🇫🇷
SpaceHost-Server
2026-09-11 22:20:13
(3 hours ago)
Brute-Force
Web App Attack
🇮🇳
evicky2002
2026-09-11 06:00:00
(19 hours ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
🇩🇪
Séfora Srl
2026-09-11 05:37:46
(20 hours ago)
crowdsecurity/http-bad-user-agent detected by CrowdSec
Bad Web Bot
Anonymous
2026-09-11 05:23:10
(20 hours ago)
Banned by Fail2Ban on server
Web App Attack
Anonymous
2026-09-11 05:12:11
(20 hours ago)
[ns3.backorder.gr] httpd-config-scan: sites=www.gosolar.gr; logs=/var/log/httpd/domains/gosolar.gr.l ...
show more
[ns3.backorder.gr] httpd-config-scan: sites=www.gosolar.gr; logs=/var/log/httpd/domains/gosolar.gr.log; samples=/@fs/app/.env?raw?? | /@fs/..%252f..%252f..%252f..%252f..%252froot/.env?raw?? | /@fs/../.env?raw??
show less
Hacking
Web App Attack
🇩🇪
bazter.pro
2026-09-11 04:50:50
(20 hours ago)
Fail2Ban: plesk-bot-aggressive - 15 failures
Port Scan
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 04:20:13
(21 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.47.27.78 (78.27.47.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.47.27.78 (78.27.47.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 00:20:09.657858 2026] [security2:error] [pid 23931:tid 23931] [client 34.47.27.78:38444] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||forgottenvictims.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "forgottenvictims.com"] [uri "/z9x8c7v6b5-debug-trigger-forgottenvictims.com"] [unique_id "aqOBeTfz6rM4gFaS5m2S-AAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
svr
2026-09-11 04:17:45
(21 hours ago)
Abusive Automated Web Scanner
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 04:01:20
(21 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.47.27.78 (78.27.47.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.47.27.78 (78.27.47.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 00:01:15.334400 2026] [security2:error] [pid 20893:tid 20893] [client 34.47.27.78:39376] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||fiestadj.com.mx|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "fiestadj.com.mx"] [uri "/ssl/localhost.key"] [unique_id "aqN9C7eQqQ9988tExdP7BgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FeG Deutschland
2026-09-11 03:56:06
(21 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
🇩🇪
macrob
2026-09-11 03:52:21
(21 hours ago)
2026/09/11 03:52:19 [error] 100826#100826: *1134827 access forbidden by rule, client: 34.47.27.78, s ...
show more
2026/09/11 03:52:19 [error] 100826#100826: *1134827 access forbidden by rule, client: 34.47.27.78, server: fastcredit.net.ua, request: "GET /.aws/credentials HTTP/2.0", host: "fastcredit.net.ua"
2026/09/11 03:52:19 [error] 100822#100822: *1130630 access forbidden by rule, client: 34.47.27.78, server: fastcredit.net.ua, request: "GET /.aws/config HTTP/2.0", host: "fastcredit.net.ua"
2026/09/11 03:52:19 [error] 100824#100824: *1133366 access forbidden by rule, client: 34.47.27.78, server: fastcredit.net.ua, request: "GET /.git/config HTTP/2.0", host: "fastcredit.net.ua"
...
show less
Web App Attack
Anonymous
2026-09-11 03:47:56
(21 hours ago)
☣️ WAF rule violation. Dangerous payload detected in the request.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 02:38:49
(23 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.47.27.78 (78.27.47.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.47.27.78 (78.27.47.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 22:38:45.264901 2026] [security2:error] [pid 5682:tid 5682] [client 34.47.27.78:57062] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||drgas.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "drgas.com"] [uri "/z9x8c7v6b5-debug-trigger-drgas.com"] [unique_id "aqNptaoekklW-SxFWJ3xggAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
conseilgouz
2026-09-11 02:30:14
(23 hours ago)
doe-17 : Block hidden directories=>/.astro/manifest.json(/)
Hacking
🇳🇱
EGP Abuse Dept
2026-09-11 02:07:44
(23 hours ago)
Scanning for web/db/file exploits on dewisri.nl
SQL Injection
Bad Web Bot
Web App Attack