Anonymous
2026-09-23 15:10:14
(19 hours ago)
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: TW, Attack patterns: Word ...
show more
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: TW, Attack patterns: WordPress scanning, Backup file probing, Cloud secrets probing
show less
Bad Web Bot
Web App Attack
๐จ๐ฆ
zXero
2026-09-23 12:41:10
(22 hours ago)
Fail2Ban automatic report - jail: recidive
Brute-Force
SSH
DDoS Attack
๐ฎ๐ณ
evicky2002
2026-09-23 06:00:01
(1 day ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ช๐ธ
robotstxt
2026-09-23 01:46:10
(1 day ago)
34.81.56.233 - - [23/Sep/2026:01:45:52 +0000] "GET /public/.env HTTP/2.0" 403 0 "https://www.economi ...
show more
34.81.56.233 - - [23/Sep/2026:01:45:52 +0000] "GET /public/.env HTTP/2.0" 403 0 "https://www.economipedia.com/public/.env" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/)" "-"
34.81.56.233 - - [23/Sep/2026:01:45:52 +0000] "GET /docker/.env HTTP/2.0" 403 0 "https://www.economipedia.com/docker/.env" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)" "-"
34.81.56.233 - - [23/Sep/2026:01:45:52 +0000] "GET /api/.env HTTP/2.0" 403 0 "https://www.economipedia.com/api/.env" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)" "-"
34.81.56.233 - - [23/Sep/2026:01:45:52 +0000] "GET /app/.env HTTP/2.0" 403 0 "https://www.economipedia.com/app/.env" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)" "-"
34.81.56.233 - - [23/Sep/2026:01:45:52 +0000] "GET /dist/.env HTTP/2.0" 403 0 "https://www.economipedia.com/dist/.env" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/)" "-"
...
show less
Web App Attack
Anonymous
2026-09-23 00:32:58
(1 day ago)
"GET /.env HTTP/1.1"
Hacking
Web App Attack
๐ณ๐ฑ
ConsulHosting
2026-09-22 22:14:25
(1 day ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
๐ซ๐ท
regishoussin
2026-09-22 22:00:25
(1 day ago)
Automated web scanning detected by Wazuh (rule 100180): repeated 400/404 errors from mass probing of ...
show more
Automated web scanning detected by Wazuh (rule 100180): repeated 400/404 errors from mass probing of admin/backdoor paths (e.g. wp-login.php, known CMS shell filenames) on an Apache web server, on 2026-09-22 22:00 UTC.
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
doarg
2026-09-22 21:04:51
(1 day ago)
[Tue Sep 22 23:04:49.618674 2026] [authz_core:error] [pid 921695] [client 34.81.56.233:36556] AH0163 ...
show more
[Tue Sep 22 23:04:49.618674 2026] [authz_core:error] [pid 921695] [client 34.81.56.233:36556] AH01630: client denied by server configuration: /var/www/doarg.com/webpack-stats.json
[Tue Sep 22 23:04:50.039625 2026] [authz_core:error] [pid 921870] [client 34.81.56.233:36604] AH01630: client denied by server configuration: /var/www/doarg.com/asset-manifest.json
[Tue Sep 22 23:04:50.045658 2026] [authz_core:error] [pid 921692] [client 34.81.56.233:36592] AH01630: client denied by server configuration: /var/www/doarg.com/assets/manifest.json
[Tue Sep 22 23:04:50.057186 2026] [authz_core:error] [pid 922117] [client 34.81.56.233:36566] AH01630: client denied by server configuration: /var/www/doarg.com/manifest.json
[Tue Sep 22 23:04:51.009432 2026] [authz_core:error] [pid 921689] [client 34.81.56.233:36586] AH01630: client denied by server configuration: /var/www/doarg.com/config/.env
...
show less
Brute-Force
๐บ๐ธ
factor1
2026-09-22 20:32:24
(1 day ago)
CrowdSec at apollo Reports Abuse
Web App Attack
๐บ๐ธ
factor1
2026-09-22 18:33:21
(1 day ago)
CrowdSec at sherman Reports Abuse
Web App Attack
๐ฎ๐น
eliosbrocchi
2026-09-22 17:38:00
(1 day ago)
34.81.56.233 - - [22/Sep/2026:19:37:58 +0200] "GET /bootstrap.yml HTTP/2.0" 301 333 "-" "Mozilla/5.0 ...
show more
34.81.56.233 - - [22/Sep/2026:19:37:58 +0200] "GET /bootstrap.yml HTTP/2.0" 301 333 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.4; +https://openai.com/gptbot"
...
show less
VPN IP
๐จ๐ญ
dalslab ltd
2026-09-22 17:33:24
(1 day ago)
34.81.56.233 - - [22/Sep/2026:19:33:21 +0200] "POST / HTTP/1.1" 405 154 "-" "Mozilla/5.0 AppleWebKit ...
show more
34.81.56.233 - - [22/Sep/2026:19:33:21 +0200] "POST / HTTP/1.1" 405 154 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.4; +https://openai.com/gptbot"
34.81.56.233 - - [22/Sep/2026:19:33:22 +0200] "POST /api HTTP/1.1" 405 154 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)"
34.81.56.233 - - [22/Sep/2026:19:33:22 +0200] "POST /graphql HTTP/1.1" 405 556 "http://dalslab.com" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
34.81.56.233 - - [22/Sep/2026:19:33:23 +0200] "POST /api/graphql HTTP/1.1" 405 556 "http://dalslab.com" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
34.81.56.233 - - [22/Sep/2026:19:33:24 +0200] "POST /v1/graphql HTTP/1.1" 405 556 "http://dalslab.com" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
...
show less
Web Spam
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 17:18:53
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.81.56.233 (233.56.81.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.81.56.233 (233.56.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 13:18:49.275835 2026] [security2:error] [pid 31851:tid 31851] [client 34.81.56.233:60300] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||dmasoftlab.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "dmasoftlab.com"] [uri "/z9x8c7v6b5-debug-trigger-dmasoftlab.com"] [unique_id "arK4ed9qDR9nk4TML1PF5gAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
doarg
2026-09-22 16:33:35
(1 day ago)
[Tue Sep 22 18:33:30.051024 2026] [authz_core:error] [pid 920073] [client 34.81.56.233:41686] AH0163 ...
show more
[Tue Sep 22 18:33:30.051024 2026] [authz_core:error] [pid 920073] [client 34.81.56.233:41686] AH01630: client denied by server configuration: /var/www/doarg.com/assets/manifest.json
[Tue Sep 22 18:33:30.275518 2026] [authz_core:error] [pid 920143] [client 34.81.56.233:41726] AH01630: client denied by server configuration: /var/www/doarg.com/manifest.json
[Tue Sep 22 18:33:30.284593 2026] [authz_core:error] [pid 920071] [client 34.81.56.233:41736] AH01630: client denied by server configuration: /var/www/doarg.com/asset-manifest.json
[Tue Sep 22 18:33:30.300773 2026] [authz_core:error] [pid 919723] [client 34.81.56.233:41800] AH01630: client denied by server configuration: /var/www/doarg.com/webpack-stats.json
[Tue Sep 22 18:33:34.987145 2026] [authz_core:error] [pid 920173] [client 34.81.56.233:41880] AH01630: client denied by server configuration: /var/www/doarg.com/.env
...
show less
Brute-Force
๐ฉ๐ช
dbmwebdesign
2026-09-22 15:50:03
(1 day ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack