๐ซ๐ท
andreighitan
2026-06-12 11:18:53
(1 day ago)
Coordinated attack against 84.46.253.134. Webshell scanning, PHPUnit RCE, credential harvesting, PHP ...
show more
Coordinated attack against 84.46.253.134. Webshell scanning, PHPUnit RCE, credential harvesting, PHP vuln scanning. Active June 7-11 2026. ZAC Bayern ref BY0257-500359-26/8.
show less
Web App Attack
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-08 16:18:17
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 34.93.59.72 (72.59.93.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.93.59.72 (72.59.93.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 12:18:09.760508 2026] [security2:error] [pid 8226:tid 8226] [client 34.93.59.72:49696] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ikutabukkyokai.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ikutabukkyokai.com"] [uri "/.config/gcloud/credentials.db"] [unique_id "aibrQQ79JtXaxUbMFR57aQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-08 14:39:59
(5 days ago)
Aggressive web scan
Web App Attack
๐ธ๐ช
nekopavel
2026-06-08 13:22:24
(5 days ago)
34.93.59.72 - - [08/Jun/2026:15:22:21 +0200]"GET /.aws/config HTTP/1.1" 404 804"-" de3.dorito.pavel. ...
show more
34.93.59.72 - - [08/Jun/2026:15:22:21 +0200]"GET /.aws/config HTTP/1.1" 404 804"-" de3.dorito.pavel.gg "Opera/8.01 (J2ME/MIDP; Opera Mini/1.0.1479/HiFi; SonyEricsson P900; no; U; ssr)""0.000" "-""Mumbai" "IN"
34.93.59.72 - - [08/Jun/2026:15:22:21 +0200]"GET /aws.json HTTP/1.1" 404 804"-" de3.dorito.pavel.gg "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:52.0) Gecko/20100101 Firefox/52.0""0.000" "-""Mumbai" "IN"
34.93.59.72 - - [08/Jun/2026:15:22:21 +0200]"GET /aws_credentials.json HTTP/1.1" 404 804"-" de3.dorito.pavel.gg "NokiaN73-1/3.0649.0.0.1 Series60/3.0 Profile/MIDP2.0 Configuration/CLDC-1.1""0.000" "-""Mumbai" "IN"
...
show less
Hacking
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-06-08 12:53:47
(5 days ago)
20 attempts against mh-misbehave-ban on yam
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-06-08 11:46:39
(5 days ago)
Excessive 404/403 errors
Brute-Force
๐บ๐ฆ
URAN Publishing Service
2026-06-08 11:16:57
(5 days ago)
34.93.59.72 - - [08/Jun/2026:14:16:42 +0300] "GET /config.env HTTP/1.1" 404 3331 "-" "Avant Browser/ ...
show more
34.93.59.72 - - [08/Jun/2026:14:16:42 +0300] "GET /config.env HTTP/1.1" 404 3331 "-" "Avant Browser/1.2.789rel1 (http://www.avantbrowser.com)"
34.93.59.72 - - [08/Jun/2026:14:16:45 +0300] "GET /secrets.env HTTP/1.1" 404 3333 "-" "Mozilla/5.0 (iPad; CPU OS 12_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/76.0.3809.81 Mobile/15E148 Safari/605.1"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 04:22:19
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 34.93.59.72 (72.59.93.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.93.59.72 (72.59.93.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 00:22:13.806613 2026] [security2:error] [pid 12527:tid 12527] [client 34.93.59.72:53780] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||bookonline.lakewoodranchhairsalon.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bookonline.lakewoodranchhairsalon.com"] [uri "/.config/gcloud/credentials.db"] [unique_id "aiZDdejeMusRZHyL4yTsdwAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-06-08 03:55:04
(5 days ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐ซ๐ท
dynamix
2026-06-08 02:18:35
(5 days ago)
Multiple WAF Violations
Web App Attack