๐บ๐ธ
antlac1
2026-10-03 07:39:51
(3 days ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
๐ฉ๐ช
tentwentyfour
2026-10-03 05:04:58
(4 days ago)
Blocked for probing for sensitive web application components
Brute-Force
Web App Attack
๐ซ๐ท
masterguru
2026-10-03 04:28:45
(4 days ago)
BAD BOT - Detected and Blocked.. Matched phrase "baidu" at REQUEST_HEADERS:user-agent. (1100000-131)
Bad Web Bot
๐ณ๐ฑ
Site.eu
2026-10-03 03:45:39
(4 days ago)
Excessive multi-domain requests
Brute-Force
๐ฉ๐ช
maxpower
2026-10-03 03:22:04
(4 days ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 8.234.148.232 (US/United States/232.148. ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 8.234.148.232 (US/United States/232.148.234.8.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 8.234.148.232 - - [03/Oct/2026:05:22:02 +0200] "GET /config/env/aws_credentials.env HTTP/2.0" 200 12028 "-" "Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)" "-" host=mediaqualitylab.com
show less
Port Scan
๐ฉ๐ช
Philister11
2026-10-03 02:56:30
(4 days ago)
CrowdSec: crowdsecurity/http-admin-interface-probing (US/AS396982)
Web App Attack
Hacking
๐ณ๐ฑ
e.fierstra
2026-10-03 00:41:08
(4 days ago)
excessive HTTP 404 errors
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-03 00:21:52
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 8.234.148.232 (232.148.234.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 8.234.148.232 (232.148.234.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 20:21:47.834590 2026] [security2:error] [pid 7299:tid 7299] [client 8.234.148.232:51768] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.festival.bluegrassexpressband.com|F|2"] [data ".festival.bluegrassexpressband.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.festival.bluegrassexpressband.com"] [uri "/z9x8c7v6b5-debug-trigger-www.festival.bluegrassexpressband.com"] [unique_id "asBKm2NttY-meeLHJA8NBAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-10-02 23:06:10
(4 days ago)
3.185 requests from abuseipdb.com blacklisted IP (1yr9mos1w)
Brute-Force
Bad Web Bot
๐บ๐ธ
hostmach
2026-10-02 21:35:44
(4 days ago)
(cpanel) Failed cPanel login from 8.234.148.232 (US/United States/232.148.234.8.bc.googleusercontent ...
show more
(cpanel) Failed cPanel login from 8.234.148.232 (US/United States/232.148.234.8.bc.googleusercontent.com): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CPANEL; Logs: [2026-10-02 17:35:39 -0400] info [cpaneld] 8.234.148.232 - - "GET /model/info HTTP/1.1" FAILED LOGIN cpaneld: Authorization: type not known
[2026-10-02 17:35:41 -0400] info [cpaneld] 8.234.148.232 - - "GET /secrets.env HTTP/1.1" FAILED LOGIN cpaneld: login attempt without username
[2026-10-02 17:35:41 -0400] info [cpaneld] 8.234.148.232 - - "GET /secrets.json HTTP/1.1" FAILED LOGIN cpaneld: login attempt without username
[2026-10-02 17:35:41 -0400] info [cpaneld] 8.234.148.232 - - "GET /403.shtml HTTP/1.1" FAILED LOGIN cpaneld: login attempt without username
[2026-10-02 17:35:41 -0400] info [cpaneld] 8.234.148.232 - - "GET /secrets.yml HTTP/1.1" FAILED LOGIN cpaneld: login attempt without username
show less
Brute-Force
SSH
๐ซ๐ท
Octopuce
2026-10-02 21:14:58
(4 days ago)
Aggressive web search of vulnerable pages: /userfiles?path=../../../../.env /userfiles?path=../../.. ...
show more
Aggressive web search of vulnerable pages: /userfiles?path=../../../../.env /userfiles?path=../../../.env /userfiles/x?path=../../.env /.env /. ...
show less
Web App Attack
๐ซ๐ท
Feelautom
2026-10-02 21:08:26
(4 days ago)
[FeelAutom Auto-Ban] BotIdentityRotation: /backend/settings.py (Score: 222)
Hacking
๐ฉ๐ช
rh24
2026-10-02 20:59:46
(4 days ago)
(badbots) Bad bot user-agent [redacted] from 8.234.148.232 (US/United States/232.148.234.8.bc.google ...
show more
(badbots) Bad bot user-agent [redacted] from 8.234.148.232 (US/United States/232.148.234.8.bc.googleusercontent.com)
show less
Hacking
๐ฉ๐ช
ardexter
2026-10-02 20:49:23
(4 days ago)
Wordpress attack and DDOS
DDoS Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 19:40:31
(4 days ago)
(mod_security) mod_security (id:949110) triggered by 8.234.148.232 (232.148.234.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:949110) triggered by 8.234.148.232 (232.148.234.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 15:40:27.264442 2026] [security2:error] [pid 11521:tid 11521] [client 8.234.148.232:49282] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.exorex.com"] [uri "/server.key"] [unique_id "asAIq-OD0QGYtPdkGlVfkQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack