Anonymous
2026-10-02 06:05:18
(3 days ago)
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: BR, Attack patterns: Back ...
show more
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: BR, Attack patterns: Backup file probing, Cloud secrets probing, Directory traversal
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
[email protected]
2026-10-01 07:06:17
(4 days ago)
CrowdSec ban: crowdsecurity/unifi-flood-detection (duration: 71h59m51s)
Port Scan
๐ฉ๐ช
yvoictra
2026-10-01 06:20:08
(4 days ago)
Bloqueado automรกticamente por CrowdSec. Escenario: crowdsecurity/http-probing
Web App Attack
Anonymous
2026-10-01 05:10:33
(4 days ago)
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: BR, Attack patterns: Back ...
show more
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: BR, Attack patterns: Backup file probing, Cloud secrets probing, Directory traversal
show less
Bad Web Bot
Web App Attack
๐ท๐ด
iulianh
2026-10-01 03:03:22
(4 days ago)
80,443
Brute-Force
SSH
๐บ๐ธ
CDO
2026-10-01 01:58:03
(4 days ago)
URL Injection attempt detected. Automated web attack.
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 01:57:57
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.95.136.90 (90.136.95.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.95.136.90 (90.136.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 21:57:52.784159 2026] [security2:error] [pid 7805:tid 7805] [client 34.95.136.90:44878] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.randeen.com"] [uri "/.htpasswd"] [unique_id "ar2-IFkusoal0L0qIzvOZwAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 01:40:49
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 34.95.136.90 (90.136.95.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.95.136.90 (90.136.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 21:40:45.027314 2026] [security2:error] [pid 9047:tid 9047] [client 34.95.136.90:34190] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||marklex.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "marklex.com"] [uri "/z9x8c7v6b5-debug-trigger-marklex.com"] [unique_id "ar26HTDb-EzAQgbMm6L9PQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 00:28:21
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 34.95.136.90 (90.136.95.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.95.136.90 (90.136.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 20:28:14.819287 2026] [security2:error] [pid 14569:tid 14569] [client 34.95.136.90:53764] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||m.bluegrassexpressband.com|F|2"] [data ".bluegrassexpressband.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "m.bluegrassexpressband.com"] [uri "/z9x8c7v6b5-debug-trigger-m.bluegrassexpressband.com"] [unique_id "ar2pHuTk-AtbZOVI8-hZ9AAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
[email protected]
2026-09-30 23:40:28
(4 days ago)
CrowdSec ban: crowdsecurity/http-crawl-non_statics (duration: 72h0m0s)
Web App Attack
๐ฌ๐ง
consul.to
2026-09-30 18:14:41
(4 days ago)
Web attack/malicious scanning detected
Web App Attack
๐ซ๐ท
dynamix
2026-09-30 17:47:13
(4 days ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 12:57:12
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 34.95.136.90 (90.136.95.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.95.136.90 (90.136.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 08:57:07.787036 2026] [security2:error] [pid 13116:tid 13116] [client 34.95.136.90:60374] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.gisur.com|F|2"] [data ".gisur.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.gisur.com"] [uri "/z9x8c7v6b5-debug-trigger-www.gisur.com"] [unique_id "ar0HI5MlKjujtyECHfyDUwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
mscode.pl
2026-09-30 09:58:27
(5 days ago)
Triggered Cloudflare WAF (firewallCustom) from BR.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Prot ...
show more
Triggered Cloudflare WAF (firewallCustom) from BR.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/2 (POST method)
Zone: r2.lsstories.com:8443
Endpoint: /index.php
UA: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )
show less
Bad Web Bot
๐ณ๐ฑ
EGP Abuse Dept
2026-09-30 09:47:26
(5 days ago)
Unauthorized connection to proxy port 8080
Port Scan
Hacking