๐ฉ๐ช
webanyone
2026-06-26 02:45:37
(24 minutes ago)
Apache web server attack detected by Fail2Ban in plesk-apache jail
Web App Attack
๐ฉ๐ช
webanyone
2026-06-26 02:15:38
(54 minutes ago)
Repeated 404 errors, blocked by Fail2ban in custom-404 jail
Bad Web Bot
๐ฌ๐ง
consul.to
2026-06-26 02:12:22
(57 minutes ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-26 02:03:08
(1 hour ago)
(mod_security) mod_security (id:210831) triggered by 35.190.158.51 (51.158.190.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210831) triggered by 35.190.158.51 (51.158.190.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 25 22:03:03.942397 2026] [security2:error] [pid 31757:tid 31757] [client 35.190.158.51:38308] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||wamgirlz.com|F|4"] [data "EmailWolf"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "wamgirlz.com"] [uri "/env"] [unique_id "aj3d13EY3f-7sK-NGFi4sAAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
webanyone
2026-06-26 02:00:37
(1 hour ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-26 01:46:56
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 35.190.158.51 (51.158.190.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.190.158.51 (51.158.190.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 25 21:46:50.933472 2026] [security2:error] [pid 14926:tid 14950] [client 35.190.158.51:33146] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.advantageplus.richardleeweatherman.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.advantageplus.richardleeweatherman.com"] [uri "/.config/gcloud/credentials.db"] [unique_id "aj3aCp1vEo9OZ4oJzpp53QAAAMY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-26 00:56:13
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.190.158.51 (51.158.190.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.190.158.51 (51.158.190.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 25 20:56:09.438028 2026] [security2:error] [pid 1194:tid 1194] [client 35.190.158.51:58562] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||test.aiamur.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "test.aiamur.com"] [uri "/.config/gcloud/credentials.db"] [unique_id "aj3OKU69akPJBsMbKnbKOgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Starburst SysOp Team
2026-06-26 00:52:32
(2 hours ago)
BAD BOT, BAD BOT, WHAT YA GONNA DO - Detected and Blocked.. Matched phrase "MicroMessenger" at REQUE ...
show more
BAD BOT, BAD BOT, WHAT YA GONNA DO - Detected and Blocked.. Matched phrase "MicroMessenger" at REQUEST_HEADERS:User-Agent. (1100000-mnz6-1)
show less
Bad Web Bot
๐ซ๐ท
dynamix
2026-06-25 20:20:40
(6 hours ago)
Multiple WAF Violations
Web App Attack
๐ณ๐ฑ
Savvii
2026-06-25 19:53:24
(7 hours ago)
20 attempts against mh-misbehave-ban on boron
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-06-25 19:04:25
(8 hours ago)
20 attempts against mh-misbehave-ban on acorn
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฟ
Antinson
2026-06-25 16:44:42
(10 hours ago)
Scraping with a high error ratio and request rate
Bad Web Bot
๐ต๐ฑ
TaKeN
2026-06-25 14:08:38
(13 hours ago)
Automated Wazuh local observation. Wazuh rule 31151 lvl=10 detected repeated HTTP web application pr ...
show more
Automated Wazuh local observation. Wazuh rule 31151 lvl=10 detected repeated HTTP web application probing from this source IP. Observed 3 matching blocked event(s) between 2026-06-25T16:08:38+02:00 and 2026-06-25T16:08:38+02:00. Sample requested paths: /api/actuator/configprops, /app/actuator/logfile, /.aws/credentials.
show less
Web App Attack
Hacking