๐ญ๐บ
kranem
2026-10-11 18:00:09
(1 hour ago)
Triggered Cloudflare WAF from US.
Action taken: BLOCK
ASN: 16509 (Amazon.com, Inc.)
Protocol: HTTP/2 ...
show more
Triggered Cloudflare WAF from US.
Action taken: BLOCK
ASN: 16509 (Amazon.com, Inc.)
Protocol: HTTP/2 (GET method)
Endpoint: /
Timestamp: 2026-10-11T16:27:34Z
User-Agent: Mozilla/5.0 (iPhone; CPU iPhone OS 14_0 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0 Mobile/15E148 Safari/604.1
show less
Bad Web Bot
๐ง๐ช
taivas.nl
2026-10-11 17:32:11
(2 hours ago)
Site scraper
Web App Attack
๐บ๐ธ
cwytech
2026-10-11 17:11:00
(2 hours ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: crowdsecurity/http-probing.
Bad Web Bot
Web App Attack
๐ช๐ธ
robotstxt
2026-10-11 17:04:25
(2 hours ago)
44.244.70.94 - - [11/Oct/2026:17:03:37 +0000] "GET /wp-content/plugins/complianz-gdpr/readme.txt HTT ...
show more
44.244.70.94 - - [11/Oct/2026:17:03:37 +0000] "GET /wp-content/plugins/complianz-gdpr/readme.txt HTTP/2.0" 403 27307 "-" "MerchantSecurityScanner/1.0 (+https://stri.pe/go/merchant-security-scanner)" "-" edge="44.244.70.94"
44.244.70.94 - - [11/Oct/2026:17:03:37 +0000] "GET /config.toml HTTP/2.0" 403 27269 "-" "MerchantSecurityScanner/1.0 (+https://stri.pe/go/merchant-security-scanner)" "-" edge="44.244.70.94"
44.244.70.94 - - [11/Oct/2026:17:03:37 +0000] "GET /config.yaml HTTP/2.0" 403 27306 "-" "MerchantSecurityScanner/1.0 (+https://stri.pe/go/merchant-security-scanner)" "-" edge="44.244.70.94"
44.244.70.94 - - [11/Oct/2026:17:03:38 +0000] "GET /config.yml HTTP/2.0" 403 27305 "-" "MerchantSecurityScanner/1.0 (+https://stri.pe/go/merchant-security-scanner)" "-" edge="44.244.70.94"
44.244.70.94 - - [11/Oct/2026:17:03:38 +0000] "GET /app/config.toml HTTP/2.0" 403 27306 "-" "MerchantSecurityScanner/1.0 (+https://stri.pe/go/merchant-security-scanner)" "-" edge="44.244.70.94"
...
show less
Web App Attack
๐บ๐ธ
ruusvuu
2026-10-11 16:57:49
(2 hours ago)
Automated abuse report: 25 attack/probe requests from Amazon.com, Inc. / US.
Targeted paths: /docker ...
show more
Automated abuse report: 25 attack/probe requests from Amazon.com, Inc. / US.
Targeted paths: /docker-compose.yml, /docker-compose.yaml, /docker-compose.prod.yml, /docker-compose.production.yml.
Sample log lines:
[nafco] 2026-10-11T16:57:48.122Z 44.244.70.94 - GET /docker-compose.yaml 404 - - 1.105 ms ref="-"
[nafco] 2026-10-11T16:57:48.222Z 44.244.70.94 - GET /docker-compose.prod.yml 404 - - 1.378 ms ref="-"
[nafco] 2026-10-11T16:57:48.310Z 44.244.70.94 - GET /docker-compose.production.yml 404 - - 0.886 ms ref="-"
Detected by an automated web-server log monitor.
show less
Web App Attack
๐บ๐ธ
pachec
2026-10-11 16:39:03
(3 hours ago)
Automated vulnerability scanning blocked by fail2ban
Web App Attack
Hacking
๐ฎ๐น
VHosting
2026-10-11 16:35:05
(3 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-11 15:55:46
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 44.244.70.94 (ec2-44-244-70-94.us-west-2.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 44.244.70.94 (ec2-44-244-70-94.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 11 11:55:38.479897 2026] [security2:error] [pid 21815:tid 21815] [client 44.244.70.94:55942] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ymbrixi.com"] [uri "/.git/HEAD"] [unique_id "asuxekphGZpH3jFQ5B6EUQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-10-11 15:52:42
(4 hours ago)
Technology fingerprinting | method: GET | path: /core/install.php | ua: MerchantSecurityScanner/1.0 ...
show more
Technology fingerprinting | method: GET | path: /core/install.php | ua: MerchantSecurityScanner/1.0 (+https://stri.pe/go/merchant-security-scanner)
show less
Port Scan
Web App Attack
๐ฉ๐ช
raph
2026-10-11 15:40:44
(4 hours ago)
[LIB DIR] crawler /vendor/*, /node_modules/*, /laravel/*, etc.
Bad Web Bot
Web App Attack