π©πͺ
altenglaner
2026-09-30 04:44:46
(2 days ago)
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show more
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-30 02:25:51
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.39.137.249 (249.137.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.39.137.249 (249.137.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 22:25:48.214369 2026] [security2:error] [pid 13993:tid 13993] [client 34.39.137.249:51348] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||gwdailey.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "gwdailey.com"] [uri "/z9x8c7v6b5-debug-trigger-gwdailey.com"] [unique_id "arxzLIET-aqZbVuWum3wzwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Alt255
2026-09-30 02:15:39
(2 days ago)
[mx03al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Examp ...
show more
[mx03al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.39.137.249 - - [30/Sep/2026:04:15:22 +0200] "GET /.env.js HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)"
...
show less
Bad Web Bot
Web App Attack
π³π±
Site.eu
2026-09-29 22:00:47
(2 days ago)
Excessive multi-domain requests
Brute-Force
πΊπΈ
TPI-Abuse
2026-09-29 21:05:40
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.39.137.249 (249.137.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.39.137.249 (249.137.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 17:05:34.208284 2026] [security2:error] [pid 32016:tid 32016] [client 34.39.137.249:58832] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||halvaughan.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "halvaughan.com"] [uri "/z9x8c7v6b5-debug-trigger-halvaughan.com"] [unique_id "arwoHubtzqkF6cynkjXNEAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
regishoussin
2026-09-29 20:52:10
(2 days ago)
Automated web scanning detected by Wazuh (rule 100180): repeated 400/404 errors from mass probing of ...
show more
Automated web scanning detected by Wazuh (rule 100180): repeated 400/404 errors from mass probing of admin/backdoor paths (e.g. wp-login.php, known CMS shell filenames) on an Apache web server, on 2026-09-29 20:52 UTC.
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-29 20:49:19
(2 days ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
πΊπΈ
TPI-Abuse
2026-09-29 20:39:35
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.39.137.249 (249.137.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.39.137.249 (249.137.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 16:39:29.161723 2026] [security2:error] [pid 13211:tid 13211] [client 34.39.137.249:47190] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||gsrsv.org|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "gsrsv.org"] [uri "/rclone.conf"] [unique_id "arwiAU-GHnVLFCyJCbb3LwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
Bedios GmbH
2026-09-29 20:16:58
(2 days ago)
Keyfile theft attempt
Hacking
πͺπΈ
pipeline.es
2026-09-29 20:12:02
(2 days ago)
Web scanning / probing for vulnerable paths | URL: /openapi.json | Evidence: microsites.grupoeuropa. ...
show more
Web scanning / probing for vulnerable paths | URL: /openapi.json | Evidence: microsites.grupoeuropa.com 34.39.137.249 - - [29/Sep/2026:22:08:40 +0200] \"GET /openapi.json HTTP/1.1\" 404 - \"-\" \"Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email])\" GEOIP_COUNTRY_CODE=BR | ASN: GOOGLE-CLOUD-PLATFORM | Country: BR
show less
Port Scan
Web App Attack
Anonymous
2026-09-29 19:44:28
(2 days ago)
IP matched detection query more than 2 hosts and only bad rq long ban.
Brute-Force
Web App Attack
Hacking
πΊπΈ
TPI-Abuse
2026-09-29 19:30:02
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.39.137.249 (249.137.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.39.137.249 (249.137.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 15:29:56.365787 2026] [security2:error] [pid 26239:tid 26239] [client 34.39.137.249:56104] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||grupoporvenir.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "grupoporvenir.com"] [uri "/z9x8c7v6b5-debug-trigger-grupoporvenir.com"] [unique_id "arwRtFIgbq-ArfH-WqAaaAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-29 19:17:04
(2 days ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
Anonymous
2026-09-29 18:05:08
(3 days ago)
WAF repeated trigger detected by Fail2Ban
Web App Attack
π«π·
dynamix
2026-09-29 17:10:43
(3 days ago)
Multiple WAF Violations
Web App Attack