๐ฉ๐ช
BlueWire Hosting
2026-10-05 07:35:15
(8 hours ago)
Bad bot ignoring robot.txt
Bad Web Bot
Anonymous
2026-10-05 07:25:03
(8 hours ago)
Bot / scanning and/or hacking attempts: POST /cgi-bin/php-cgi?-d+allow_url_include%3don+-d+auto_prep ...
show more
Bot / scanning and/or hacking attempts: POST /cgi-bin/php-cgi?-d+allow_url_include%3don+-d+auto_prepend, GET /userfiles/x?path=../../../../proc/self/environ HTTP/2.0, POST /cgi-bin/php-cgi.exe?%ADd+allow_url_include%3d1+%ADd+auto_, GET /firebase-credentials.json HTTP/2.0, POST /index.php?-d+allow_url_include%3don+-d+auto_prepend_file%, POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e, POST /cgi-bin/php?-d+allow_url_include%3don+-d+auto_prepend_fil, GET /api/orders/..%2f..%2fproc/self/environ HTTP/2.0
show less
Hacking
Web App Attack
๐บ๐ธ
mnsf
2026-10-05 07:05:23
(8 hours ago)
Abuse Detected (7)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 06:52:48
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.48.176.210 (210.176.48.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.48.176.210 (210.176.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 02:52:40.616967 2026] [security2:error] [pid 1811:tid 1842] [client 34.48.176.210:33050] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "woadwellness.com"] [uri "/.htpasswd"] [unique_id "asNJOFiahgDrszE2FNw1vwAAAJU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
vtchost.com
2026-10-05 06:30:11
(9 hours ago)
requested HTTP honeypot page - ignored robots.txt - bad crawler
...
Bad Web Bot
Exploited Host
๐ง๐ฌ
HighWay
2026-10-05 04:27:49
(11 hours ago)
34.48.176.210 - - [05/Oct/2026:04:27:43 +0000] "POST /lib/terminal-xhr.php HTTP/1.1" 404 4759 "-" "M ...
show more
34.48.176.210 - - [05/Oct/2026:04:27:43 +0000] "POST /lib/terminal-xhr.php HTTP/1.1" 404 4759 "-" "Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)"
34.48.176.210 - - [05/Oct/2026:04:27:43 +0000] "POST /graphql HTTP/1.1" 404 770 "https://vhelectronics.com" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36"
34.48.176.210 - - [05/Oct/2026:04:27:43 +0000] "GET /48qmyo3tuuky01zjn2o2 HTTP/1.1" 404 4759 "-" "Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)"
34.48.176.210 - - [05/Oct/2026:04:27:44 +0000] "POST /icecoder/lib/terminal-xhr.php HTTP/1.1" 404 770 "-" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)"
34.48.176.210 - - [05/Oct/2026:04:27:44 +0000] "POST /api/graphql HTTP/1.1" 404 770 "https://vhelectronics.com" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36"
34.48.176.210 - - [05/Oct/2026:04:27:44 +00
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-10-05 04:02:59
(11 hours ago)
34.48.176.210 - - [04/Oct/2026:23:02:51 -0500] "GET /.env?raw?? HTTP/1.1" 403 199 "http://synapseres ...
show more
34.48.176.210 - - [04/Oct/2026:23:02:51 -0500] "GET /.env?raw?? HTTP/1.1" 403 199 "http://synapseresults.com/@fs/../.env?raw??" "Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)" 104.22.93.19
34.48.176.210 - - [04/Oct/2026:23:02:55 -0500] "GET /.env?import&raw?? HTTP/1.1" 403 199 "http://synapseresults.com/@fs/../.env?import&raw??" "Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)" 104.22.93.19
34.48.176.210 - - [04/Oct/2026:23:02:57 -0500] "GET /.env?import&raw HTTP/1.1" 301 258 "-" "Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)" 172.68.138.219
34.48.176.210 - - [04/Oct/2026:23:02:57 -0500] "GET /.env?raw HTTP/1.1" 301 247 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36; compatible; OAI-SearchBot/1.4; +https://openai.com/searchbot" 162.158.79.72
34.48.176.210 - - [04/Oct/2026:23:02:57 -0500] "GET /.env?import&url&inline HTTP/1.1" 301 269 "-" "Mozilla/5.0 (compatible; Bai
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 03:51:15
(12 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.48.176.210 (210.176.48.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.48.176.210 (210.176.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 23:51:12.681462 2026] [security2:error] [pid 32407:tid 32407] [client 34.48.176.210:56770] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||smartstylehair.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "smartstylehair.com"] [uri "/z9x8c7v6b5-debug-trigger-smartstylehair.com"] [unique_id "asMesIkv655WjsaQ_GcelQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-10-05 03:34:10
(12 hours ago)
734 requests with url.path */@fs/*
237 requests with url.path */proc/*
160 requests with url.path ...
show more
734 requests with url.path */@fs/*
237 requests with url.path */proc/*
160 requests with url.path *.aws/*
152 requests with url.path *credentials.json
138 requests with url.path *.ssh/*
115 requests with url.path *config.json
show less
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-05 03:28:37
(12 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.48.176.210 (210.176.48.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.48.176.210 (210.176.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 23:28:32.765920 2026] [security2:error] [pid 13229:tid 13229] [client 34.48.176.210:54598] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||rdhtrucking.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "rdhtrucking.com"] [uri "/z9x8c7v6b5-debug-trigger-rdhtrucking.com"] [unique_id "asMZYADZDBLedeTocUkVHAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 03:10:16
(12 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.48.176.210 (210.176.48.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.48.176.210 (210.176.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 23:10:07.583720 2026] [security2:error] [pid 28428:tid 28428] [client 34.48.176.210:58636] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||pghsea.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "pghsea.com"] [uri "/z9x8c7v6b5-debug-trigger-pghsea.com"] [unique_id "asMVDzs-OmA0wttOtih5eAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 02:54:36
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.48.176.210 (210.176.48.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.48.176.210 (210.176.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 22:54:32.172389 2026] [security2:error] [pid 3571880:tid 3571905] [client 34.48.176.210:41000] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "oplconnect.com"] [uri "/.htpasswd"] [unique_id "asMRaFWiIozRRsksE9ejnAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
on-com
2026-10-05 02:52:55
(13 hours ago)
URL scan
Brute-Force
Web App Attack
๐ณ๐ฑ
Savvii
2026-10-05 02:24:32
(13 hours ago)
20 attempts against mh-misbehave-ban on pavo
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
kosada.com
2026-10-05 02:06:41
(13 hours ago)
Repeated exploit attempts, for example: /.ssh/id_ed25519 /.ssh (HTTP/2.0 port 443, user agent: "Mozi ...
show more
Repeated exploit attempts, for example: /.ssh/id_ed25519 /.ssh (HTTP/2.0 port 443, user agent: "Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)")
show less
Web App Attack