๐บ๐ธ
solantex
2026-09-30 18:22:42
(5 hours ago)
Unauthorized automated scanning and reconnaissance against Solantex resources. No crawl, scan or tes ...
show more
Unauthorized automated scanning and reconnaissance against Solantex resources. No crawl, scan or test permission has been granted to this source.
show less
Web App Attack
๐บ๐ธ
mnsf
2026-09-30 18:05:57
(6 hours ago)
Scanning/Probing (14)
Brute-Force
Web App Attack
๐บ๐ธ
VanKoh
2026-09-30 17:39:56
(6 hours ago)
(cpanel) Failed cPanel login from 34.75.236.159 (US/United States/South Carolina/North Charleston/15 ...
show more
(cpanel) Failed cPanel login from 34.75.236.159 (US/United States/South Carolina/North Charleston/159.236.75.34.bc.googleusercontent.com): 5 in the last 3600 secs; IP: 34.75.236.159; Ports: *; Direction: 1; Trigger: LF_TRIGGER; Logs: [2026-09-30 11:39:53 -0600] info [cpaneld] 34.75.236.159 - - "GET /model/info HTTP/1.1" FAILED LOGIN cpaneld: Authorization: type not known [2026-09-30 11:39:53 -0600] info [cpaneld] 34.75.236.159 - - "POST /graphql HTTP/1.1" FAILED LOGIN cpaneld: login attempt without username [2026-09-30 11:39:54 -0600] info [cpaneld] 34.75.236.159 - - "GET /static../.env HTTP/1.1" FAILED LOGIN cpaneld: login attempt without username [2026-09-30 11:39:54 -0600] info [cpaneld] 34.75.236.159 - - "GET /config.json HTTP/1.1" FAILED LOGIN cpaneld: login attempt without username [2026-09-30 11:39:54 -0600] info [cpaneld] 34.75.236.159 - - "POST /v1/graphql HTTP/1.1" FAILED LOGIN cpaneld: login attempt without username
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-30 15:02:59
(9 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.75.236.159 (159.236.75.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.75.236.159 (159.236.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 11:02:54.480850 2026] [security2:error] [pid 15777:tid 15893] [client 34.75.236.159:47550] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||credit-card-cap.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "credit-card-cap.com"] [uri "/z9x8c7v6b5-debug-trigger-credit-card-cap.com"] [unique_id "ar0knu14HsboWLZrESlRtQAAAlc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 14:26:12
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.75.236.159 (159.236.75.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.75.236.159 (159.236.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 10:26:08.090115 2026] [security2:error] [pid 375:tid 375] [client 34.75.236.159:35138] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.cruanyes.com"] [uri "/img../.env"] [unique_id "ar0cAKaG65mAmoh87qxr3gAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-30 14:05:06
(10 hours ago)
WAF repeated trigger detected by Fail2Ban
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 13:15:18
(10 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.75.236.159 (159.236.75.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.75.236.159 (159.236.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 09:15:11.576045 2026] [security2:error] [pid 17951:tid 17951] [client 34.75.236.159:58996] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||crowleywoodworking.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "crowleywoodworking.com"] [uri "/z9x8c7v6b5-debug-trigger-crowleywoodworking.com"] [unique_id "ar0LX4pp1l4OdNwPHT_8GwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-30 12:08:26
(11 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐ซ๐ท
dynamix
2026-09-30 10:56:41
(13 hours ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
CDO
2026-09-30 10:48:11
(13 hours ago)
URL Injection attempt detected. Automated web attack.
Hacking
Bad Web Bot
Web App Attack
๐ฉ๐ช
paissangroup
2026-09-30 10:21:15
(13 hours ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-09-30 10:13:26
(13 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐ฎ๐น
VHosting
2026-09-30 09:45:03
(14 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 09:27:11
(14 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.75.236.159 (159.236.75.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.75.236.159 (159.236.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 05:27:03.995199 2026] [security2:error] [pid 8004:tid 8004] [client 34.75.236.159:36266] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||digbie.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "digbie.com"] [uri "/z9x8c7v6b5-debug-trigger-digbie.com"] [unique_id "arzV5_YVzybar7eKJIb51AAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-30 09:25:21
(14 hours ago)
[cb-03al] Web exploit scanning: 2 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[cb-03al] Web exploit scanning: 2 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.75.236.159 - - [30/Sep/2026:11:25:01 +0200] "GET /phpinfo.php HTTP/2.0" 404 346 "-" "Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)"
...
show less
Bad Web Bot
Web App Attack