πΊπΈ
xKaramx
2026-09-01 12:03:33
(37 minutes ago)
HTTP honeypot (internet-facing deception server) observed 27 request(s) from this address. Observed: ...
show more
HTTP honeypot (internet-facing deception server) observed 27 request(s) from this address. Observed: git repository and credential file harvesting; environment/secrets file harvesting; login endpoint brute-force attempts. Reported automatically from honeypot telemetry.
show less
Hacking
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-31 10:19:12
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.96.36.80 (80.36.96.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.96.36.80 (80.36.96.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 06:19:05.643701 2026] [security2:error] [pid 9203:tid 9203] [client 34.96.36.80:41123] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.142"] [uri "/.htaccessb74b2c0c8a0643dca9862bec6922eeee3766f5612b784bf49465e31e055fd0ca76480670edfd421aa0fae3013884cca6"] [unique_id "apVVGeilm3LUPpOa1K-BFwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³πΏ
Antinson
2026-08-31 09:52:18
(1 day ago)
Requests to unauthorized or suspicious endpoints (.git, .well-known, .php, etc.)
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-08-31 09:34:29
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.96.36.80 (80.36.96.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.96.36.80 (80.36.96.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 05:34:25.534570 2026] [security2:error] [pid 28802:tid 28802] [client 34.96.36.80:10782] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.105"] [uri "/.htaccesscfc956fcc7544cef8395550b190a1409"] [unique_id "apVKodXvUAOx8yi5QhjIwwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-31 08:49:32
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.96.36.80 (80.36.96.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.96.36.80 (80.36.96.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 04:49:26.597712 2026] [security2:error] [pid 25682:tid 25682] [client 34.96.36.80:32742] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.151.9"] [uri "/.htaccesseccef74435ac4571903efe6dbd499feb"] [unique_id "apVAFpM1gO-ArAcQKU5n9wAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¦πΊ
AWW-Admin
2026-08-31 04:03:00
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted] 34.96.36.80 (US/United States/80.36.96. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.96.36.80 (US/United States/80.36.96.34.bc.googleusercontent.com)
show less
SQL Injection
πΊπΈ
jfz-abuse
2026-08-30 23:51:50
(1 day ago)
fail2ban: apache-php-recon
...
Web App Attack
Anonymous
2026-08-30 22:11:38
(1 day ago)
Web Server Enforcement Violation.
Hacking
πΊπΈ
xKaramx
2026-08-30 06:03:32
(2 days ago)
HTTP honeypot (internet-facing deception server) observed 27 request(s) from this address. Observed: ...
show more
HTTP honeypot (internet-facing deception server) observed 27 request(s) from this address. Observed: git repository and credential file harvesting; environment/secrets file harvesting; login endpoint brute-force attempts. Reported automatically from honeypot telemetry.
show less
Hacking
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
akasolutions.de
2026-08-29 04:22:29
(3 days ago)
(mod_security) mod_security triggered on hostname [redacted] 34.96.36.80 (US/United States/80.36.96. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.96.36.80 (US/United States/80.36.96.34.bc.googleusercontent.com)
show less
SQL Injection
πΊπΈ
xKaramx
2026-08-29 00:04:18
(3 days ago)
HTTP honeypot (internet-facing deception server) observed 27 request(s) from this address. Observed: ...
show more
HTTP honeypot (internet-facing deception server) observed 27 request(s) from this address. Observed: git repository and credential file harvesting; environment/secrets file harvesting; login endpoint brute-force attempts. Reported automatically from honeypot telemetry.
show less
Hacking
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-28 14:43:04
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.96.36.80 (80.36.96.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.96.36.80 (80.36.96.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 10:42:55.932735 2026] [security2:error] [pid 8592:tid 8592] [client 34.96.36.80:18608] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.15"] [uri "/.htaccess678f74281d424f918360ffc312a608fb"] [unique_id "apGebzeYqHFS4Splw1nJWgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
xKaramx
2026-08-27 18:01:14
(4 days ago)
HTTP honeypot (internet-facing deception server) observed 27 request(s) from this address. Observed: ...
show more
HTTP honeypot (internet-facing deception server) observed 27 request(s) from this address. Observed: git repository and credential file harvesting; environment/secrets file harvesting; login endpoint brute-force attempts. Reported automatically from honeypot telemetry.
show less
Hacking
Brute-Force
Bad Web Bot
Web App Attack
πΈπ¬
rocky limit
2026-08-27 12:33:30
(5 days ago)
Fail2ban jail 'nginx-badbots' - 2 failed attempts
Port Scan
Hacking
π¨π±
ovallevelasquezanibal
2026-08-27 12:00:22
(5 days ago)
Detectado por Wazuh SIEM en api-ux.com | Alertas: 327 | Nivel max: 10 | Agentes: web-apiux-2025 | Mu ...
show more
Detectado por Wazuh SIEM en api-ux.com | Alertas: 327 | Nivel max: 10 | Agentes: web-apiux-2025 | Multiple web server 400 error codes from same source ip.; Suspicious URL access.; Web server 400 error code.
show less
Web App Attack