๐ธ๐ฌ
Cloudkul Cloudkul
2026-10-11 02:36:45
(58 minutes ago)
Attempted Brute Force on our application
Brute-Force
Web App Attack
๐ฉ๐ช
thesimonmanuel
2026-10-11 02:03:19
(1 hour ago)
34.39.213.159 - - [11/Oct/2026:07:33:18 +0530] "GET /.aws/config HTTP/2.0" 404 106 "-" "Mozilla/5.0 ...
show more
34.39.213.159 - - [11/Oct/2026:07:33:18 +0530] "GET /.aws/config HTTP/2.0" 404 106 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.4; +https://openai.com/gptbot" "-"
show less
Web App Attack
Anonymous
2026-10-11 01:30:03
(2 hours ago)
CrowdSec decision: crowdsecurity/http-bad-user-agent (origin: crowdsec)
Port Scan
๐ฌ๐ง
andypiper
2026-10-11 01:02:48
(2 hours ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
๐บ๐ธ
IndigoRidge
2026-10-11 00:54:14
(2 hours ago)
34.39.213.159 - - [10/Oct/2026:20:54:12 -0400] "GET /userfiles?path=../../../../.env HTTP/1.1" 404 6 ...
show more
34.39.213.159 - - [10/Oct/2026:20:54:12 -0400] "GET /userfiles?path=../../../../.env HTTP/1.1" 404 61738 "https://westernupstatemls.com/userfiles?path=../../../../.env" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)"
34.39.213.159 - - [10/Oct/2026:20:54:13 -0400] "GET /userfiles/x?path=../../.env HTTP/1.1" 404 61738 "https://westernupstatemls.com/userfiles/x?path=../../.env" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexity-user)"
34.39.213.159 - - [10/Oct/2026:20:54:12 -0400] "GET /cache/original/%2e%2e/.env HTTP/1.1" 404 61738 "https://westernupstatemls.com/cache/original/%2e%2e/.env" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)"
...
show less
Web App Attack
๐บ๐ธ
masterguru
2026-10-11 00:50:23
(2 hours ago)
COMODO WAF: URL file extension is restricted by policy. Match of "pmFromFile userdata_wl_extensions" ...
show more
COMODO WAF: URL file extension is restricted by policy. Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. (210730-169)
show less
Hacking
๐ฉ๐ช
thesimonmanuel
2026-10-11 00:21:28
(3 hours ago)
34.39.213.159 - - [11/Oct/2026:05:51:28 +0530] "GET /@fs/home/ec2-user/.aws/credentials?raw?? HTTP/2 ...
show more
34.39.213.159 - - [11/Oct/2026:05:51:28 +0530] "GET /@fs/home/ec2-user/.aws/credentials?raw?? HTTP/2.0" 404 8193 "-" "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
show less
Web App Attack
๐บ๐ธ
Mundo Bueno
2026-10-11 00:18:31
(3 hours ago)
[ISILIA Protection v2.3] Tentative d'accรจs: /.env [RATE LIMITED - 1800s quarantine] | Pays: BR | UA: ...
show more
[ISILIA Protection v2.3] Tentative d'accรจs: /.env [RATE LIMITED - 1800s quarantine] | Pays: BR | UA: Mozilla/5.0 (compatible; Meta-WebIndexer/1.0; +https://developers.facebook.com/docs/sharing/webmaste
show less
Hacking
Web App Attack
๐จ๐ฆ
lakered
2026-10-11 00:11:18
(3 hours ago)
Detectors: [SURICATA, NGINX] | Reasons: Automated scan targeting an unauthorized host or default ser ...
show more
Detectors: [SURICATA, NGINX] | Reasons: Automated scan targeting an unauthorized host or default server sinkhole | Suricata: Web Server attack | Evidence: High-Criminality-Signature (p0f:*:64:0:*:mss*46,10:mss,sok,ts,nop,ws:df,id+:0 - Ratio:0.80) | TCP Fingerprint: Modern Linux (Kernel 3.x+) (Link:generic tunnel or VPN, Uptime:0m)
show less
Web App Attack
Hacking
Port Scan
Bad Web Bot
๐ณ๐ฑ
Alt255
2026-10-10 23:59:00
(3 hours ago)
[ti-22al] Web exploit scanning: 3 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-22al] Web exploit scanning: 3 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.39.213.159 - - [11/Oct/2026:01:58:49 +0200] "GET /@fs/app/.env?raw?? HTTP/2.0" 403 346 "-" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-10 23:53:38
(3 hours ago)
(mod_security) mod_security (id:210580) triggered by 34.39.213.159 (159.213.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210580) triggered by 34.39.213.159 (159.213.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 19:53:32.902665 2026] [security2:error] [pid 27114:tid 27114] [client 34.39.213.159:0] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at ARGS:path. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||nyemdr.com|F|2"] [data "Matched Data: proc/self/environ found within ARGS:path: ../../../../proc/self/environ"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "nyemdr.com"] [uri "/userfiles/x"] [unique_id "asrP_PemexIYy_Dv9DJmTgAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-10 23:25:07
(4 hours ago)
IP banned by Fail2Ban in jail nginx-abusive-ips
Web App Attack
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-10 23:18:39
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.39.213.159 (159.213.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.39.213.159 (159.213.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 19:18:33.072093 2026] [security2:error] [pid 24660:tid 24660] [client 34.39.213.159:50474] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||metcomarine.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "metcomarine.com"] [uri "/z9x8c7v6b5-debug-trigger-metcomarine.com"] [unique_id "asrHyW8D-7lCxqgPhBXcYwAAAEA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-10-10 23:12:53
(4 hours ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-10 22:55:31
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.39.213.159 (159.213.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.39.213.159 (159.213.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 18:55:23.362374 2026] [security2:error] [pid 17154:tid 17154] [client 34.39.213.159:47198] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||meshbagsandmore.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "meshbagsandmore.com"] [uri "/z9x8c7v6b5-debug-trigger-meshbagsandmore.com"] [unique_id "asrCW0TbhfBWFReGPMxdgQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack