๐จ๐ฆ
SSH-Admin
2026-10-10 22:34:02
(10 minutes ago)
Probing for Exploits on ns124
Exploited Host
Web App Attack
๐บ๐ธ
dtorrer
2026-10-10 22:26:48
(18 minutes ago)
General vulnerability scan.
Port Scan
Anonymous
2026-10-10 22:09:14
(35 minutes ago)
๐คก Fake Googlebot crawler detected. The IP used the Googlebot user-agent but does not belong to Googl ...
show more
๐คก Fake Googlebot crawler detected. The IP used the Googlebot user-agent but does not belong to Google's verified crawler IP ranges.
show less
Bad Web Bot
๐ฉ๐ช
dbmwebdesign
2026-10-10 21:50:11
(54 minutes ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-10-10 21:46:16
(58 minutes ago)
csagent: score 22.4: 404 noise floor x10, secrets grab x2; 2 domain(s) in 7s
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-10 21:33:52
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 34.19.239.205 (205.239.19.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.19.239.205 (205.239.19.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 17:33:46.784084 2026] [security2:error] [pid 30132:tid 30132] [client 34.19.239.205:33744] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||dayspapass.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "dayspapass.com"] [uri "/z9x8c7v6b5-debug-trigger-dayspapass.com"] [unique_id "asqvOiyR_b2HuyJbHsV6tQAAAD0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐น
penguin-solutions.at
2026-10-10 21:25:28
(1 hour ago)
Excessive 403/404 errors
...
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-10 21:05:45
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 34.19.239.205 (205.239.19.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.19.239.205 (205.239.19.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 17:05:40.784393 2026] [security2:error] [pid 14746:tid 14746] [client 34.19.239.205:38552] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||davidlbennett.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "davidlbennett.com"] [uri "/z9x8c7v6b5-debug-trigger-davidlbennett.com"] [unique_id "asqopCcVbGCZvG-N6vSNxgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฏ๐ต
Valhalla
2026-10-10 21:03:08
(1 hour ago)
/z9x8c7v6b5-debug-trigger-davidgreenmusician.com
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-10 20:46:55
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 34.19.239.205 (205.239.19.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.19.239.205 (205.239.19.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 16:46:51.711858 2026] [security2:error] [pid 14020:tid 14020] [client 34.19.239.205:58628] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||davedoeswater.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "davedoeswater.com"] [uri "/z9x8c7v6b5-debug-trigger-davedoeswater.com"] [unique_id "asqkO-frojLWi4wFMv3OLwAAAEU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-10-10 20:20:11
(2 hours ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ฉ๐ช
yitzhaq
2026-10-10 20:15:44
(2 hours ago)
34.19.239.205 - - [10/Oct/2026:22:15:40 +0200] "GET /.env.production::$DATA?raw HTTP/2.0" 404 28063 ...
show more
34.19.239.205 - - [10/Oct/2026:22:15:40 +0200] "GET /.env.production::$DATA?raw HTTP/2.0" 404 28063 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
34.19.239.205 - - [10/Oct/2026:22:15:40 +0200] "GET /%2Fapi/config HTTP/2.0" 404 293 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)"
34.19.239.205 - - [10/Oct/2026:22:15:40 +0200] "GET /@fs/root/.env?raw?? HTTP/2.0" 404 28072 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot"
34.19.239.205 - - [10/Oct/2026:22:15:40 +0200] "GET /@fs/proc/self/environ?import&raw?? HTTP/2.0" 404 28072 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)"
34.19.239.205 - - [10/Oct/2026:22:15:40 +0200] "GET /.env.local::$DATA?raw HTTP/2.0" 404 28063 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)"
34.19.239.205 - - [10/Oct/2026:22:15:41 +0200] "GET /pages/index.astro.mjs.map HTTP/2.0" 403 319 "-" "Mozilla/5.0 AppleWebKit/537.36
show less
Bad Web Bot
๐ฌ๐ง
consul.to
2026-10-10 20:09:59
(2 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-10 20:05:36
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.19.239.205 (205.239.19.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.19.239.205 (205.239.19.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 16:05:29.320179 2026] [security2:error] [pid 31890:tid 31890] [client 34.19.239.205:55094] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cruisingforsex.com"] [uri "/dist/.env"] [unique_id "asqaicz2zHEyGqc96OMY6AAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-10 20:00:05
(2 hours ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection