๐ฟ๐ฆ
conure.sh
2026-10-05 12:05:47
(1 day ago)
csagent: score 20.0: secrets grab x2; 1 domain(s) in 7s
Web App Attack
๐บ๐ธ
WizardsToolkit
2026-10-05 11:13:29
(1 day ago)
tried to access forbidden files; attempted to access /app/.env
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 10:15:59
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.84.155.66 (66.155.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.84.155.66 (66.155.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 06:15:53.348726 2026] [security2:error] [pid 26437:tid 26437] [client 34.84.155.66:55524] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||luxebikinis.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "luxebikinis.com"] [uri "/z9x8c7v6b5-debug-trigger-luxebikinis.com"] [unique_id "asN42c0IO-M_hv0gGI81awAAAF0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
rubixstudios
2026-10-05 09:05:03
(1 day ago)
Excessive HTTP requests consistent with automated attack behaviour detected by Imunify360
DDoS Attack
Brute-Force
Web App Attack
๐ง๐ช
cmbplf
2026-10-05 08:35:39
(1 day ago)
158 requests with url.path */@fs/*
Brute-Force
Bad Web Bot
Anonymous
2026-10-05 08:35:02
(1 day ago)
suspicious request in access.log
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-05 08:02:56
(1 day ago)
[cb-01al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[cb-01al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.84.155.66 - - [05/Oct/2026:10:02:45 +0200] "GET /files../.env HTTP/2.0" 404 1338 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)"
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-10-05 07:52:37
(1 day ago)
Automated report (2026-10-05T15:52:37+08:00). Scraper detected.
Bad Web Bot
Anonymous
2026-10-05 07:52:34
(1 day ago)
Automated report (2026-10-05T15:52:34+08:00). Scraper detected.
Bad Web Bot
Anonymous
2026-10-05 07:32:56
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
๐ณ๐ฑ
Site.eu
2026-10-05 07:24:26
(1 day ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
masterguru
2026-10-05 07:11:44
(1 day ago)
COMODO WAF: URL file extension is restricted by policy. Match of "pmFromFile userdata_wl_extensions" ...
show more
COMODO WAF: URL file extension is restricted by policy. Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. (210730-169)
show less
Hacking
๐บ๐ธ
TAY
2026-10-05 06:33:08
(1 day ago)
34.84.155.66 - - [05/Oct/2026:14:33:02 +0800] "GET /public/plugins/text/../../../../../../../../proc ...
show more
34.84.155.66 - - [05/Oct/2026:14:33:02 +0800] "GET /public/plugins/text/../../../../../../../../proc/self/environ HTTP/1.1" 400 2056 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
34.84.155.66 - - [05/Oct/2026:14:33:03 +0800] "GET /@fs/../.env?raw?? HTTP/1.1" 404 2049 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)"
34.84.155.66 - - [05/Oct/2026:14:33:04 +0800] "GET /@fs/../.env?import&raw?? HTTP/1.1" 404 2049 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)"
34.84.155.66 - - [05/Oct/2026:14:33:06 +0800] "GET /_nuxt/../.env HTTP/1.1" 404 2049 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1)"
34.84.155.66 - - [05/Oct/2026:14:33:07 +0800] "GET /_image?href=/../../../.env HTTP/1.1" 404 2049 "-" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)"
34.84.155.66 - - [05/Oct/2026:14:33:07 +0800] "GET /public/plugins/alertlist/../..
...
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-10-05 06:23:40
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.84.155.66 (66.155.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.155.66 (66.155.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 02:23:32.058557 2026] [security2:error] [pid 31852:tid 31852] [client 34.84.155.66:50640] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "khtcpl.com"] [uri "/cache/original/%2e%2e/%2e%2e/.env"] [unique_id "asNCZOTNhAskzrmkjGnwEQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 04:17:54
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.84.155.66 (66.155.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.84.155.66 (66.155.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 00:17:49.798979 2026] [security2:error] [pid 26713:tid 26713] [client 34.84.155.66:45192] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||jfexpressfr8.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "jfexpressfr8.com"] [uri "/z9x8c7v6b5-debug-trigger-jfexpressfr8.com"] [unique_id "asMk7XfybuWxdTZlwMIjqgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack