๐บ๐ธ
Secure Gatewayยฎ๏ธ
2026-09-20 22:00:22
(3 days ago)
Report By Secure Gateway Security Team: Brute Force Login Attempt
SQL Injection
๐บ๐ธ
ALSCOยฎ๏ธ
2026-09-20 22:00:22
(3 days ago)
Report By ALSCO Security Team: SQL Injection Attempt Detected
Web App Attack
๐ช๐ธ
robotstxt
2026-09-20 15:24:28
(4 days ago)
34.81.21.66 - - [20/Sep/2026:15:23:37 +0000] "GET /.bash_profile HTTP/2.0" 403 26793 "-" "Mozilla/5. ...
show more
34.81.21.66 - - [20/Sep/2026:15:23:37 +0000] "GET /.bash_profile HTTP/2.0" 403 26793 "-" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)" "-" edge="34.81.21.66"
34.81.21.66 - - [20/Sep/2026:15:23:37 +0000] "GET /@fs/app/.env?raw?? HTTP/2.0" 403 26793 "-" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)" "-" edge="34.81.21.66"
34.81.21.66 - - [20/Sep/2026:15:23:37 +0000] "GET /@fs/src/.env?raw?? HTTP/2.0" 403 26793 "-" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" "-" edge="34.81.21.66"
34.81.21.66 - - [20/Sep/2026:15:23:38 +0000] "GET /@fs/../.env?raw?? HTTP/2.0" 403 26793 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)" "-" edge="34.81.21.66"
34.81.21.66 - - [20/Sep/2026:15:23:38 +0000] "GET /@fs/..%252f..%252f..%252f..%252f..%252froot/.env?raw?? HTTP/2.0" 403 26793 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)" "-" edge="34.81.21.66"
...
show less
Web App Attack
๐ณ๐ฑ
ConsulHosting
2026-09-20 15:22:56
(4 days ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 15:15:33
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 34.81.21.66 (66.21.81.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.81.21.66 (66.21.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 11:15:28.121065 2026] [security2:error] [pid 25806:tid 25806] [client 34.81.21.66:40930] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||domainbydomain.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "domainbydomain.com"] [uri "/z9x8c7v6b5-debug-trigger-domainbydomain.com"] [unique_id "aq_4kDmp0OIh3Y_ws6iYdAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
regishoussin
2026-09-20 15:05:44
(4 days ago)
Automated web scanning detected by Wazuh (rule 100241): repeated 400/404 errors from mass probing of ...
show more
Automated web scanning detected by Wazuh (rule 100241): repeated 400/404 errors from mass probing of admin/backdoor paths (e.g. wp-login.php, known CMS shell filenames) on an Apache web server, on 2026-09-20 15:05 UTC.
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 14:40:19
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 34.81.21.66 (66.21.81.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.81.21.66 (66.21.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 10:40:15.442153 2026] [security2:error] [pid 16286:tid 16286] [client 34.81.21.66:41074] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||dogdimension.com|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "dogdimension.com"] [uri "/host.key"] [unique_id "aq_wT6xXYjPN3nUXdOJLrwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-09-20 14:20:08
(4 days ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 14:18:53
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 34.81.21.66 (66.21.81.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.81.21.66 (66.21.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 10:18:49.795103 2026] [security2:error] [pid 16383:tid 16383] [client 34.81.21.66:58512] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||doctorspainmanagement.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "doctorspainmanagement.com"] [uri "/z9x8c7v6b5-debug-trigger-doctorspainmanagement.com"] [unique_id "aq_rSefXYNkzeQhQ4aotGwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-20 14:08:57
(4 days ago)
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encod ...
show more
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encoding/ /proxy/ /lock-token/ /content-range/ /if/ /x-http-method-override/ /x-http-method/ /x-method-override/ /x-middleware-subrequest/ /expect/" at TX:header_name_920450_x-middleware-subrequest. (920450-201)
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-20 13:58:41
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 34.81.21.66 (66.21.81.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.81.21.66 (66.21.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 09:58:38.545117 2026] [security2:error] [pid 16303:tid 16330] [client 34.81.21.66:51566] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||docdalton.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "docdalton.com"] [uri "/z9x8c7v6b5-debug-trigger-docdalton.com"] [unique_id "aq_mjqZ3t86YyJ_JmKQ2fQAAAIU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
yitzhaq
2026-09-20 13:55:40
(4 days ago)
34.81.21.66 - - [20/Sep/2026:15:55:37 +0200] "GET /.env.stage HTTP/2.0" 404 293 "-" "Mozilla/5.0 (co ...
show more
34.81.21.66 - - [20/Sep/2026:15:55:37 +0200] "GET /.env.stage HTTP/2.0" 404 293 "-" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)"
34.81.21.66 - - [20/Sep/2026:15:55:37 +0200] "GET /ai/.env HTTP/2.0" 404 293 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)"
34.81.21.66 - - [20/Sep/2026:15:55:37 +0200] "GET /api/settings HTTP/2.0" 404 293 "-" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/)"
34.81.21.66 - - [20/Sep/2026:15:55:37 +0200] "GET /apps/.env HTTP/2.0" 403 296 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email])"
34.81.21.66 - - [20/Sep/2026:15:55:37 +0200] "GET /build/.env HTTP/2.0" 404 293 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)"
34.81.21.66 - - [20/Sep/2026:15:55:37 +0200] "GET /llm/.env HTTP/2.0" 404 293 "-" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)"
34.81.21.66 - - [20/Sep/2026:15:55:37 +0200] "GET /api/v1/settings HTTP/2.0" 403 296 "-" "
show less
Web App Attack
Hacking
Anonymous
2026-09-20 13:29:01
(4 days ago)
Attempting to access restricted files
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 13:22:23
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 34.81.21.66 (66.21.81.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.81.21.66 (66.21.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 09:22:18.381559 2026] [security2:error] [pid 11584:tid 11584] [client 34.81.21.66:58458] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||disio.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "disio.com"] [uri "/z9x8c7v6b5-debug-trigger-disio.com"] [unique_id "aq_eCunki5qJIKz8-ullagAAAC0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
factor1
2026-09-20 13:19:25
(4 days ago)
CrowdSec at apollo Reports Abuse
Web App Attack