๐ต๐ฑ
mscode.pl
2026-09-08 06:24:50
(1 week ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Pro ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/1.1 (GET method)
Zone: admin.e-modo.pl
Endpoint: /wp-config.php~
UA: crusader-worker/1.0
show less
Bad Web Bot
๐ฉ๐ช
itsolon
2026-09-08 03:11:55
(1 week ago)
[08/Sep/2026:05:11:55 +0200] 178883711569.049019 34.48.113.182 54632 217.154.7.177 443
[08/Sep/2026: ...
show more
[08/Sep/2026:05:11:55 +0200] 178883711569.049019 34.48.113.182 54632 217.154.7.177 443
[08/Sep/2026:05:11:55 +0200] 178883711525.543191 34.48.113.182 54684 217.154.7.177 443
[08/Sep/2026:05:11:55 +0200] 178883711592.482266 34.48.113.182 54754 217.154.7.177 443
[08/Sep/2026:05:11:55 +0200] 178883711592.026822 34.48.113.182 54698 217.154.7.177 443
[08/Sep/2026:05:11:55 +0200] 178883711562.218495 34.48.113.182 54732 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
Anonymous
2026-09-08 02:53:40
(1 week ago)
(mod_security) mod_security triggered on hostname [redacted] 34.48.113.182 (US/United States/182.113 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.48.113.182 (US/United States/182.113.48.34.bc.googleusercontent.com)
show less
SQL Injection
๐ณ๐ฑ
homeshowdomain.nl
2026-09-07 21:59:02
(1 week ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-06.
show less
Web App Attack
SSH
Hacking
๐ซ๐ท
a.mohamed.go
2026-09-07 13:58:04
(1 week ago)
34.48.113.182 - - [07/Sep/2026:13:58:03 +0000] "GET /claude_desktop_config.json HTTP/1.1" 200 42498 ...
show more
34.48.113.182 - - [07/Sep/2026:13:58:03 +0000] "GET /claude_desktop_config.json HTTP/1.1" 200 42498 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36"
...
show less
Hacking
Web App Attack
๐ง๐ท
SOC Blue Team
2026-09-07 09:25:54
(1 week ago)
IPs get by Hunting on SIEM
Phishing
Web Spam
Port Scan
Hacking
๐น๐ผ
tye
2026-09-07 05:32:11
(1 week ago)
Wazuh Alert Evidence: 34.48.113.182 (34.48.113.182) - - [07/Sep/2026:13:32:02 +0800] "GET /backup.zi ...
show more
Wazuh Alert Evidence: 34.48.113.182 (34.48.113.182) - - [07/Sep/2026:13:32:02 +0800] "GET /backup.zip HTTP/1.1" 404 5205 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36"
show less
Web App Attack
๐ฉ๐ช
Uwe Sarpe
2026-09-06 09:30:47
(2 weeks ago)
[Sun Sep 06 11:30:47.200546 2026] [access_compat:error] [pid 43459:tid 43459] [client 34.48.113.182: ...
show more
[Sun Sep 06 11:30:47.200546 2026] [access_compat:error] [pid 43459:tid 43459] [client 34.48.113.182:39252] AH01797: client denied by server configuration: /var/www/backup.tar.gz
[Sun Sep 06 11:30:47.200577 2026] [access_compat:error] [pid 43462:tid 43462] [client 34.48.113.182:39236] AH01797: client denied by server configuration: /var/www/backup.zip
[Sun Sep 06 11:30:47.205375 2026] [access_compat:error] [pid 43457:tid 43457] [client 34.48.113.182:39260] AH01797: client denied by server configuration: /var/www/backup.tar
[Sun Sep 06 11:30:47.213644 2026] [access_compat:error] [pid 43461:tid 43461] [client 34.48.113.182:39240] AH01797: client denied by server configuration: /var/www/dump.sql
[Sun Sep 06 11:30:47.219427 2026] [access_compat:error] [pid 44215:tid 44215] [client 34.48.113.182:39242] AH01797: client denied by server configuration: /var/www/backup.sql
...
show less
Brute-Force
Web App Attack
๐ฉ๐ช
srtzero
2026-09-06 06:30:45
(2 weeks ago)
34.48.113.182 - - [06/Sep/2026:08:30:44 +0200] "GET /.env.local HTTP/1.1" 404 3271 "-" "crusader-wor ...
show more
34.48.113.182 - - [06/Sep/2026:08:30:44 +0200] "GET /.env.local HTTP/1.1" 404 3271 "-" "crusader-worker/1.0"
34.48.113.182 - - [06/Sep/2026:08:30:44 +0200] "GET /.env.prod HTTP/1.1" 404 3271 "-" "crusader-worker/1.0"
34.48.113.182 - - [06/Sep/2026:08:30:44 +0200] "GET /.env.production HTTP/1.1" 404 3271 "-" "crusader-worker/1.0"
...
show less
Port Scan
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-06 03:06:07
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.48.113.182 (182.113.48.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.48.113.182 (182.113.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:06:00.620370 2026] [security2:error] [pid 16492:tid 16492] [client 34.48.113.182:47308] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.waxjet510.com"] [uri "/.env.save"] [unique_id "apzYmD4pDVzks0hxWUJYMwAAAFQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 03:03:00
(2 weeks ago)
Detected by CrowdSec: crowdsecurity/http-probing
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-09-06 01:44:30
(2 weeks ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-09-06 00:48:41
(2 weeks ago)
[SunSep0602:48:36.2722452026][security2:error][pid2218098:tid2218364][client34.48.113.182:0]ModSecur ...
show more
[SunSep0602:48:36.2722452026][security2:error][pid2218098:tid2218364][client34.48.113.182:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"cpanel.ecosuber.com\"][uri\"/.env.old\"][unique_id\"apy4ZCvMOosR9HRJmObnZAAAAEM\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-06 00:43:09
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 34.48.113.182 (182.113.48.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.48.113.182 (182.113.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:43:01.824747 2026] [security2:error] [pid 8547:tid 8547] [client 34.48.113.182:56296] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||arnebowman.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "arnebowman.com"] [uri "/backup.sql"] [unique_id "apy3FV71OiEfBag4g0HRjAAAAGU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
pm33
2026-09-06 00:22:55
(2 weeks ago)
Wordpress login attempts
Brute-Force