🇲🇽
octageeks.com
2026-09-14 04:09:36
(7 hours ago)
Wordpress malicious attack:[octablocked]
Web App Attack
Anonymous
2026-09-13 18:05:06
(17 hours ago)
WAF repeated trigger detected by Fail2Ban
Web App Attack
🇳🇱
MM-bot
2026-09-13 17:00:20
(18 hours ago)
URL-probe: HTTP/2 GET request on /wp-json (2026-09-13 19:00:20 UTC+2)
Web App Attack
Hacking
🇳🇱
Site.eu
2026-09-13 16:38:04
(18 hours ago)
Excessive 404/403 errors
Brute-Force
🇺🇸
TPI-Abuse
2026-09-13 15:24:19
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.245.119.87 (87.119.245.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.245.119.87 (87.119.245.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 11:24:11.167789 2026] [security2:error] [pid 26835:tid 26856] [client 35.245.119.87:59246] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pamper.com"] [uri "/%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env"] [unique_id "aqbAG6FNe8vfFkYLc5PLVAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 15:02:15
(20 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.245.119.87 (87.119.245.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.245.119.87 (87.119.245.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 11:02:11.190195 2026] [security2:error] [pid 5787:tid 5787] [client 35.245.119.87:34422] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||paleopathologist.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "paleopathologist.com"] [uri "/z9x8c7v6b5-debug-trigger-paleopathologist.com"] [unique_id "aqa688QA-D6kHjmBrddcYgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-13 15:00:43
(20 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇫🇷
ecode hosting
2026-09-13 14:59:04
(20 hours ago)
Domain : paksoyteknikdestek.com
Rule : env
2026-09-13 14:56:40 10.100.1.20 GET /css../.env - 443 - 3 ...
show more
Domain : paksoyteknikdestek.com
Rule : env
2026-09-13 14:56:40 10.100.1.20 GET /css../.env - 443 - 35.245.119.87 HTTP/2 Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] ) - paksoyteknikdestek.com 200 0 0 109 448 181 - -
show less
Hacking
SQL Injection
🇺🇸
TPI-Abuse
2026-09-13 14:42:44
(20 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.245.119.87 (87.119.245.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.245.119.87 (87.119.245.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 10:42:38.153427 2026] [security2:error] [pid 19730:tid 19730] [client 35.245.119.87:57758] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||paihianz.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "paihianz.com"] [uri "/z9x8c7v6b5-debug-trigger-paihianz.com"] [unique_id "aqa2XhPt-7myuKM_vKNAugAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇦
polycoda
2026-09-13 14:37:06
(20 hours ago)
🔥 VERY AGGRESSIVE SCANNER probed over 500 inexistent files and PHP scripts in less than an hour.
Hacking
Web App Attack
🇩🇪
ramazan
2026-09-13 13:58:14
(21 hours ago)
Fail2Ban: nginx-4xx | Failures: 10 | Log: /.vite/manifest.json /@fs/proc/self/cwd/.env?raw?? /@fs/va ...
show more
Fail2Ban: nginx-4xx | Failures: 10 | Log: /.vite/manifest.json /@fs/proc/self/cwd/.env?raw?? /@fs/var/task/.env?raw?? /admin%2F.env /build/manifest.json
show less
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-13 13:33:17
(21 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.245.119.87 (87.119.245.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.245.119.87 (87.119.245.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 09:33:11.069582 2026] [security2:error] [pid 4959:tid 4959] [client 35.245.119.87:52880] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||owenmail.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "owenmail.com"] [uri "/z9x8c7v6b5-debug-trigger-owenmail.com"] [unique_id "aqamF55PafaW8GWL9CjM_AAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
interbiznw.com
2026-09-13 13:12:36
(22 hours ago)
malicious-web-requests-vulnerability-scanning
Hacking
Brute-Force
Exploited Host
Web App Attack
🇺🇸
Penny Packer
2026-09-13 13:08:01
(22 hours ago)
Fail2Ban apache-tripwires
Web App Attack
🇨🇦
polycoda
2026-09-13 13:04:28
(22 hours ago)
AutoBlock: 🎯 Vulnerability Scanner (Non Decay-Based) - ⚙️ Configuration File Access (Non Decay-Based ...
show more
AutoBlock: 🎯 Vulnerability Scanner (Non Decay-Based) - ⚙️ Configuration File Access (Non Decay-Based) - 📊 Admin Panel Scanning (Decay-Based)
show less
Hacking
Bad Web Bot
Web App Attack