๐บ๐ธ
TPI-Abuse
2026-10-09 01:59:47
(19 minutes ago)
(mod_security) mod_security (id:949110) triggered by 8.231.250.46 (46.250.231.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:949110) triggered by 8.231.250.46 (46.250.231.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 21:59:42.658898 2026] [security2:error] [pid 30800:tid 30800] [client 8.231.250.46:47846] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "letahaabooking.com"] [uri "/z9x8c7v6b5-debug-trigger-letahaabooking.com"] [unique_id "ashKjnoi4APD8VvPzk5AvAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-10-09 01:23:19
(56 minutes ago)
Excessive multi-domain requests
Brute-Force
๐ฌ๐ง
andypiper
2026-10-09 01:00:22
(1 hour ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
๐จ๐ฆ
Mediashaker
2026-10-09 00:48:07
(1 hour ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 8.231.250.46 (US/Uni ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 8.231.250.46 (US/United States/46.250.231.8.bc.googleusercontent.com)
show less
Bad Web Bot
๐ช๐ธ
robotstxt
2026-10-09 00:29:31
(1 hour ago)
8.231.250.46 - - [09/Oct/2026:00:28:28 +0000] "GET /auth HTTP/2.0" 403 165 "https://keepitsimplelab. ...
show more
8.231.250.46 - - [09/Oct/2026:00:28:28 +0000] "GET /auth HTTP/2.0" 403 165 "https://keepitsimplelab.com/auth" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "-" edge="8.231.250.46"
8.231.250.46 - - [09/Oct/2026:00:28:28 +0000] "GET /auth/login HTTP/2.0" 403 165 "https://keepitsimplelab.com/auth/login" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "-" edge="8.231.250.46"
8.231.250.46 - - [09/Oct/2026:00:28:28 +0000] "GET /users/login HTTP/2.0" 403 165 "https://keepitsimplelab.com/users/login" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "-" edge="8.231.250.46"
8.231.250.46 - - [09/Oct/2026:00:28:28 +0000] "GET /z9x8c7v6b5-debug-trigger-keepitsimplelab.com HTTP/2.0" 403 189 "https://keepitsimplelab.com/z9x8c7v6b5-debug-trigger-keepitsimplelab.com" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) A
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 00:17:21
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.231.250.46 (46.250.231.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 8.231.250.46 (46.250.231.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 20:17:14.837951 2026] [security2:error] [pid 28712:tid 28712] [client 8.231.250.46:50028] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "karenjoyce.com"] [uri "/%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env"] [unique_id "asgyinq-N2Lny99PcVMZWwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-09 00:16:50
(2 hours ago)
SIEM ALERT AUTO REPORT
Email Spam
๐ฉ๐ช
TheDjRider
2026-10-09 00:11:34
(2 hours ago)
CrowdSec detected Sensitive file or backup discovery attempt. Scenario: local/apache-sensitive-paths ...
show more
CrowdSec detected Sensitive file or backup discovery attempt. Scenario: local/apache-sensitive-paths. Automatic ban triggered. Detection time (UTC): 2026-10-09T00:11:32.397009561Z. Context: http_status=404
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 23:47:49
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.231.250.46 (46.250.231.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 8.231.250.46 (46.250.231.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 19:47:42.804216 2026] [security2:error] [pid 4592:tid 4592] [client 8.231.250.46:33752] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jonathanwilsonphotography.com"] [uri "/.htpasswd"] [unique_id "asgrnmx7jQ1HIntwNobavgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
JLKnoch Software GmbH
2026-10-08 23:36:48
(2 hours ago)
CrowdSec crowdsecurity/http-probing
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 23:31:45
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 8.231.250.46 (46.250.231.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 8.231.250.46 (46.250.231.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 19:31:39.485362 2026] [security2:error] [pid 23223:tid 23223] [client 8.231.250.46:38976] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||jhbookdesign.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "jhbookdesign.com"] [uri "/z9x8c7v6b5-debug-trigger-jhbookdesign.com"] [unique_id "asgn27d_Y5Iwubldmf-yQwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
jcbriar
2026-10-08 23:21:00
(2 hours ago)
Searching for vulnerable scripts
Hacking
Web App Attack
๐ช๐ธ
robotstxt
2026-10-08 23:15:44
(3 hours ago)
8.231.250.46 - - [08/Oct/2026:23:15:05 +0000] "GET /dist/.vite/manifest.json HTTP/2.0" 403 15417 "ht ...
show more
8.231.250.46 - - [08/Oct/2026:23:15:05 +0000] "GET /dist/.vite/manifest.json HTTP/2.0" 403 15417 "https://javiercasares.com/dist/.vite/manifest.json" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "-" edge="8.231.250.46"
8.231.250.46 - - [08/Oct/2026:23:15:05 +0000] "GET /wp-content/cache/autoptimize/js/autoptimize_c0a7994c5aa3fec626476e359cdabc89.js HTTP/2.0" 403 165 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "-" edge="8.231.250.46"
8.231.250.46 - - [08/Oct/2026:23:15:05 +0000] "GET /.vite/manifest.json HTTP/2.0" 403 15392 "https://javiercasares.com/.vite/manifest.json" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "-" edge="8.231.250.46"
8.231.250.46 - - [08/Oct/2026:23:15:06 +0000] "GET /z9x8c7v6b5-debug-trigger-javiercasares.com HTTP/2.0" 403 15741 "https://javiercasares.com/z9x8c7v6b5-debug-trigger-javie
...
show less
Web App Attack
๐บ๐ธ
iwle
2026-10-08 23:00:18
(3 hours ago)
[Thu Oct 08 19:00:16.123848 2026] [:error] [pid 1478:tid 1626] [client 8.231.250.46:0] [client 8.231 ...
show more
[Thu Oct 08 19:00:16.123848 2026] [:error] [pid 1478:tid 1626] [client 8.231.250.46:0] [client 8.231.250.46] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "125"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /cache/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "iwle.com"] [uri "/cache/.env"] [unique_id "asgggK3nn8hvTBDp0D9COwAAAJg"]
[Thu Oct 08 19:00:16.132667 2026] [:error] [pid 1477:tid 1604] [client 8.231.250.46:0] [client 8.231.250.46] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "125"] [id "9
...
show less
Web App Attack
๐ฒ๐พ
Rizzy
2026-10-08 23:00:04
(3 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack