๐ฒ๐ฝ
octageeks.com
2026-10-02 04:20:41
(4 hours ago)
Wordpress malicious attack:[octamissingdomain]
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-01 14:57:41
(17 hours ago)
[mx01aln] Web exploit scanning: 7 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[mx01aln] Web exploit scanning: 7 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.79.85.185 - - [01/Oct/2026:16:57:41 +0200] "GET /@fs/.env?raw&url?? HTTP/2.0" 404 2004 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)"
34.79.85.185 - - [01/Oct/2026:16:57:41 +0200] "GET /@fs/.env?import&?raw?? HTTP/2.0" 404 2004 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )"
34.79.85.185 - - [01/Oct/2026:16:57:41 +0200] "GET /@fs/app/.env.local?import&raw?? HTTP/2.0" 404 2004 "-" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)"
34.79.85.185 - - [01/Oct/2026:16:57:41 +0200] "GET /@fs/proc/self/cwd/.env?raw?? HTTP/2.0" 404 2004 "-" "Mozilla/5.0 (compatible;
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
Hagen Schoebel
2026-10-01 14:07:05
(18 hours ago)
Blocked by CrowdSec - Enabling body inspection (BE)
Port Scan
Brute-Force
Web App Attack
SSH
๐ณ๐ฑ
Site.eu
2026-10-01 13:51:58
(18 hours ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-10-01 13:49:05
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.79.85.185 (185.85.79.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.79.85.185 (185.85.79.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 09:49:00.365106 2026] [security2:error] [pid 16269:tid 16269] [client 34.79.85.185:42508] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.blastjet.net"] [uri "/media../.env"] [unique_id "ar5kzL38lFVogWaG_MhWYgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
noise.agency
2026-10-01 13:28:42
(18 hours ago)
34.79.85.185 (BE/Belgium/185.85.79.34.bc.googleusercontent.com), more than 10 Apache 403 hits
Hacking
๐บ๐ธ
kadour
2026-10-01 12:31:03
(19 hours ago)
[Thu Oct 01 07:31:01.578590 2026] [proxy_fcgi:error] [pid 1426711:tid 1426860] [client 34.79.85.185: ...
show more
[Thu Oct 01 07:31:01.578590 2026] [proxy_fcgi:error] [pid 1426711:tid 1426860] [client 34.79.85.185:47660] AH01071: Got error 'Primary script unknown'
[Thu Oct 01 07:31:01.708695 2026] [proxy_fcgi:error] [pid 1431410:tid 1431453] [client 34.79.85.185:47730] AH01071: Got error 'Primary script unknown'
[Thu Oct 01 07:31:01.774966 2026] [proxy_fcgi:error] [pid 1431410:tid 1431460] [client 34.79.85.185:47706] AH01071: Got error 'Primary script unknown'
[Thu Oct 01 07:31:01.841126 2026] [proxy_fcgi:error] [pid 1431410:tid 1431457] [client 34.79.85.185:47664] AH01071: Got error 'Primary script unknown'
[Thu Oct 01 07:31:01.959602 2026] [proxy_fcgi:error] [pid 1426710:tid 1426849] [client 34.79.85.185:47676] AH01071: Got error 'Primary script unknown'
...
show less
Web App Attack
๐บ๐ธ
Charlesiv
2026-10-01 12:01:13
(20 hours ago)
Triggered Cloudflare WAF (firewallCustom) from BE.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Prot ...
show more
Triggered Cloudflare WAF (firewallCustom) from BE.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/2 (POST method)
Endpoint: /exec-py
Timestamp: 2026-10-01T11:39:31Z
Ray ID: a43b2ff00d02d4f6
UA: Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-01 11:52:56
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.79.85.185 (185.85.79.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.79.85.185 (185.85.79.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 07:52:53.330039 2026] [security2:error] [pid 4468:tid 4468] [client 34.79.85.185:56122] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sisix.net"] [uri "/.env.js"] [unique_id "ar5JlQhLTeNRU30eVW9i4gAAAC0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
raph
2026-10-01 11:41:33
(20 hours ago)
[PROTECTED PATHS] crawler credentials.ini, aws.ini, aws.yml, etc.
Bad Web Bot
Web App Attack
๐ฉ๐ช
AetherFox
2026-10-01 11:21:20
(21 hours ago)
AetherFox VoidGuard detected: [Thu Oct 01 11:21:19.644729 2026] [security2:error] [pid 780943:tid 78 ...
show more
AetherFox VoidGuard detected: [Thu Oct 01 11:21:19.644729 2026] [security2:error] [pid 780943:tid 780983] [client 34.79.85.185:53586] [client 34.79.85.185] ModSecurity: Access denied with code 403 (phase 1). Match of "ipMatch 23.88.112.221" against "REMOTE_ADDR" required. [file "/etc/modsecurity/AetherFox.conf"] [line "40"] [id "100055"] [msg "wp-json access blocked by AetherFox VoidGuard"] [hostname "draconigen.net"] [uri "/wp-json"] [unique_id "ar5CLzvZNU0Z9Xk3nNqqUAAAAMs"]
[Thu Oct 01 11:21:19.645560 2026] [security2:error] [pid 780943:tid 780995] [client 34.79.85.185:53540] [client 34.79.85.185] ModSecurity: Access denied with code 403 (phase 1). String match "/.env" at REQUEST_URI. [file "/etc/modsecurity/AetherFox.conf"] [line "99"] [id "100067"] [msg ".env access blocked by AetherFox VoidGuard"] [tag "custom-blocklist"] [hostname "draconigen.net"] [uri "/files../.env"] [unique_id "ar5CLzvZNU0Z9Xk3nNqqUQAAANc"]
[Thu Oct 01 11:21:19.691388 2026] [security2:erro
...
show less
Hacking
Bad Web Bot
๐บ๐ธ
entangled_mongoose
2026-10-01 11:20:40
(21 hours ago)
Probed /wp-json.
Web App Attack
Anonymous
2026-10-01 11:20:10
(21 hours ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection
๐ฎ๐น
ciccio diddo
2026-10-01 11:15:10
(21 hours ago)
URL Scanner multiple 30X port:Tcp/80,443
Brute-Force
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-10-01 11:13:59
(21 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking