๐ฉ๐ช
IVski.com
2026-10-11 19:53:22
(2 hours ago)
IVski WAF | Suspicious activity detected - generic bot or scanner pattern
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
Shouddy Tarano
2026-10-10 12:56:41
(1 day ago)
[Sat Oct 10 06:56:34.668733 2026] [authz_core:error] [pid 262928:tid 139791505020672] [client 35.231 ...
show more
[Sat Oct 10 06:56:34.668733 2026] [authz_core:error] [pid 262928:tid 139791505020672] [client 35.231.18.164:56294] AH01630: client denied by server configuration: /var/www/ccmApi/public/api
[Sat Oct 10 06:56:38.310844 2026] [authz_core:error] [pid 290036:tid 139792301868800] [client 35.231.18.164:58082] AH01630: client denied by server configuration: /var/www/ccmApi/public/.env.production::$DATA
[Sat Oct 10 06:56:39.976861 2026] [authz_core:error] [pid 290036:tid 139792385795840] [client 35.231.18.164:58380] AH01630: client denied by server configuration: /var/www/ccmApi/public/pages
[Sat Oct 10 06:56:40.220721 2026] [authz_core:error] [pid 290036:tid 139792301868800] [client 35.231.18.164:58470] AH01630: client denied by server configuration: /var/www/ccmApi/public/secrets.json
[Sat Oct 10 06:56:40.524979 2026] [authz_core:error] [pid 290036:tid 139792285083392] [client 35.231.18.164:58576] AH01630: client denied by server configuration: /var/www/ccmApi/public/src
...
show less
DDoS Attack
Web Spam
Brute-Force
Web App Attack
๐ฉ๐ช
TheDjRider
2026-10-10 12:42:26
(1 day ago)
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban tri ...
show more
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban triggered. Detection time (UTC): 2026-10-10T12:42:25.154551477Z. Context: http_status=200
show less
Web App Attack
๐บ๐ธ
MakoWish
2026-10-10 11:54:25
(1 day ago)
Fuzzing for misconfigured web servers.
Hacking
Web App Attack
๐ซ๐ฎ
albionfreemarket.com
2026-10-10 11:35:04
(1 day ago)
35.231.18.164 - - [10/Oct/2026:11:35:03 +0000] "GET /console HTTP/2.0" 403 555 "-" "Mozilla/5.0 (Win ...
show more
35.231.18.164 - - [10/Oct/2026:11:35:03 +0000] "GET /console HTTP/2.0" 403 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36" 0.000 "-" "US"
35.231.18.164 - - [10/Oct/2026:11:35:03 +0000] "POST /graphql HTTP/2.0" 403 555 "https://api.albionfreemarket.com" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36" 0.000 "-" "US"
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-10-10 09:01:33
(1 day ago)
malicious scanning tool activity
Web App Attack
๐ณ๐ฑ
Site.eu
2026-10-10 05:00:23
(1 day ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
CDO
2026-10-10 04:50:46
(1 day ago)
URL Injection attempt detected. Automated web attack.
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-10 04:49:00
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.231.18.164 (164.18.231.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.231.18.164 (164.18.231.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 00:48:56.662268 2026] [security2:error] [pid 18307:tid 18307] [client 35.231.18.164:38018] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||spyasociados.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "spyasociados.com"] [uri "/z9x8c7v6b5-debug-trigger-spyasociados.com"] [unique_id "asnDuAkVZop5jVD_17O78QAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-10-10 03:49:29
(1 day ago)
20 attempts against mh-misbehave-ban on pavo
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
pachec
2026-10-10 02:21:15
(1 day ago)
Automated vulnerability scanning blocked by fail2ban
Web App Attack
Hacking
๐ฉ๐ช
zUnlegit
2026-10-10 02:14:26
(1 day ago)
Automated web scanner requested sensitive path: /.ssh/id_rsa
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-10 01:55:22
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.231.18.164 (164.18.231.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.231.18.164 (164.18.231.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 21:55:17.928295 2026] [security2:error] [pid 17415:tid 17415] [client 35.231.18.164:52382] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||joesteiner.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "joesteiner.com"] [uri "/z9x8c7v6b5-debug-trigger-joesteiner.com"] [unique_id "asmbBTfHKMDdGFQAJQ4ikAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
JLKnoch Software GmbH
2026-10-10 01:51:48
(1 day ago)
CrowdSec crowdsecurity/http-probing
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-10 01:23:58
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.231.18.164 (164.18.231.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.231.18.164 (164.18.231.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 21:23:53.919769 2026] [security2:error] [pid 4283:tid 4283] [client 35.231.18.164:34284] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||instantanything.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "instantanything.com"] [uri "/z9x8c7v6b5-debug-trigger-instantanything.com"] [unique_id "asmTqRK5xS125XXOyJNxrgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack