๐ฎ๐น
paoloartone
2026-08-21 05:00:29
(2 days ago)
Reverse proxy TCO: 344 richieste malevole bloccate (scan/exploit/brute-force WordPress) il 20/08/202 ...
show more
Reverse proxy TCO: 344 richieste malevole bloccate (scan/exploit/brute-force WordPress) il 20/08/2026.
show less
Web App Attack
Hacking
Port Scan
Anonymous
2026-08-20 16:31:50
(2 days ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
๐บ๐ธ
TPI-Abuse
2026-08-20 11:26:09
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.23.45.180 (180.45.23.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.23.45.180 (180.45.23.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 07:26:05.673868 2026] [security2:error] [pid 11219:tid 11245] [client 34.23.45.180:46694] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.pizzadlux.com"] [uri "/.git/config"] [unique_id "aobkTTOMMOdVXc5zMq8powAAARg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-08-20 10:27:56
(2 days ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
kosada.com
2026-08-20 10:20:32
(2 days ago)
Web vulnerability probing: /rclone.conf
Web App Attack
๐ฌ๐ง
NotCool
2026-08-20 09:14:02
(2 days ago)
(CRAWLDELAY) Generic Bot Crawl-delay Violation 34.23.45.180 (US/United States/180.45.23.34.bc.google ...
show more
(CRAWLDELAY) Generic Bot Crawl-delay Violation 34.23.45.180 (US/United States/180.45.23.34.bc.googleusercontent.com): 50 in the last 3600 secs
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-20 08:59:34
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.23.45.180 (180.45.23.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.23.45.180 (180.45.23.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 04:59:26.225121 2026] [security2:error] [pid 32708:tid 32708] [client 34.23.45.180:53338] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||adrienberthaud.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "adrienberthaud.com"] [uri "/rclone.conf"] [unique_id "aobB7rPpWGIXrym73Df3rwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐น๐ผ
kk_it_man
2026-08-20 08:13:03
(2 days ago)
ET INFO Request to Hidden Environment File - Inbound
GPL WEB_SERVER .htpasswd access
GPL WEB_SER ...
show more
ET INFO Request to Hidden Environment File - Inbound
GPL WEB_SERVER .htpasswd access
GPL WEB_SERVER 403 Forbidden
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-08-20 08:10:55
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.23.45.180 (180.45.23.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.23.45.180 (180.45.23.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 04:10:51.968291 2026] [security2:error] [pid 9394:tid 9394] [client 34.23.45.180:50184] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.bodybuildbid.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.bodybuildbid.com"] [uri "/rclone.conf"] [unique_id "aoa2i5NPugiQOto9hSZsJgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฟ
antihack.anarchista.xyz
2026-08-20 08:01:36
(2 days ago)
404 burst: 30 hits in 10 min, URI /user/login, Ref , UA Mozilla/5.0 (Windows NT 10.0; Win64; x64) Ap ...
show more
404 burst: 30 hits in 10 min, URI /user/login, Ref , UA Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Edg/149.0.0.0
show less
Brute-Force
Web App Attack
Bad Web Bot
๐ฆ๐น
penguin-solutions.at
2026-08-20 07:55:23
(2 days ago)
Excessive 403/404 errors
...
Brute-Force
Web App Attack
๐ณ๐ฑ
Savvii
2026-08-20 07:38:15
(2 days ago)
20 attempts against mh-misbehave-ban on ozone
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-20 06:40:44
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.23.45.180 (180.45.23.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.23.45.180 (180.45.23.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 02:40:40.744229 2026] [security2:error] [pid 23025:tid 23025] [client 34.23.45.180:55010] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/Web.config" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.infojeffreysbay.com"] [uri "/web.config"] [unique_id "aoahaMw1Y2bs5OENuScJ0wAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-20 06:30:16
(3 days ago)
Suspicious URL access.
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-20 05:10:16
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 34.23.45.180 (180.45.23.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.23.45.180 (180.45.23.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 01:10:11.533407 2026] [security2:error] [pid 18199:tid 18199] [client 34.23.45.180:36458] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||circlehealthcaregroup.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "circlehealthcaregroup.com"] [uri "/rclone.conf"] [unique_id "aoaMMy1zNKthmHuiHD0oogAAAEo"]
show less
Brute-Force
Bad Web Bot
Web App Attack