๐ซ๐ฎ
paissangroup
2026-09-23 08:06:42
(5 hours ago)
Multiple WAF Violations
Web App Attack
๐ซ๐ท
masterguru
2026-09-23 06:37:35
(6 hours ago)
Restricted File Access Attempt. Matched phrase "/auth.json" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 02:04:06
(11 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.86.87.240 (240.87.86.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.86.87.240 (240.87.86.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 22:03:59.503713 2026] [security2:error] [pid 12126:tid 12364] [client 34.86.87.240:60684] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ace-es.com|F|2"] [data ".json.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ace-es.com"] [uri "/.codex/auth.json.bak"] [unique_id "arMzjyNxeHD4szQ9UDDxDwAAAU8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 09:49:56
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.86.87.240 (240.87.86.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.86.87.240 (240.87.86.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 05:49:48.825522 2026] [security2:error] [pid 6292:tid 6292] [client 34.86.87.240:36582] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bencurry.curryfirm.com|F|2"] [data ".json.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bencurry.curryfirm.com"] [uri "/.codex/auth.json.bak"] [unique_id "arJPPK9DO5tZDAyMkKF5jQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
MBombeck
2026-09-22 08:36:47
(1 day ago)
Fail2Ban/traefik-botsearch on apps-01: banned after 5 failures
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-22 08:36:35
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ธ
mnsf
2026-09-22 08:05:05
(1 day ago)
Too many Status 40X (11)
Brute-Force
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-08-11 22:00:03
(1 month ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-08-10.
show less
Web App Attack
SSH
Hacking
๐ฌ๐ง
openstrike.co.uk
2026-08-11 05:14:03
(1 month ago)
133 attacks on env grabbing URLs, PHP URLs, config grabbing URLs (type 2), site downloads, password ...
show more
133 attacks on env grabbing URLs, PHP URLs, config grabbing URLs (type 2), site downloads, password grabbing URLs, deployment descriptor URLs:
GET /aws/.env HTTP/1.1
GET /info.php HTTP/1.1
GET /config/gcp.json HTTP/1.1
GET /db.sql HTTP/1.1
GET /pms?module=logging&file_name=../../../../../../.aws/credentials&number_of_lines=10000 HTTP/1.1
GET /WEB-INF/web.xml HTTP/1.1
show less
Hacking
Web App Attack
๐จ๐ฟ
ddw
2026-08-11 03:31:59
(1 month ago)
ModSecurity detection - Rules: 930130(Restricted File Access Attempt)
Web App Attack
๐ฉ๐ช
SiyCah
2026-08-11 03:00:02
(1 month ago)
IP banned by fail2ban; banned in jail apache-modsecurity. Report generated by fail2abuseipdb.
Hacking
Brute-Force
Web App Attack
๐ฉ๐ช
macrob
2026-08-11 02:36:09
(1 month ago)
2026/08/11 02:36:07 [error] 2267767#2267767: *466614585 access forbidden by rule, client: 34.86.87.2 ...
show more
2026/08/11 02:36:07 [error] 2267767#2267767: *466614585 access forbidden by rule, client: 34.86.87.240, server: binixo.pl, request: "GET /.aws/credentials HTTP/2.0", host: "binixo.pl", referrer: "https://www.binixo.pl/.aws/credentials"
2026/08/11 02:36:07 [error] 2267767#2267767: *466614585 access forbidden by rule, client: 34.86.87.240, server: binixo.pl, request: "GET /.env.local HTTP/2.0", host: "binixo.pl", referrer: "https://www.binixo.pl/.env.local"
2026/08/11 02:36:07 [error] 2267766#2267766: *466636900 access forbidden by rule, client: 34.86.87.240, server: binixo.pl, request: "GET /.env HTTP/2.0", host: "binixo.pl", referrer: "https://www.binixo.pl/.env"
...
show less
Web App Attack
๐ณ๐ด
tmiland
2026-08-11 02:27:46
(1 month ago)
(nginx_444) Nginx 444 34.86.87.240 (US/United States/240.87.86.34.bc.googleusercontent.com): 5 in th ...
show more
(nginx_444) Nginx 444 34.86.87.240 (US/United States/240.87.86.34.bc.googleusercontent.com): 5 in the last 3600 secs; IP: 34.86.87.240; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.86.87.240 - - [11/Aug/2026:04:27:45 +0200] "GET /files../etc/passwd HTTP/1.1" 444 0 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot" 34.86.87.240 - - [11/Aug/2026:04:27:45 +0200] "GET /.env HTTP/1.1" 444 0 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot" 34.86.87.240 - - [11/Aug/2026:04:27:45 +0200] "GET /fetch?uri=http%3A%2F%2F169.254.169.254%2Flatest%2Fmeta-data%2F HTTP/1.1" 444 0 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot" 34.86.87.240 - - [11/Aug/2026:04:27:45 +0200] "GET /fetch?uri=http%3A%2F%2F169.254.169.254%2Flatest%2Fmeta-data%2Fiam%2Finfo HTTP/1.1" 444 0 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); co
show less
Brute-Force
๐ฌ๐ง
Aetherweb Ark
2026-08-11 02:05:57
(1 month ago)
(mod_security) mod_security (id:949110) triggered by 34.86.87.240 (US/United States/240.87.86.34.bc. ...
show more
(mod_security) mod_security (id:949110) triggered by 34.86.87.240 (US/United States/240.87.86.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
๐ฎ๐ช
AutosOnShow
2026-08-11 01:59:05
(1 month ago)
blocked for webapp attack | path requested: /pms | seen at 2026-08-11 01:58:22.490 |
Web App Attack