🇳🇱
Savvii
2026-09-07 02:56:35
(5 days ago)
20 attempts against mh-misbehave-ban on ceres
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 01:45:09
(5 days ago)
(mod_security) mod_security (id:210580) triggered by 34.44.22.33 (33.22.44.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210580) triggered by 34.44.22.33 (33.22.44.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 21:45:06.078532 2026] [security2:error] [pid 25235:tid 25235] [client 34.44.22.33:58144] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at ARGS:path. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||socialstudiesforkids.com|F|2"] [data "Matched Data: proc/self/environ found within ARGS:path: /proc/self/environ"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "socialstudiesforkids.com"] [uri "/api/fs/read"] [unique_id "ap4XIpQ6MgJMT_5eUZ78YwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
rubixstudios
2026-09-07 00:39:03
(6 days ago)
Excessive HTTP requests consistent with automated attack behaviour detected by Imunify360
DDoS Attack
Brute-Force
Web App Attack
🇪🇸
masterguru
2026-09-07 00:09:17
(6 days ago)
BAD BOT - Detected and Blocked.. Matched phrase "PerplexityBot" at REQUEST_HEADERS:user-agent. (1100 ...
show more
BAD BOT - Detected and Blocked.. Matched phrase "PerplexityBot" at REQUEST_HEADERS:user-agent. (1100000-122)
show less
Bad Web Bot
Anonymous
2026-09-06 21:54:26
(6 days ago)
Multiple web server 400 error codes from same source ip
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 21:05:44
(6 days ago)
(mod_security) mod_security (id:210730) triggered by 34.44.22.33 (33.22.44.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.44.22.33 (33.22.44.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 17:05:37.969973 2026] [security2:error] [pid 15108:tid 15108] [client 34.44.22.33:59028] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||scifitimeline.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "scifitimeline.com"] [uri "/z9x8c7v6b5-debug-trigger-scifitimeline.com"] [unique_id "ap3VofAr3d4TaahzzYBN7wAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-06 20:16:51
(6 days ago)
Excessive multi-domain requests
Brute-Force
🇫🇮
Shaik Sai Meera
2026-09-06 19:00:09
(6 days ago)
IM360 WAF: Hidden file access
Brute-Force
🇺🇸
TPI-Abuse
2026-09-06 18:54:04
(6 days ago)
(mod_security) mod_security (id:210730) triggered by 34.44.22.33 (33.22.44.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.44.22.33 (33.22.44.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 14:53:58.214490 2026] [security2:error] [pid 1298767:tid 1298801] [client 34.44.22.33:52240] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.williampower.com|F|2"] [data ".williampower.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.williampower.com"] [uri "/z9x8c7v6b5-debug-trigger-www.williampower.com"] [unique_id "ap22xtVrpJ3amG0N8_xskgAAAEE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 18:40:05
(6 days ago)
| Suspicious URL access.
Web App Attack
Hacking
SQL Injection
🇺🇸
jormaster3k
2026-09-06 17:59:19
(6 days ago)
Attack against Apache (too many 404s)
Web App Attack
🇫🇮
mnazibo
2026-09-06 17:00:06
(6 days ago)
Date: 06/Sep/2026 19:48:09 | Reported IP: 34.44.22.33 mod_security | id: 930100 930110 930120 930130 ...
show more
Date: 06/Sep/2026 19:48:09 | Reported IP: 34.44.22.33 mod_security | id: 930100 930110 930120 930130 932160 | US/group.my_domain/- | Connections: 205 | Blocked: Permanent Block: [LF_MODSEC] | URIs: /%2eenv; /admin%2F.env; /admin/.env; /api%2F.env; /api/.env.bak; /api/.env/public/.env; /api/fs/read?path=/proc/self/environ&allowOutsideWorkspace=true; /api/w/admins/jobs_u/get_log_file/../../../../proc/self/environ; /api/w/default/jobs_u/get_log_file/../../../../proc/self/environ; /api/w/starter/jobs_u/get_log_file/../../../../proc/self/environ; /app-config.json; /app/.env; /apps/.env; /assets../.env; /auth.json; /.aws/config; /.aws/credentials; /backend/.env; /.bash_profile; /.bashrc; /.boto; /build../.env; /config/database.yml; /config.env; /config/.env; /config/.env.php; /config/gcp-credentials.json; /config.json.js; /config.php.bak; /config.py; /config/secrets.yml; /config.toml; /config.yaml; /core/.env; /credentials.json; /css../.env;
show less
SQL Injection
Brute-Force
Bad Web Bot
🇫🇷
dynamix
2026-09-06 15:57:42
(6 days ago)
Multiple WAF Violations
Web App Attack
🇦🇺
paulshipley.com.au
2026-09-06 15:28:32
(6 days ago)
[Mon Sep 07 01:28:32.422577 2026] [security2:error] [pid 958023] [client 34.44.22.33:54674] [client ...
show more
[Mon Sep 07 01:28:32.422577 2026] [security2:error] [pid 958023] [client 34.44.22.33:54674] [client 34.44.22.33] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "winesbydesign.com.au"] [uri "/@fs/var/task/.env"] [unique_id "ap2GoNgv4Sw2ZUe04sdoPgAAAA0"]
...
show less
Web App Attack
Anonymous
2026-09-06 15:00:37
(6 days ago)
[ns41.kdns.gr] httpd-config-scan: sites=www.sostis.gr; logs=/var/log/httpd/domains/sostis.gr.log; sa ...
show more
[ns41.kdns.gr] httpd-config-scan: sites=www.sostis.gr; logs=/var/log/httpd/domains/sostis.gr.log; samples=/@fs/proc/self/cwd/.env?raw?? | /settings%2F.env | /dashboard%2F.env
show less
Hacking
Web App Attack