๐ซ๐ท
andreighitan
2026-06-12 11:18:50
(11 hours ago)
Coordinated attack against 84.46.253.134. Webshell scanning, PHPUnit RCE, credential harvesting, PHP ...
show more
Coordinated attack against 84.46.253.134. Webshell scanning, PHPUnit RCE, credential harvesting, PHP vuln scanning. Active June 7-11 2026. ZAC Bayern ref BY0257-500359-26/8.
show less
Web App Attack
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-08 16:30:38
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 34.75.223.138 (138.223.75.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.75.223.138 (138.223.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 12:30:34.293651 2026] [security2:error] [pid 10119:tid 10119] [client 34.75.223.138:57616] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||tallahasseepartybuses.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "tallahasseepartybuses.com"] [uri "/.config/gcloud/credentials.db"] [unique_id "aibuKoOSDsdcP3hykDhYHQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2026-06-08 15:21:01
(4 days ago)
block ruleset Badbot using very old user-agents 5CF3CDB778C7D82564405B86B9242E612F378C68
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-08 15:10:20
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 34.75.223.138 (138.223.75.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.75.223.138 (138.223.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 11:10:14.473910 2026] [security2:error] [pid 26517:tid 26517] [client 34.75.223.138:43882] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||burke698.org.nilestree.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "burke698.org.nilestree.com"] [uri "/.config/gcloud/credentials.db"] [unique_id "aibbVle3zI4QxQRl4pW4zgAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฟ
Tripwire
2026-06-08 14:51:16
(4 days ago)
Scanning for exploits - /config/.aws/credentials
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 12:37:31
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 34.75.223.138 (138.223.75.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.75.223.138 (138.223.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 08:37:27.323491 2026] [security2:error] [pid 5788:tid 5816] [client 34.75.223.138:49642] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.abdominaletching.aafm.us|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.abdominaletching.aafm.us"] [uri "/.config/gcloud/credentials.db"] [unique_id "aia3h5OvBRRyYMvfAf04wQAAAVg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-06-08 12:05:19
(4 days ago)
Abuse Detected (14)
Brute-Force
Web App Attack
๐ณ๐ฑ
Site.eu
2026-06-08 09:53:41
(4 days ago)
Excessive 404/403 errors
Brute-Force
๐ฌ๐ง
Celtic
2026-06-08 05:12:46
(4 days ago)
Blocked by Fail2Ban with Jail (plesk-modsecurity)
Brute-Force
SSH
๐ฌ๐ง
Aetherweb Ark
2026-06-08 05:02:34
(4 days ago)
(mod_security) mod_security (id:949110) triggered by 34.75.223.138 (US/United States/138.223.75.34.b ...
show more
(mod_security) mod_security (id:949110) triggered by 34.75.223.138 (US/United States/138.223.75.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
๐ฌ๐ง
consul.to
2026-06-08 04:49:20
(4 days ago)
Web attack/malicious scanning detected
Web App Attack
Anonymous
2026-06-08 02:29:48
(4 days ago)
Multiple web server 400 error codes from same source ip
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 02:11:12
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 34.75.223.138 (138.223.75.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.75.223.138 (138.223.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 07 22:11:06.721060 2026] [security2:error] [pid 15689:tid 15689] [client 34.75.223.138:46510] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||chrischamberlain.mindrelaxation.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "chrischamberlain.mindrelaxation.com"] [uri "/.config/gcloud/credentials.db"] [unique_id "aiYkuhCg4mx3draDbesCbQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-06-08 01:30:03
(4 days ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐ฉ๐ช
updown.io
2026-06-08 01:11:12
(4 days ago)
{"level":"info","ts":1780881071.7546823,"logger":"http.log.access.log1","msg":"handled request","req ...
show more
{"level":"info","ts":1780881071.7546823,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.75.223.138","remote_port":"52246","client_ip":"34.75.223.138","proto":"HTTP/1.1","method":"GET","host":"update.wupdate.srqponmlkjilkjihgc7402a95-6fc9-4756-b4e6-fa6c7eeb29c6.random.159.89.98.98.nip.io","uri":"/actuator/env","headers":{"Connection":["close"],"User-Agent":["Mozilla/5.0 (Symbian/3; Series60/5.2 NokiaC7-00/012.003; Profile/MIDP-2.1 Configuration/CLDC-1.1 ) AppleWebKit/525 (KHTML, like Gecko) Version/3.0 BrowserNG/7.2.7.3 3gpp-gba"],"Accept-Charset":["utf-8"],"Accept-Encoding":["gzip"]}},"bytes_read":0,"user_id":"","duration":0.000035938,"size":0,"status":308,"resp_headers":{"Connection":["close"],"Location":["https://update.wupdate.srqponmlkjilkjihgc7402a95-6fc9-4756-b4e6-fa6c7eeb29c6.random.159.89.98.98.nip.io/actuator/env"],"Content-Type":[],"Server":["Caddy"]}}
{"level":"info","ts":1780881071.7619936,"logger":"http.log.access.log1","msg":"handled req
...
show less
DDoS Attack
Web App Attack