🇮🇩
bebekpintar
2026-09-07 08:42:47
(1 hour ago)
BebekPintar-Bappenas CSIRT automated WAF report. IP is now forced through a challenge at our perimet ...
show more
BebekPintar-Bappenas CSIRT automated WAF report. IP is now forced through a challenge at our perimeter. Attack type: Persistent blocked attempts (severity MEDIUM) Trigger: 25+ non-200 (blocked) requests to our WAF in one day; status breakdown {'403': 25} Decision basis: sustained probing volume despite repeated blocks Outcome: attempt blocked (HTTP 403) Volume: 25 malicious requests logged from this IP Source: Bappenas CSIRT SOC auto-defense gateway.
show less
Fraud Orders
🇫🇷
mouafiq
2026-09-07 05:50:47
(4 hours ago)
2026-09-07 05:50:46,616 15395 INFO ? werkzeug: 34.48.172.147 - - [07/Sep/2026 05:50:46] "GET /__aws_ ...
show more
2026-09-07 05:50:46,616 15395 INFO ? werkzeug: 34.48.172.147 - - [07/Sep/2026 05:50:46] "GET /__aws_leak_probe_5e241513__ HTTP/1.0" 404 - 1 0.002 0.005
2026-09-07 05:50:46,830 15486 INFO ? werkzeug: 34.48.172.147 - - [07/Sep/2026 05:50:46] "GET /static../.env HTTP/1.0" 404 - 1 0.002 0.007
2026-09-07 05:50:47,077 15486 INFO ? werkzeug: 34.48.172.147 - - [07/Sep/2026 05:50:47] "GET /media../.env HTTP/1.0" 404 - 1 0.003 0.007
2026-09-07 05:50:47,139 15395 INFO ? werkzeug: 34.48.172.147 - - [07/Sep/2026 05:50:47] "GET /@fs/proc/self/environ HTTP/1.0" 404 - 1 0.002 0.005
2026-09-07 05:50:47,161 15486 INFO ? werkzeug: 34.48.172.147 - - [07/Sep/2026 05:50:47] "GET /@fs/proc/self/environ?raw?? HTTP/1.0" 404 - 1 0.002 0.016
show less
Brute-Force
SSH
Anonymous
2026-09-06 22:29:08
(11 hours ago)
Fail2Ban: repeated malicious HTTP requests (path probing / exploit attempts) against a public web se ...
show more
Fail2Ban: repeated malicious HTTP requests (path probing / exploit attempts) against a public web server.
show less
Web App Attack
Bad Web Bot
🇧🇪
sid3windr
2026-09-06 06:16:56
(1 day ago)
GET /_ignition/health-check (Tarpitted for 4m18s, wasted 15.23kB)
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 04:42:54
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.48.172.147 (147.172.48.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.48.172.147 (147.172.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 00:42:47.040028 2026] [security2:error] [pid 2649:tid 2649] [client 34.48.172.147:36666] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||campconcerto.com.accordionclub.org|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "campconcerto.com.accordionclub.org"] [uri "/mysql.sql"] [unique_id "apzvR2-7mIPWOKS2kWIdvQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:51:14
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.48.172.147 (147.172.48.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.48.172.147 (147.172.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:51:09.560121 2026] [security2:error] [pid 23495:tid 23495] [client 34.48.172.147:54360] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.batonrougecustomcabinets.com"] [uri "/.env.bak"] [unique_id "apzjLWEeWgW1yW-LAF-toAAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇷🇴
clauss
2026-09-06 03:38:18
(1 day ago)
34.48.172.147 - - [06/Sep/2026:06:38:17 +0300] "GET /wp-config.php~ HTTP/1.1" 403 10358 "-" "crusade ...
show more
34.48.172.147 - - [06/Sep/2026:06:38:17 +0300] "GET /wp-config.php~ HTTP/1.1" 403 10358 "-" "crusader-worker/1.0"
34.48.172.147 - - [06/Sep/2026:06:38:17 +0300] "GET /wp-config.php.swp HTTP/1.1" 403 10364 "-" "crusader-worker/1.0"
...
show less
Web App Attack
🇩🇪
FD-IX
2026-09-06 03:23:49
(1 day ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇫🇷
Delta-shop
2026-09-06 03:17:12
(1 day ago)
PrestaShop Security Module: Suspicious path detected (/.env)
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:59:25
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.48.172.147 (147.172.48.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.48.172.147 (147.172.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:59:17.917675 2026] [security2:error] [pid 2482:tid 2482] [client 34.48.172.147:46676] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.ttlatl.com"] [uri "/.env.old"] [unique_id "apzXBVh2scUnoRlmcg3KDAAAADY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-06 02:55:18
(1 day ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-196)
Hacking
Web App Attack
🇫🇷
✨
2026-09-06 02:02:19
(1 day ago)
Domain : mannall.com
Rule : hack
2026-09-06 02:00:51 ***hidden-privacy*** GET /wp-config.php.bak - 4 ...
show more
Domain : mannall.com
Rule : hack
2026-09-06 02:00:51 ***hidden-privacy*** GET /wp-config.php.bak - 443 - 34.48.172.147 HTTP/1.1 crusader-worker/1.0 - mannall.com 404 0 0 371 100 732 - -
show less
Hacking
SQL Injection
Brute-Force
🇫🇷
masterguru
2026-09-06 01:12:28
(1 day ago)
Attempt to access a backup or working file. Pattern match "\\\\. (920500-197)
Hacking
🇺🇸
TPI-Abuse
2026-09-06 01:09:51
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.48.172.147 (147.172.48.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.48.172.147 (147.172.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:09:48.209493 2026] [security2:error] [pid 2071:tid 2071] [client 34.48.172.147:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.empoweruamerica.org"] [uri "/.env.dev"] [unique_id "apy9XGmN4oySLwWQJX51mQAAACs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 00:35:45
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.48.172.147 (147.172.48.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.48.172.147 (147.172.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:35:37.848696 2026] [security2:error] [pid 24425:tid 24425] [client 34.48.172.147:41072] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "houstontenemosunproblema.com"] [uri "/.env.old"] [unique_id "apy1WSYG2sXOdWs3FpdMjwAAAGE"]
show less
Brute-Force
Bad Web Bot
Web App Attack