfo/ .ws/ .wsc/ .wsf/ .wsh/ .xsd/ .xsx/" at TX:extension. (920440-193)
show less
Hacking