๐บ๐ธ
kosada.com
2026-09-17 10:38:25
(4 hours ago)
Repeated requests for suspicious nonexistent URLs, for example: /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2 ...
show more
Repeated requests for suspicious nonexistent URLs, for example: /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fproc/self/environ (HTTP/2.0 port 443, user agent: "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; OAI-SearchBot/1.0; +https://openai.com/searchbot)")
show less
Web App Attack
๐ฎ๐ฉ
Burayot
2026-09-17 09:46:43
(4 hours ago)
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 34.21.200.201 (SG/Singapore/201.200. ...
show more
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 34.21.200.201 (SG/Singapore/201.200.21.34.bc.googleusercontent.com): 2 in the last 3600 secs
show less
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-09-17 09:17:25
(5 hours ago)
excessive HTTP 404 errors
Bad Web Bot
๐ฉ๐ช
XICTRON
2026-09-17 07:55:06
(6 hours ago)
ModSecurity rule violation detected by Fail2Ban
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-09-17 06:58:51
(7 hours ago)
[Thu Sep 17 16:58:49.549157 2026] [security2:error] [pid 488123] [client 34.21.200.201:49536] [clien ...
show more
[Thu Sep 17 16:58:49.549157 2026] [security2:error] [pid 488123] [client 34.21.200.201:49536] [client 34.21.200.201] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "winesbydesign.com.au"] [uri "/rclone.conf"] [unique_id "aquPqZXo0R1f6vfH9OSrnQAAAAg"]
...
show less
Web App Attack
๐ฉ๐ช
Vegascosmetics
2026-09-17 06:48:11
(7 hours ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure probe. Evidence: AttackPattern: /\.env (Match: /.env)
show less
Hacking
Brute-Force
Web App Attack
Anonymous
2026-09-17 06:33:47
(8 hours ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
๐ฎ๐ณ
evicky2002
2026-09-17 06:00:05
(8 hours ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ฉ๐ช
niedson
2026-09-17 04:30:02
(10 hours ago)
Automated scanning for exposed secrets: repeated requests for multiple distinct credential paths (.e ...
show more
Automated scanning for exposed secrets: repeated requests for multiple distinct credential paths (.env variants, .git metadata, .ssh private keys, .aws/credentials). Unsolicited. Reported automatically.
show less
Web App Attack
๐ณ๐ฑ
BlueWire Hosting
2026-09-17 04:15:35
(10 hours ago)
Bad bot ignoring robot.txt
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-17 04:03:20
(10 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.21.200.201 (201.200.21.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.21.200.201 (201.200.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 00:03:14.689898 2026] [security2:error] [pid 7666:tid 7666] [client 34.21.200.201:53310] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||sigridsnaturalfoods.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "sigridsnaturalfoods.com"] [uri "/z9x8c7v6b5-debug-trigger-sigridsnaturalfoods.com"] [unique_id "aqtmgkMt1C1sKh7ym_NDuAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FD-IX
2026-09-17 03:49:27
(10 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐ง๐พ
lns.bz
2026-09-17 03:34:24
(11 hours ago)
Too many 404 requests [BY]
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-17 03:31:46
(11 hours ago)
[cb-14al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[cb-14al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.21.200.201 - - [17/Sep/2026:05:31:45 +0200] "GET /__vite_rsc_findSourceMapURL?filename=file:///root/.ssh/id_rsa&environmentName=rsc HTTP/1.0" 404 3579 "-" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)"
...
show less
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-17 03:03:32
(11 hours ago)
Multiple WAF Violations
Web App Attack