๐ฌ๐ง
thetomtaylor.co.uk
2026-10-02 07:08:02
(2 days ago)
Fail2Ban - [WAF]ModSecurity OWASP CRS rule violation on nginx-modsecurity ... [ice01,ice02,wa01,wa02 ...
show more
Fail2Ban - [WAF]ModSecurity OWASP CRS rule violation on nginx-modsecurity ... [ice01,ice02,wa01,wa02]
show less
Hacking
SQL Injection
Web App Attack
๐ฎ๐ช
tarlabs
2026-10-02 06:33:15
(2 days ago)
IP banned by Fail2Ban (traefik-404 jail)
Web App Attack
๐ซ๐ฎ
Christopher Hughes
2026-10-02 06:12:33
(2 days ago)
35.243.43.206 - - [02/Oct/2026:07:12:33 +0100] "GET /staging/.env HTTP/2.0" 401 410 "-" "Mozilla/5.0 ...
show more
35.243.43.206 - - [02/Oct/2026:07:12:33 +0100] "GET /staging/.env HTTP/2.0" 401 410 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
...
show less
Web App Attack
๐ง๐ช
taivas.nl
2026-10-02 04:33:27
(2 days ago)
Many_bad_calls
Web App Attack
๐ฆ๐บ
AWW-Admin
2026-10-02 04:19:21
(2 days ago)
(mod_security) mod_security triggered on hostname [redacted] 35.243.43.206 (US/United States/206.43. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.243.43.206 (US/United States/206.43.243.35.bc.googleusercontent.com)
show less
SQL Injection
๐ซ๐ฎ
Christopher Hughes
2026-10-02 04:12:14
(2 days ago)
35.243.43.206 - - [02/Oct/2026:05:12:13 +0100] "GET /api/env HTTP/2.0" 401 410 "-" "Mozilla/5.0 (com ...
show more
35.243.43.206 - - [02/Oct/2026:05:12:13 +0100] "GET /api/env HTTP/2.0" 401 410 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 03:33:48
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.243.43.206 (206.43.243.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.243.43.206 (206.43.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 23:33:44.671752 2026] [security2:error] [pid 32092:tid 32092] [client 35.243.43.206:34036] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.whatireallydid.com"] [uri "/media../.env"] [unique_id "ar8mGE856lb8swgVkwtXogAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
wassita
2026-10-02 02:04:24
(2 days ago)
automated scan probing for sensitive/config files โ requested path: /.bashrc โ response: 404
Bad Web Bot
Web App Attack
๐ฉ๐ช
arnisolutions
2026-10-02 01:44:10
(2 days ago)
Vulnerability scanning (requests for admin panels, shells, backup files etc.) against a production s ...
show more
Vulnerability scanning (requests for admin panels, shells, backup files etc.) against a production server. Observed on 1 day(s) between 2026-10-02 and 2026-10-02 (UTC). Sample request: GET /auth.json HTTP/2.0
show less
Web App Attack
Hacking
Anonymous
2026-10-02 01:37:33
(2 days ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 01:11:23
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 35.243.43.206 (206.43.243.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.243.43.206 (206.43.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 21:11:16.399754 2026] [security2:error] [pid 2349:tid 2349] [client 35.243.43.206:49684] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||whaletailpuckerbutt.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "whaletailpuckerbutt.com"] [uri "/z9x8c7v6b5-debug-trigger-whaletailpuckerbutt.com"] [unique_id "ar8EtKfTPB9YnV9mr1SvfAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
andypiper
2026-10-02 01:01:05
(2 days ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
๐ซ๐ฎ
Christopher Hughes
2026-10-02 00:52:52
(2 days ago)
35.243.43.206 - - [02/Oct/2026:01:52:52 +0100] "GET /pages/index.astro.mjs.map HTTP/2.0" 401 410 "-" ...
show more
35.243.43.206 - - [02/Oct/2026:01:52:52 +0100] "GET /pages/index.astro.mjs.map HTTP/2.0" 401 410 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 00:48:38
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.243.43.206 (206.43.243.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.243.43.206 (206.43.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 20:48:30.645586 2026] [security2:error] [pid 17944:tid 17944] [client 35.243.43.206:48612] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wethepeoplealliance.org"] [uri "/.htpasswd"] [unique_id "ar7_Xkh6UKZluTx8Z-ZUpgAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
Christopher Hughes
2026-10-02 00:15:04
(2 days ago)
35.243.43.206 - - [02/Oct/2026:01:15:04 +0100] "GET /appsettings.Production.json HTTP/2.0" 401 410 " ...
show more
35.243.43.206 - - [02/Oct/2026:01:15:04 +0100] "GET /appsettings.Production.json HTTP/2.0" 401 410 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
...
show less
Web App Attack