Anonymous
2026-10-01 07:30:19
(1 day ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐ฌ๐ง
consul.to
2026-10-01 06:13:54
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 05:33:18
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.84.99.90 (90.99.84.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.99.90 (90.99.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 01:33:13.967468 2026] [security2:error] [pid 22884:tid 22884] [client 34.84.99.90:43406] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.llaira.com"] [uri "/.htpasswd"] [unique_id "ar3wmUJ0Gi4X9_M1fAUjPAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 05:03:18
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.84.99.90 (90.99.84.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.99.90 (90.99.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 01:03:13.073628 2026] [security2:error] [pid 32204:tid 32204] [client 34.84.99.90:53182] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.loneoakhoney.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "ar3pkbtSzD5v6NxPAf72-gAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 04:13:47
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.84.99.90 (90.99.84.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.99.90 (90.99.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 00:13:43.462924 2026] [security2:error] [pid 9925:tid 9925] [client 34.84.99.90:48812] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.oxfordgliding.com"] [uri "/dist../.env"] [unique_id "ar3d91UnXF4CWdjaHK_jZwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-10-01 03:47:24
(1 day ago)
165 requests with url.path */@fs/*
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-01 00:55:00
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.84.99.90 (90.99.84.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.84.99.90 (90.99.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 20:54:55.458475 2026] [security2:error] [pid 30780:tid 30889] [client 34.84.99.90:44488] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||philacentric.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "philacentric.com"] [uri "/z9x8c7v6b5-debug-trigger-philacentric.com"] [unique_id "ar2vX9JT9AfPgJAjW-63pAAAAdc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
kosada.com
2026-10-01 00:50:38
(1 day ago)
Repeated exploit attempts, for example: /api/graphql {x22queryx22:x22{ __schema { types { name field ...
show more
Repeated exploit attempts, for example: /api/graphql {x22queryx22:x22{ __schema { types { name fields { name args { name defaultValue } } } } }x22} (HTTP/2.0 port 443, user agent: "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36")
show less
Web App Attack
๐บ๐ธ
JustMeHere
2026-10-01 00:41:31
(1 day ago)
[Wed Sep 30 20:41:26.593861 2026] [security2:error] [pid 794:tid 913] [client 34.84.99.90:38530] Mod ...
show more
[Wed Sep 30 20:41:26.593861 2026] [security2:error] [pid 794:tid 913] [client 34.84.99.90:38530] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.15.0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "login2.yorknation.com"] [uri "/"] [unique_id "ar2sNmsAeERpDBes91Y3TAAAAAo"]
...
show less
Web App Attack
๐ฉ๐ช
bazter.pro
2026-09-30 23:27:28
(1 day ago)
Fail2Ban: plesk-bot-aggressive - 15 failures
Port Scan
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-09-30 23:22:01
(1 day ago)
Wordlist path sweep | method: GET | path: /webpack-stats.json, /static/manifest.json, /dist/manifest ...
show more
Wordlist path sweep | method: GET | path: /webpack-stats.json, /static/manifest.json, /dist/manifest.json (+3 more) | ua: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36 EdgA/152.0.0.0, CCBot/2.0 (https://commoncrawl.org/faq/)
show less
Port Scan
Web App Attack
๐ฎ๐น
VHosting
2026-09-30 22:05:03
(1 day ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ฌ๐ง
blik2108
2026-09-30 20:32:10
(1 day ago)
34.84.99.90 - - [30/Sep/2026:20:32:06 +0000] "GET /z9x8c7v6b5-debug-trigger-old.bigmotive.com HTTP/1 ...
show more
34.84.99.90 - - [30/Sep/2026:20:32:06 +0000] "GET /z9x8c7v6b5-debug-trigger-old.bigmotive.com HTTP/1.1" 404 3431 "-" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)" "-"
34.84.99.90 - - [30/Sep/2026:20:32:07 +0000] "GET /p1u240padeluwicfg38n HTTP/1.1" 404 3431 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)" "-"
34.84.99.90 - - [30/Sep/2026:20:32:07 +0000] "GET /model/info HTTP/1.1" 404 3431 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)" "-"
34.84.99.90 - - [30/Sep/2026:20:32:07 +0000] "GET /jadad0097t76u60km6xb HTTP/1.1" 404 3431 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )" "-"
34.84.99.90 - - [30/Sep/2026:20:32:07 +0000] "GET /build/manifest.json HTTP/1.1" 404 3431 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36" "-"
34.84.99.90 - - [30/Sep/2026:20:32:07 +0000] "POST /lib/terminal-xhr
...
show less
Web App Attack
๐ง๐ช
brechtr
2026-09-30 19:46:09
(1 day ago)
[Press84-BanHammer] 404 flood โ 30 hits in 60s โ Sourced from: brechtryckaert.com โ Request: GET /co ...
show more
[Press84-BanHammer] 404 flood โ 30 hits in 60s โ Sourced from: brechtryckaert.com โ Request: GET /configuration.js
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
raph
2026-09-30 15:04:45
(1 day ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack