๐ฌ๐ง
poundawebsiteltd
2026-06-10 20:22:43
(1 week ago)
Malicious activity in apache-honeypot. Evidence: Automated block: Evidence found in system journals ...
show more
Malicious activity in apache-honeypot. Evidence: Automated block: Evidence found in system journals but could not be parsed.
show less
Brute-Force
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-06-08 22:07:04
(2 weeks ago)
Auto-ban: >3000 req/min op 2026-06-08
Web App Attack
SSH
Hacking
๐ซ๐ท
masterguru
2026-06-08 14:27:08
(2 weeks ago)
Restricted File Access Attempt. Matched phrase ".aws/" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
๐ท๐ด
iulianh
2026-06-08 10:29:22
(2 weeks ago)
*
Brute-Force
SSH
๐ซ๐ฎ
indev.fi
2026-06-08 07:56:59
(2 weeks ago)
aidemoc.peltopiri.com 35.237.110.117 - - [08/Jun/2026:10:56:00 +0300] "GET /.gitlab-ci.yml HTTP/1.1" ...
show more
aidemoc.peltopiri.com 35.237.110.117 - - [08/Jun/2026:10:56:00 +0300] "GET /.gitlab-ci.yml HTTP/1.1" 444 0 "-" "SearchExpress"
aidemoc.peltopiri.com 35.237.110.117 - - [08/Jun/2026:10:56:00 +0300] "GET /.github/workflows/deploy.yml HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.25 Safari/537.36 Core/1.70.3722.400 QQBrowser/10.5.3763.400"
aidemoc.peltopiri.com 35.237.110.117 - - [08/Jun/2026:10:56:00 +0300] "GET /.github/workflows/main.yml HTTP/1.1" 444 0 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 12_4 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/12.1.2 Mobile/15E148 Safari/604.1"
...
show less
Port Scan
Hacking
Bad Web Bot
Web App Attack
๐ธ๐ช
konseptit
2026-06-08 07:25:56
(2 weeks ago)
(mod_security) mod_security triggered on hostname [redacted] 35.237.110.117 (US/United States/117.11 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.237.110.117 (US/United States/117.110.237.35.bc.googleusercontent.com)
show less
SQL Injection
๐บ๐ธ
mnsf
2026-06-08 07:07:51
(2 weeks ago)
Too many Status 40X (11)
Scanning/Probing (61)
Request Overload (383)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 06:32:41
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 35.237.110.117 (117.110.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.237.110.117 (117.110.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 02:32:33.806990 2026] [security2:error] [pid 14374:tid 14374] [client 35.237.110.117:45572] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kotelbarmitzvah.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kotelbarmitzvah.com"] [uri "/.config/gcloud/credentials.db"] [unique_id "aiZiAUGGLa5lYGK3rxsK0gAAAEI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Octopuce
2026-06-08 06:12:33
(2 weeks ago)
Aggressive web search of vulnerable pages: /phpinfo.php /info.php /php.php /debug.php /phptest.php / ...
show more
Aggressive web search of vulnerable pages: /phpinfo.php /info.php /php.php /debug.php /phptest.php /api/phpinfo.php /config.php /configuration. ...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 05:50:27
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 35.237.110.117 (117.110.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.237.110.117 (117.110.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 01:50:24.099646 2026] [security2:error] [pid 32047:tid 32047] [client 35.237.110.117:59996] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.antoniocobo.net|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.antoniocobo.net"] [uri "/.config/gcloud/credentials.db"] [unique_id "aiZYINnQR9QBL6dpx0qP-gAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-06-08 03:04:20
(2 weeks ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 03:02:58
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 35.237.110.117 (117.110.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.237.110.117 (117.110.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 07 23:02:55.300215 2026] [security2:error] [pid 10948:tid 10965] [client 35.237.110.117:45236] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||barkdullit.com.ceol.us|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "barkdullit.com.ceol.us"] [uri "/database.ini"] [unique_id "aiYw35OpamBTYxS72hYjdAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
masterguru
2026-06-08 02:45:04
(2 weeks ago)
BAD BOT - Detected and Blocked.. Matched phrase "baidu" at REQUEST_HEADERS:User-Agent. (1100000-169)
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-08 02:42:11
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 35.237.110.117 (117.110.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.237.110.117 (117.110.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 07 22:42:04.984447 2026] [security2:error] [pid 23318:tid 23318] [client 35.237.110.117:35694] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||hteca.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "hteca.com"] [uri "/.config/gcloud/credentials.db"] [unique_id "aiYr_CAgs5pQqz-U0npebAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
lns.bz
2026-06-08 02:24:14
(2 weeks ago)
Web app attack [PL.Lu]
Exploited Host
Web App Attack