๐ซ๐ท
pm33
2026-10-01 07:11:20
(1 day ago)
Unauthorized connections HTTP 403
Web App Attack
๐บ๐ธ
brightenfield
2026-10-01 05:50:56
(1 day ago)
Web App Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 05:39:07
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.84.4.27 (27.4.84.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.4.27 (27.4.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 01:39:02.126895 2026] [security2:error] [pid 11767:tid 11869] [client 34.84.4.27:32904] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.kettlehill.com"] [uri "/.htpasswd"] [unique_id "ar3x9hfvffc6aAQuuta2yAAAAkM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Apache
2026-10-01 05:36:08
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.84.4.27 (JP/Japan/27.4.84.34.bc.googleuserco ...
show more
(mod_security) mod_security (id:210730) triggered by 34.84.4.27 (JP/Japan/27.4.84.34.bc.googleusercontent.com): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
๐ฌ๐ง
openstrike.co.uk
2026-10-01 05:13:34
(1 day ago)
162 attacks on directory traversals, env grabbing URLs, password/key grabbing URLs, PHP URLs, shell ...
show more
162 attacks on directory traversals, env grabbing URLs, password/key grabbing URLs, PHP URLs, shell probes, config grabbing URLs (type 2), env grabbing URLs (type 2):
GET /..%2f..%2f.env HTTP/1.1
GET /%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env HTTP/1.1
GET /id_ecdsa HTTP/1.1
POST /index.php?-d+allow_url_include%3don+-d+auto_prepend_file%3dphp://input HTTP/1.1
POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1
GET /src/amplifyconfiguration.json HTTP/1.1
GET /api/console/api_server?sense_version=%40%40SENSE_VERSION&apis=../../../../../../proc/self/environ HTTP/1.1
show less
Hacking
Web App Attack
๐ณ๐ฑ
Savvii
2026-10-01 04:09:01
(1 day ago)
20 attempts against mh-misbehave-ban on grape
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 02:21:52
(1 day ago)
(mod_security) mod_security (id:210580) triggered by 34.84.4.27 (27.4.84.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210580) triggered by 34.84.4.27 (27.4.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 22:21:47.544094 2026] [security2:error] [pid 26571:tid 26571] [client 34.84.4.27:51052] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at ARGS:path. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||jbaydeliveries.com|F|2"] [data "Matched Data: proc/self/environ found within ARGS:path: ../../../../proc/self/environ"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "jbaydeliveries.com"] [uri "/userfiles/x"] [unique_id "ar3DuxK6PxXJg35tb3jY9AAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
Mediashaker
2026-10-01 01:47:40
(1 day ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 34.84.4.27 (JP/Japan ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 34.84.4.27 (JP/Japan/27.4.84.34.bc.googleusercontent.com)
show less
Bad Web Bot
๐ง๐ช
cmbplf
2026-10-01 00:50:36
(1 day ago)
236 requests with url.path */@fs/*
Brute-Force
Bad Web Bot
Anonymous
2026-10-01 00:14:21
(1 day ago)
Aggressive web scan
Web App Attack
๐ฆ๐บ
Klaverstyn
2026-09-30 23:41:37
(1 day ago)
Persistent attacker, repeat offender
Hacking
Anonymous
2026-09-30 23:30:06
(1 day ago)
CrowdSec decision: crowdsecurity/http-admin-interface-probing (origin: crowdsec)
Web App Attack
๐ฉ๐ช
stinpriza
2026-09-30 22:39:37
(1 day ago)
common Web Exploits being scanned
Web App Attack
๐บ๐ธ
pachec
2026-09-30 22:34:48
(1 day ago)
Automated vulnerability scanning blocked by fail2ban
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-30 15:34:52
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.84.4.27 (27.4.84.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210730) triggered by 34.84.4.27 (27.4.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 11:34:47.463992 2026] [security2:error] [pid 20052:tid 20052] [client 34.84.4.27:54938] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kikisfriends.truefauxstudio.com|F|2"] [data ".truefauxstudio.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kikisfriends.truefauxstudio.com"] [uri "/z9x8c7v6b5-debug-trigger-kikisfriends.truefauxstudio.com"] [unique_id "ar0sF2pq6i5V3yVcJI2eegAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack