๐ฒ๐ฝ
octageeks.com
2026-10-06 04:19:57
(11 hours ago)
Wordpress malicious attack:[octaflood]
Web App Attack
๐ฉ๐ช
XICTRON
2026-10-05 18:20:09
(20 hours ago)
ModSecurity rule violation detected by Fail2Ban
Web App Attack
๐บ๐ธ
solantex
2026-10-05 15:14:56
(1 day ago)
Unauthorized automated scanning and reconnaissance against Solantex resources. No crawl, scan or tes ...
show more
Unauthorized automated scanning and reconnaissance against Solantex resources. No crawl, scan or test permission has been granted to this source.
show less
Web App Attack
๐ฉ๐ช
Sรฉfora Srl
2026-10-05 12:27:45
(1 day ago)
crowdsecurity/http-sensitive-files detected by CrowdSec
Web App Attack
๐ช๐ธ
robotstxt
2026-10-05 11:14:48
(1 day ago)
35.231.150.184 - - [05/Oct/2026:11:14:38 +0000] "GET /z9x8c7v6b5-debug-trigger-monteroespinosaonline ...
show more
35.231.150.184 - - [05/Oct/2026:11:14:38 +0000] "GET /z9x8c7v6b5-debug-trigger-monteroespinosaonline.com HTTP/2.0" 403 22214 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" "-" edge="35.231.150.184"
35.231.150.184 - - [05/Oct/2026:11:14:38 +0000] "GET /.vite/manifest.json HTTP/2.0" 403 21587 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "-" edge="35.231.150.184"
35.231.150.184 - - [05/Oct/2026:11:14:38 +0000] "GET /dist/manifest.json HTTP/2.0" 403 21587 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "-" edge="35.231.150.184"
35.231.150.184 - - [05/Oct/2026:11:14:38 +0000] "GET /build/manifest.json HTTP/2.0" 403 21587 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "-" edge="35.231.150.184"
35.231.150.184 - - [05/Oct/2026:11:14:38 +0000] "GET /dis
...
show less
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-05 11:09:45
(1 day ago)
[ti-05al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-05al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 35.231.150.184 - - [05/Oct/2026:13:09:38 +0200] "GET /.ssh/id_rsa HTTP/2.0" 403 346 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
MaxSmartCode
2026-10-05 11:09:12
(1 day ago)
Credential brute-force attacks on webpage.
Brute-Force
SSH
๐ช๐ธ
robotstxt
2026-10-05 10:43:33
(1 day ago)
35.231.150.184 - - [05/Oct/2026:10:42:38 +0000] "GET /wp-content/cache/autoptimize/js/autoptimize_c0 ...
show more
35.231.150.184 - - [05/Oct/2026:10:42:38 +0000] "GET /wp-content/cache/autoptimize/js/autoptimize_c0a7994c5aa3fec626476e359cdabc89.js HTTP/2.0" 403 165 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "-" edge="35.231.150.184"
35.231.150.184 - - [05/Oct/2026:10:42:39 +0000] "GET /?370cd1=07dad60dc6.js& HTTP/2.0" 403 2 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "-" edge="35.231.150.184"
35.231.150.184 - - [05/Oct/2026:10:42:39 +0000] "GET /wp-content/plugins/autoptimize/classes/external/js/lazysizes.min.js HTTP/2.0" 403 15393 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "-" edge="35.231.150.184"
35.231.150.184 - - [05/Oct/2026:10:42:39 +0000] "GET /wp-includes/js/dist/script-modules/interactivity/index.min.js?ver=efaa5193bbad9c60ffd1 HTTP/2.0" 403 15393 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/5
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 10:10:07
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.231.150.184 (184.150.231.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.231.150.184 (184.150.231.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 06:10:00.242423 2026] [security2:error] [pid 26838:tid 26838] [client 35.231.150.184:49430] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||glaswood.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "glaswood.com"] [uri "/z9x8c7v6b5-debug-trigger-glaswood.com"] [unique_id "asN3ePBcWCMA7AZfdhnA5QAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
svr
2026-10-05 10:06:47
(1 day ago)
Abusive Automated Web Scanner
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 09:23:18
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.231.150.184 (184.150.231.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.231.150.184 (184.150.231.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 05:23:14.379645 2026] [security2:error] [pid 3897205:tid 3897241] [client 35.231.150.184:35624] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||credit-card-cap.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "credit-card-cap.com"] [uri "/z9x8c7v6b5-debug-trigger-credit-card-cap.com"] [unique_id "asNsgmJWho2RCZumZieXLQAAANU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
SwinT
2026-10-05 09:00:04
(1 day ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 06:33:11
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.231.150.184 (184.150.231.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.231.150.184 (184.150.231.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 02:33:02.738186 2026] [security2:error] [pid 28381:tid 28381] [client 35.231.150.184:52416] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||alizakarp.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "alizakarp.com"] [uri "/z9x8c7v6b5-debug-trigger-alizakarp.com"] [unique_id "asNEnsYTrp-MXIVLl3byTAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 06:14:08
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.231.150.184 (184.150.231.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.231.150.184 (184.150.231.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 02:14:00.279780 2026] [security2:error] [pid 23780:tid 23780] [client 35.231.150.184:57160] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "alissacaputo.com"] [uri "/.htpasswd"] [unique_id "asNAKNSPX7tHqaN7TGFVvQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-10-05 05:59:18
(1 day ago)
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .back/ .b ...
show more
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .back/ .backup/ .bak/ .bck/ .bk/ .bkp/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .cnf/ .com/ .compositefont/ .config/ .conf/ .copy/ .crt/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dist/ .dll/ .dos/ .dpkg-dist/ .drv/ .gadget/ .hta/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .inf/ .ini/ .jks/ .jse/ .key/ .licx/ .lnk/ .log/ .mdb/ .msc/ .ocx/ .old/ .pass/ .pdb/ .pfx/ .pif/ .pem/ .pol/ .prf/ .printer/ .pwd/ .rdb/ .rdp/ .reg/ .resources/ .resx/ .sav/ .save/ .scr/ .sct/ .sh/ .shs/ .sql/ .sqlite/ .sqlite3/ .swap/ .swo/ .swp/ .sys/ .temp/ .tfstate/ .tlb/ .tmp/ .vb/ .vbe/ .vbs/ .vbproj/ .vsdisco/ .vxd/ .webinfo/ .ws/ .wsc/ .wsf/ .wsh/ .xsd/ .xsx/" at TX:extension. (920440-193)
show less
Hacking