Anonymous
2026-10-09 06:23:15
(2 hours ago)
Web application attack.
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-09 05:53:39
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.39.240.195 (195.240.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.39.240.195 (195.240.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 01:53:32.406270 2026] [security2:error] [pid 18300:tid 18300] [client 34.39.240.195:39302] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||anhourofshortstories.johnpritchett.com|F|2"] [data ".johnpritchett.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "anhourofshortstories.johnpritchett.com"] [uri "/z9x8c7v6b5-debug-trigger-anhourofshortstories.johnpritchett.com"] [unique_id "asiBXOxGNND1xY_NRxx1gQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
openstrike.co.uk
2026-10-09 05:15:19
(3 hours ago)
7 attacks on password/key grabbing URLs:
GET /__vite_rsc_findSourceMapURL?filename=file:///root/.ssh ...
show more
7 attacks on password/key grabbing URLs:
GET /__vite_rsc_findSourceMapURL?filename=file:///root/.ssh/id_rsa&environmentName=rsc HTTP/1.1
show less
Hacking
๐ง๐ช
taivas.nl
2026-10-09 04:32:27
(4 hours ago)
Many_bad_calls
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 04:29:32
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.39.240.195 (195.240.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.39.240.195 (195.240.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 00:29:25.790653 2026] [security2:error] [pid 21236:tid 21236] [client 34.39.240.195:51954] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||androglicksman.truefauxstudio.com|F|2"] [data ".truefauxstudio.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "androglicksman.truefauxstudio.com"] [uri "/z9x8c7v6b5-debug-trigger-androglicksman.truefauxstudio.com"] [unique_id "ashtpaa-in-OfKSeDKmkigAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-09 03:56:45
(4 hours ago)
34.39.240.195 - - [09/Oct/2026:03:56:43 +0000] "POST / HTTP/1.1" 405 166 "-" "Mozilla/5.0 (compatibl ...
show more
34.39.240.195 - - [09/Oct/2026:03:56:43 +0000] "POST / HTTP/1.1" 405 166 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)"
34.39.240.195 - - [09/Oct/2026:03:56:43 +0000] "GET /static/manifest.json HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36 EdgA/152.0.0.0"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 03:10:23
(5 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.39.240.195 (195.240.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.39.240.195 (195.240.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 23:10:20.486884 2026] [security2:error] [pid 7594:tid 7594] [client 34.39.240.195:54798] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||anchorroots.com.daisydoesoap.com|F|2"] [data ".com.daisydoesoap.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "anchorroots.com.daisydoesoap.com"] [uri "/z9x8c7v6b5-debug-trigger-anchorroots.com.daisydoesoap.com"] [unique_id "ashbHIykZKsbp2rS7PwVHQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
debestelapp
2026-10-09 02:55:09
(5 hours ago)
Web App Attack
๐ฉ๐ช
thesimonmanuel
2026-10-09 02:24:27
(6 hours ago)
34.39.240.195 - - [09/Oct/2026:07:54:26 +0530] "GET /static//.env HTTP/2.0" 403 106 "-" "Mozilla/5.0 ...
show more
34.39.240.195 - - [09/Oct/2026:07:54:26 +0530] "GET /static//.env HTTP/2.0" 403 106 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36" "-"
show less
Web App Attack
๐ง๐ช
Saec
2026-10-09 02:22:47
(6 hours ago)
Honeypot caught: /.env via analytics.saec.me. UA: Mozilla/5.0 (compatible; Google-Extended; +http:// ...
show more
Honeypot caught: /.env via analytics.saec.me. UA: Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html).
show less
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
IoT Targeted
๐บ๐ธ
Charlesiv
2026-10-09 02:13:38
(6 hours ago)
Triggered Cloudflare WAF (firewallCustom) from BR.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Prot ...
show more
Triggered Cloudflare WAF (firewallCustom) from BR.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/2 (POST method)
Endpoint: /exec-py
Timestamp: 2026-10-09T01:42:11Z
Ray ID: a479aff0eba9bc64
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36; compatible; OAI-SearchBot/1.4; +https://openai.com/searchbot
show less
Bad Web Bot
Anonymous
2026-10-09 01:59:30
(6 hours ago)
Aggressive web scan
Web App Attack
๐ฌ๐ง
andypiper
2026-10-09 01:00:21
(7 hours ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
๐ฉ๐ช
SCHAPPY
2026-10-09 00:34:34
(8 hours ago)
Malicious activity from IP detected: crowdsecurity/http-path-traversal-probing.
Web App Attack
Hacking
๐ฌ๐ง
andypiper
2026-10-09 00:16:48
(8 hours ago)
CrowdSec ban for crowdsecurity/http-probing
Brute-Force
Web App Attack