๐ฌ๐ง
poundawebsiteltd
2026-06-10 20:22:05
(2 weeks ago)
Malicious activity in apache-honeypot. Evidence: Automated block: Evidence found in system journals ...
show more
Malicious activity in apache-honeypot. Evidence: Automated block: Evidence found in system journals but could not be parsed.
show less
Brute-Force
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-06-09 21:59:23
(2 weeks ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-06-08.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-08 16:57:19
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 34.73.175.50 (50.175.73.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.73.175.50 (50.175.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 12:57:14.792802 2026] [security2:error] [pid 3613:tid 3613] [client 34.73.175.50:55850] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||tradelosangeles.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "tradelosangeles.com"] [uri "/.config/gcloud/credentials.db"] [unique_id "aib0ah99wqdPa_R893qecwAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-08 16:55:15
(2 weeks ago)
Multiple web server 400 error codes from same source ip
Web App Attack
๐ณ๐ฑ
Site.eu
2026-06-08 15:27:26
(2 weeks ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-08 12:01:21
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 34.73.175.50 (50.175.73.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.73.175.50 (50.175.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 08:01:16.474221 2026] [security2:error] [pid 25763:tid 25834] [client 34.73.175.50:49802] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||jupitermaturin.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "jupitermaturin.com"] [uri "/database.ini"] [unique_id "aiavDMQXAI7ypmnJabSdGAAAAQw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
COMAITE
2026-06-08 11:39:17
(2 weeks ago)
Suspicious URL access.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 11:21:53
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 34.73.175.50 (50.175.73.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.73.175.50 (50.175.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 07:21:48.580843 2026] [security2:error] [pid 2992:tid 2992] [client 34.73.175.50:54656] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||midcityrotary.org|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "midcityrotary.org"] [uri "/.config/gcloud/credentials.db"] [unique_id "aialzJF5NAXo3Kk01PHwbQAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
poundawebsiteltd
2026-06-08 09:23:39
(2 weeks ago)
Web App Attack (ModSecurity Block). Evidence: [REDACTED_DOMAIN]:443 34.73.175.50 - - [08/Jun/2026:10 ...
show more
Web App Attack (ModSecurity Block). Evidence: [REDACTED_DOMAIN]:443 34.73.175.50 - - [08/Jun/2026:10:23:37 +0100] GET /internal/docker-compose.yml HTTP/1.1 403 3107 - Mozilla/5.0 (compatible; Yahoo! Slurp; http://[REDACTED_DOMAIN]/help/us/ysearch/slurp)
show less
Web App Attack
๐ฌ๐ง
Aetherweb Ark
2026-06-08 07:58:43
(2 weeks ago)
(mod_security) mod_security (id:949110) triggered by 34.73.175.50 (US/United States/50.175.73.34.bc. ...
show more
(mod_security) mod_security (id:949110) triggered by 34.73.175.50 (US/United States/50.175.73.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
๐ซ๐ท
dynamix
2026-06-08 06:43:55
(2 weeks ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
updown.io
2026-06-08 06:25:52
(2 weeks ago)
{"level":"info","ts":1780899946.9651642,"logger":"http.log.access.log1","msg":"handled request","req ...
show more
{"level":"info","ts":1780899946.9651642,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.73.175.50","remote_port":"37542","client_ip":"34.73.175.50","proto":"HTTP/1.1","method":"GET","host":"admin.comww.159.89.98.98.nip.io","uri":"/actuator/heapdump","headers":{"Connection":["close"],"User-Agent":["Mozilla/5.0 (OS/2; Warp 4.5; rv:24.0) Gecko/20100101 Firefox/24.0 SeaMonkey/2.21"],"Accept-Charset":["utf-8"],"Accept-Encoding":["gzip"]}},"bytes_read":0,"user_id":"","duration":0.000059983,"size":0,"status":308,"resp_headers":{"Content-Type":[],"Server":["Caddy"],"Connection":["close"],"Location":["https://admin.comww.159.89.98.98.nip.io/actuator/heapdump"]}}
{"level":"info","ts":1780899946.9675002,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.73.175.50","remote_port":"37558","client_ip":"34.73.175.50","proto":"HTTP/1.1","method":"GET","host":"admin.comww.159.89.98.98.nip.io","uri":"/actuator/env","headers":{"Accept-Char
...
show less
DDoS Attack
Web App Attack
๐ฌ๐ง
Nick Lewis
2026-06-08 06:20:55
(2 weeks ago)
(mod_security) mod_security triggered on hostname [redacted] 34.73.175.50 (US/United States/50.175.7 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.73.175.50 (US/United States/50.175.73.34.bc.googleusercontent.com)
show less
SQL Injection
๐จ๐ญ
backslash
2026-06-08 05:03:04
(2 weeks ago)
block ruleset 3D3AFA921A373ECE19B6BA285C2D722163304638
Bad Web Bot
๐ฎ๐น
VHosting
2026-06-08 03:30:03
(2 weeks ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack