๐ซ๐ท
masterguru
2026-10-07 10:52:49
(5 hours ago)
Remote Command Execution: Unix Command Injection (command without evasion). Pattern match "(?i)(?:b ...
show more
Remote Command Execution: Unix Command Injection (command without evasion). Pattern match "(?i)(?:b (932235-195)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-07 10:48:04
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.207.78.109 (109.78.207.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.207.78.109 (109.78.207.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 06:48:00.203560 2026] [security2:error] [pid 16610:tid 16610] [client 35.207.78.109:47546] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "elianabeam.com"] [uri "/.git/config"] [unique_id "asYjYJwdhRF5SSxVLUgnUgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-10-07 10:04:10
(5 hours ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-10-07 09:57:44
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.207.78.109 (109.78.207.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.207.78.109 (109.78.207.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 05:57:39.492382 2026] [security2:error] [pid 5704:tid 5704] [client 35.207.78.109:60916] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "elhosting.us"] [uri "/.git/config"] [unique_id "asYXk1Dv7Rkto8ZING4Q6QAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
el-brujo
2026-10-07 09:27:06
(6 hours ago)
07/Oct/2026:11:27:06.091581 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
07/Oct/2026:11:27:06.091581 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 35.207.78.109] ModSecurity: Warning. Pattern match "(?:\\\\\\\\$(?:\\\\\\\\((?:\\\\\\\\(.*\\\\\\\\)|.*)\\\\\\\\)|\\\\\\\\{.*\\\\\\\\})|[<>]\\\\\\\\(.*\\\\\\\\))" at ARGS:0. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "367"] [id "932130"] [msg "Remote Command Execution: Unix Shell Expression Found"] [data "Matched Data: $((41*271)) found within ARGS:0: {then: $1:__proto__:then status: resolved_model reason: -1 value: {then:$b1337} _response: {_prefix: var res=process.mainmodule.require(child_process).execsync(echo $((41*271)) | base64 -w 0).tostring().trim() throw object.assign(new error(next_redirect) {digest: `next_redirect push/login?a=${res} 307 `}) _chunks: $q2 _formdata: {get: $1:constructor:constructor}}}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-shell"] [tag "platform-unix"] [tag "at
...
show less
Hacking
Web App Attack
๐ฉ๐ช
todix
2026-10-07 09:08:51
(6 hours ago)
Wordpress brute force or spam attempt from 35.207.78.109
Brute-Force
๐ต๐ฑ
Budyn
2026-10-05 17:40:37
(1 day ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: dev.goblinpot.online | URI: /.git/config | UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-10-05 15:33:44
(2 days ago)
Excessive 404/403 errors
Brute-Force
Anonymous
2026-10-05 15:20:37
(2 days ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
Anonymous
2026-10-05 14:20:44
(2 days ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
๐ฉ๐ช
gadix
2026-10-05 13:44:13
(2 days ago)
[05/Oct/2026:15:44:10.743991 +0200] asOpqmF7WBTLiJcFmCoL4gAAAAk 35.207.78.109 52736 127.0.0.1 7081
[ ...
show more
[05/Oct/2026:15:44:10.743991 +0200] asOpqmF7WBTLiJcFmCoL4gAAAAk 35.207.78.109 52736 127.0.0.1 7081
[05/Oct/2026:15:44:11.011132 +0200] asOpq_uukAUiuNakjZK_VwAAAAs 35.207.78.109 52764 127.0.0.1 7081
[05/Oct/2026:15:44:11.096148 +0200] asOpq4pqJ_42IGeg5i_4AgAAAAQ 35.207.78.109 52770 127.0.0.1 7081
...
show less
Web App Attack
๐ต๐ฑ
Budyn
2026-10-05 12:38:35
(2 days ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: dev.definitelynotahoneypot.online | URI: /.git/config | UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
Anonymous
2026-10-05 11:18:22
(2 days ago)
apache vulnerability scan
Web App Attack
๐ฎ๐น
VHosting
2026-10-05 11:05:05
(2 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-10-05 08:58:35
(2 days ago)
Blocked by CSF 13 firewall - Rule: config-dotfile
DE/Germany/109.78.207.35.bc.googleusercontent.com
Web App Attack