Anonymous
2026-10-10 18:30:07
(5 minutes ago)
CrowdSec decision: crowdsecurity/http-admin-interface-probing (origin: crowdsec)
Web App Attack
๐ฎ๐น
VHosting
2026-10-10 18:30:04
(5 minutes ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-10 18:29:07
(6 minutes ago)
(mod_security) mod_security (id:210730) triggered by 34.7.112.244 (244.112.7.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.7.112.244 (244.112.7.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 14:29:02.323014 2026] [security2:error] [pid 9514:tid 9514] [client 34.7.112.244:49800] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||jonesypop.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "jonesypop.com"] [uri "/z9x8c7v6b5-debug-trigger-jonesypop.com"] [unique_id "asqD7lKnWYuJA4gm1lhgNgAAAFQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
masterguru
2026-10-10 18:12:35
(22 minutes ago)
COMODO WAF: URL file extension is restricted by policy. Match of "pmFromFile userdata_wl_extensions" ...
show more
COMODO WAF: URL file extension is restricted by policy. Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. (210730-185)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-10 18:12:30
(22 minutes ago)
(mod_security) mod_security (id:210730) triggered by 34.7.112.244 (244.112.7.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.7.112.244 (244.112.7.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 14:12:23.508356 2026] [security2:error] [pid 22409:tid 22409] [client 34.7.112.244:48226] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||gotdt.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "gotdt.com"] [uri "/z9x8c7v6b5-debug-trigger-gotdt.com"] [unique_id "asqAB0RAWzXxnwVnfjQG_QAAAHo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-10-10 18:10:12
(25 minutes ago)
20 attempts against mh-misbehave-ban on onion
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
bazter.pro
2026-10-10 18:10:02
(25 minutes ago)
Fail2Ban: plesk-bot-aggressive - 15 failures
Port Scan
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-10-10 17:50:48
(44 minutes ago)
20 attempts against mh-misbehave-ban on chive
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-10 17:50:14
(45 minutes ago)
(mod_security) mod_security (id:210730) triggered by 34.7.112.244 (244.112.7.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.7.112.244 (244.112.7.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 13:50:07.790892 2026] [security2:error] [pid 6989:tid 6989] [client 34.7.112.244:46316] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||dandpcreamery.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "dandpcreamery.com"] [uri "/z9x8c7v6b5-debug-trigger-dandpcreamery.com"] [unique_id "asp6z8uX2XKxwEdVvP72DQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
renzo64
2026-10-10 17:47:06
(48 minutes ago)
Domain : conference-biomass.com
Rule : env
2026-10-10 17:45:53 ***hidden-privacy*** GET /@fs/app/.en ...
show more
Domain : conference-biomass.com
Rule : env
2026-10-10 17:45:53 ***hidden-privacy*** GET /@fs/app/.env.local import
show less
Hacking
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-10-10 17:26:29
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 34.7.112.244 (244.112.7.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.7.112.244 (244.112.7.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 13:26:26.293220 2026] [security2:error] [pid 12818:tid 12818] [client 34.7.112.244:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||atlascoombs.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "atlascoombs.com"] [uri "/z9x8c7v6b5-debug-trigger-atlascoombs.com"] [unique_id "asp1QrS0ZE_44EaS0XcoUQAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-10 17:20:14
(1 hour ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection