๐ฎ๐น
ciccio diddo
2026-10-01 16:19:44
(1 day ago)
High Burst multiple 40X port:Tcp/80,443
Brute-Force
Web App Attack
๐ฉ๐ช
yitzhaq
2026-10-01 14:14:29
(1 day ago)
8.234.158.235 - - [01/Oct/2026:16:14:27 +0200] "GET /wp-includes/js/dist/dom-ready.min.js?ver=3fe927 ...
show more
8.234.158.235 - - [01/Oct/2026:16:14:27 +0200] "GET /wp-includes/js/dist/dom-ready.min.js?ver=3fe927cab37bf38d6a23 HTTP/2.0" 200 478 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36 Edg/152.0.0.0"
8.234.158.235 - - [01/Oct/2026:16:14:27 +0200] "GET /wp-includes/js/underscore.min.js?ver=1.13.8 HTTP/2.0" 200 7503 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36 Edg/152.0.0.0"
8.234.158.235 - - [01/Oct/2026:16:14:27 +0200] "GET /wp-content/plugins/hcaptcha-for-forms-and-more/assets/js/apps/hcaptcha.js?ver=5.4.0 HTTP/2.0" 200 5848 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36 Edg/152.0.0.0"
8.234.158.235 - - [01/Oct/2026:16:14:27 +0200] "GET /config.json HTTP/2.0" 404 31029 "https://[site]/config.json" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)"
8.234.158.235 - - [01/Oct/
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-01 14:11:28
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 8.234.158.235 (235.158.234.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 8.234.158.235 (235.158.234.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 10:11:22.236799 2026] [security2:error] [pid 15668:tid 15668] [client 8.234.158.235:38554] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kaldaragroup.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kaldaragroup.com"] [uri "/z9x8c7v6b5-debug-trigger-kaldaragroup.com"] [unique_id "ar5qCsfIiXlB3QfOWyXSXgAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 13:41:36
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 8.234.158.235 (235.158.234.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 8.234.158.235 (235.158.234.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 09:41:30.664287 2026] [security2:error] [pid 31565:tid 31565] [client 8.234.158.235:50968] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kathleenullmann.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kathleenullmann.com"] [uri "/z9x8c7v6b5-debug-trigger-kathleenullmann.com"] [unique_id "ar5jCorzsio7pLO6OBVjKQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-01 12:21:16
(1 day ago)
Portscan: TCP/8443 (4x), TCP/8080 (4x)
Port Scan
๐จ๐ฆ
Anytech
2026-10-01 11:52:37
(1 day ago)
Blocked by Conn-Monitor: env-probing
Web App Attack
Hacking
Anonymous
2026-10-01 11:48:06
(1 day ago)
Bot / scanning and/or hacking attempts: GET / HTTP/2.0, [39/34] read: stream 0, , GET /wp-includes/ ...
show more
Bot / scanning and/or hacking attempts: GET / HTTP/2.0, [39/34] read: stream 0, , GET /wp-includes/js/dist/hooks.min.js?ver=f0f188028580e8dc1255 , [62/56] read: stream 0, , GET /wp-content/plugins/contact-form-7/includes/js/index.js?ver, GET /admin/login HTTP/2.0, GET /wp-includes/js/wp-api.min.js?ver=573dc39d528736c5d2d62c5aa, GET /wp-includes/js/dist/i18n.min.js?ver=1dfe7db3940c23ea9216 H
show less
Hacking
Web App Attack
Anonymous
2026-10-01 11:34:11
(1 day ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐บ๐ธ
jormaster3k
2026-10-01 10:43:48
(1 day ago)
Attack against Apache (too many 404s)
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-01 10:27:28
(1 day ago)
[ti-04al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apac ...
show more
[ti-04al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apache-404. Example: 8.234.158.235 - - [01/Oct/2026:12:27:11 +0200] "POST /graphql HTTP/2.0" 404 1855 "https://profile.easymadeit.nl" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Mobile Safari/537.36"
8.234.158.235 - - [01/Oct/2026:12:27:11 +0200] "GET /model/info HTTP/2.0" 404 1864 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
8.234.158.235 - - [01/Oct/2026:12:27:11 +0200] "POST /login HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)"
8.234.158.235 - - [01/Oct/2026:12:27:11 +0200] "POST /api/graphql HTTP/2.0" 404 1855 "https://profile.easymadeit.nl" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko)
...
show less
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-10-01 10:26:21
(1 day ago)
128 requests with url.path */proc/*
111 requests with url.path *credentials.json
Brute-Force
Bad Web Bot
๐ณ๐ฑ
Site.eu
2026-10-01 10:25:39
(1 day ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-10-01 10:22:56
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 8.234.158.235 (235.158.234.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.234.158.235 (235.158.234.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 06:22:50.448111 2026] [security2:error] [pid 16282:tid 16282] [client 8.234.158.235:40614] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.explorediablo.com"] [uri "/.htpasswd"] [unique_id "ar40esEZYfv_5m5JTKDnSAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-10-01 10:06:30
(1 day ago)
Too many Status 40X (11)
Brute-Force
Web App Attack
๐ณ๐ฑ
Savvii
2026-10-01 09:34:07
(1 day ago)
20 attempts against mh-misbehave-ban on choy
Brute-Force
Bad Web Bot
Web App Attack