๐ฌ๐ง
Steve
2026-08-28 13:47:28
(3 hours ago)
SQL Injection Attempts
Brute-Force
SQL Injection
๐ฉ๐ช
Skyrider
2026-08-28 13:26:15
(3 hours ago)
crowdsecurity/http-sensitive-files
Web App Attack
Anonymous
2026-08-28 12:21:57
(4 hours ago)
Portscan: TCP/8443 (6x), TCP/8080 (4x), TCP/80 (2x), TCP/443 (2x)
Port Scan
๐ง๐ช
voormedia
2026-08-28 11:25:17
(5 hours ago)
Accessed trap at '/.aws/credentials'
Web App Attack
๐ช๐ธ
librebit
2026-08-28 11:24:52
(5 hours ago)
Brute force
Brute-Force
๐ช๐ธ
alferez
2026-08-28 10:03:07
(6 hours ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack
๐บ๐ธ
nationaleventpros.com
2026-08-28 08:20:56
(8 hours ago)
vulnerability scan
Web App Attack
๐ฉ๐ช
Marc
2026-08-28 07:05:07
(9 hours ago)
34.204.176.68 - - [28/Aug/2026:09:05:07 +0200] "GET /ssl/localhost.key HTTP/2.0" 404 314 "-" "meta-e ...
show more
34.204.176.68 - - [28/Aug/2026:09:05:07 +0200] "GET /ssl/localhost.key HTTP/2.0" 404 314 "-" "meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)" 34.204.176.68 - - [28/Aug/2026:09:05:07 +0200] "GET /rclone.conf HTTP/2.0" 404 269 "-" "meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)" 34.204.176.68 - - [28/Aug/2026:09:05:07 +0200] "GET /.openclaw/.env HTTP/2.0" 404 269 "-" "meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)"
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-28 06:59:51
(9 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.204.176.68 (ec2-34-204-176-68.compute-1.amaz ...
show more
(mod_security) mod_security (id:210730) triggered by 34.204.176.68 (ec2-34-204-176-68.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 02:59:46.087450 2026] [security2:error] [pid 22872:tid 22872] [client 34.204.176.68:51210] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||gilgoinn.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "gilgoinn.com"] [uri "/z9x8c7v6b5-debug-trigger-gilgoinn.com"] [unique_id "apEx4lEocMU9BO44v78xuwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
cloudmax
2026-08-28 06:00:12
(10 hours ago)
Cloudmax IPS Block - Suspicious activity. Possible port scanning, service reconnaissance, or vulnera ...
show more
Cloudmax IPS Block - Suspicious activity. Possible port scanning, service reconnaissance, or vulnerability probing
show less
Port Scan
๐ง๐ช
taivas.nl
2026-08-28 04:33:55
(12 hours ago)
Many_bad_calls
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 03:22:14
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.204.176.68 (ec2-34-204-176-68.compute-1.amaz ...
show more
(mod_security) mod_security (id:210492) triggered by 34.204.176.68 (ec2-34-204-176-68.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 23:22:07.453181 2026] [security2:error] [pid 4172667:tid 4172720] [client 34.204.176.68:33562] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nesso.es"] [uri "/api/.env"] [unique_id "apD-31mN77BEr8jVXCAzWQAAAFI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
london2038.com
2026-08-28 02:09:23
(14 hours ago)
Malformed or malicious web request
34.204.176.68 - - [28/Aug/2026:04:09:21 +0200] "POST /graphql HTT ...
show more
Malformed or malicious web request
34.204.176.68 - - [28/Aug/2026:04:09:21 +0200] "POST /graphql HTTP/2.0" 404 12788 "https://forum.<REDACTED>" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/148.0.0.0 Safari/537.36"
show less
Hacking
Web App Attack
๐ง๐ช
taivas.nl
2026-08-28 01:32:10
(15 hours ago)
Bad_requests
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-28 01:00:15
(15 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.204.176.68 (ec2-34-204-176-68.compute-1.amaz ...
show more
(mod_security) mod_security (id:210730) triggered by 34.204.176.68 (ec2-34-204-176-68.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 21:00:08.107578 2026] [security2:error] [pid 29443:tid 29495] [client 34.204.176.68:43746] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||illianapartyrentals.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "illianapartyrentals.com"] [uri "/z9x8c7v6b5-debug-trigger-illianapartyrentals.com"] [unique_id "apDdmPSn8Crn7wouTBhTIAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack