๐จ๐ญ
zynex
2026-06-08 12:38:39
(2 days ago)
URL Probing: /app/config.php
Web App Attack
๐ณ๐ฑ
Savvii
2026-06-08 11:48:20
(2 days ago)
40 attempts against mh-misbehave-ban on plum
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Octopuce
2026-06-08 10:17:44
(2 days ago)
Aggressive web search of vulnerable pages: /phpinfo.php /info.php /php.php /test.php /debug.php /php ...
show more
Aggressive web search of vulnerable pages: /phpinfo.php /info.php /php.php /test.php /debug.php /phptest.php /admin/phpinfo.php /api/phpinfo.ph ...
show less
Web App Attack
๐ซ๐ท
dynamix
2026-06-08 10:14:17
(2 days ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
mnsf
2026-06-08 08:09:54
(2 days ago)
Too many Status 40X (11)
Scanning/Probing (61)
Request Overload (383)
Brute-Force
Web App Attack
๐ฉ๐ช
updown.io
2026-06-08 06:37:48
(2 days ago)
{"level":"info","ts":1780900665.216678,"logger":"http.log.access.log1","msg":"handled request","requ ...
show more
{"level":"info","ts":1780900665.216678,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.75.11.252","remote_port":"34668","client_ip":"34.75.11.252","proto":"HTTP/1.1","method":"GET","host":"www.server.eigwncvbqnwww.159.89.98.98.nip.io","uri":"/actuator/env","headers":{"User-Agent":["Mozilla/5.0 (compatible; Konqueror/4.5; Windows) KHTML/4.5.4 (like Gecko)"],"Accept-Charset":["utf-8"],"Accept-Encoding":["gzip"],"Connection":["close"]}},"bytes_read":0,"user_id":"","duration":0.000084892,"size":0,"status":308,"resp_headers":{"Server":["Caddy"],"Connection":["close"],"Location":["https://www.server.eigwncvbqnwww.159.89.98.98.nip.io/actuator/env"],"Content-Type":[]}}
{"level":"info","ts":1780900665.2667186,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.75.11.252","remote_port":"34684","client_ip":"34.75.11.252","proto":"HTTP/1.1","method":"GET","host":"www.server.eigwncvbqnwww.159.89.98.98.nip.io","uri":"/actuator/configp
...
show less
DDoS Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 06:23:10
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.75.11.252 (252.11.75.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.75.11.252 (252.11.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 02:23:07.067028 2026] [security2:error] [pid 13702:tid 13702] [client 34.75.11.252:51762] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.wetlookforum.grayhost.net|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.wetlookforum.grayhost.net"] [uri "/.config/gcloud/credentials.db"] [unique_id "aiZfy62hZ_zgk5hhZLvJVgAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-08 06:03:12
(2 days ago)
Bot / seems abusive / Apache connections: 147
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-06-08 05:39:06
(2 days ago)
Excessive 404/403 errors
Brute-Force
๐ฎ๐น
VHosting
2026-06-08 03:50:09
(3 days ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 03:06:53
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 34.75.11.252 (252.11.75.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.75.11.252 (252.11.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 07 23:06:46.862297 2026] [security2:error] [pid 4636:tid 4636] [client 34.75.11.252:60588] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.fernandodearatanha.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.fernandodearatanha.com"] [uri "/.config/gcloud/credentials.db"] [unique_id "aiYxxmUxpZe-bcBpFguX8wAAADA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Bruno
2026-06-08 01:00:56
(3 days ago)
34.75.11.252 - - [08/Jun/2026:03:00:51 +0200] "GET /.npmrc HTTP/1.1" 404 90370 "-" "EmailWolf 1.00"
...
show more
34.75.11.252 - - [08/Jun/2026:03:00:51 +0200] "GET /.npmrc HTTP/1.1" 404 90370 "-" "EmailWolf 1.00"
...
show less
Web App Attack
๐ฉ๐ช
Philister11
2026-06-08 00:18:56
(3 days ago)
CrowdSec: crowdsecurity/http-crawl-non_statics (US/AS396982)
Bad Web Bot
Web App Attack