๐ณ๐ฑ
homeshowdomain.nl
2026-06-10 22:00:54
(57 minutes ago)
Auto-ban: 265 malicious requests on 2026-06-09 (e.g., env/backup probes, brute-force, or error burst ...
show more
Auto-ban: 265 malicious requests on 2026-06-09 (e.g., env/backup probes, brute-force, or error bursts).
show less
Web App Attack
SSH
Hacking
๐ฉ๐ช
dbmwebdesign
2026-06-10 22:00:09
(58 minutes ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
Anonymous
2026-06-10 16:10:21
(6 hours ago)
(caddyscan) Scanner path probe from 34.106.82.162 (US/United States/162.82.106.34.bc.googleuserconte ...
show more
(caddyscan) Scanner path probe from 34.106.82.162 (US/United States/162.82.106.34.bc.googleusercontent.com): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 34.106.82.162 - - [10/Jun/2026:16:10:20 +0000] "GET /actuator/logfile HTTP/1.1"
[REDACTED] 200 2627 34.106.82.162 - - [10/Jun/2026:16:10:20 +0000] "GET /actuator/threaddump HTTP/1.1"
[REDACTED] 200 2627 34.106.82.162 - - [10/Jun/2026:16:10:20 +0000] "GET /api/actuator/logfile HTTP/1.1"
[REDACTED] 200 2627 34.106.82.162 - - [10/Jun/2026:16:10:20 +0000] "GET /api/actuator/env HTTP/1.1"
[REDACTED] 200 2627 34.106.82.162 - - [10/Jun/2026:16:10:20 +0000] "GET /v1/actuator/heapdump HTTP/1.1"
show less
Port Scan
๐จ๐ญ
dalslab ltd
2026-06-10 07:16:21
(15 hours ago)
[10/Jun/2026:09:16:21 +0200] - 404 404 - GET https search.dalslab.com "/heapdump" [Client 34.106.82. ...
show more
[10/Jun/2026:09:16:21 +0200] - 404 404 - GET https search.dalslab.com "/heapdump" [Client 34.106.82.162] [Length 2198] [Gzip 2.17] [Sent-to 10.1.1.41] "Mozilla/5.0 (Linux; Android 8.1.0; Moto G (5S) Plus) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.111 Mobile Safari/537.36" "-"
[10/Jun/2026:09:16:21 +0200] - 404 404 - GET https search.dalslab.com "/actuator/heapdump" [Client 34.106.82.162] [Length 2217] [Gzip 2.15] [Sent-to 10.1.1.41] "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/73.0.3683.75 Safari/537.36" "-"
[10/Jun/2026:09:16:21 +0200] - 404 404 - GET https search.dalslab.com "/actuator/env" [Client 34.106.82.162] [Length 2217] [Gzip 2.15] [Sent-to 10.1.1.41] "Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.8.1) Gecko/20061024 Firefox/2.0 (Swiftfox)" "-"
[10/Jun/2026:09:16:21 +0200] - 404 404 - GET https search.dalslab.com "/actuator/sessions" [Client 34.106.82.162] [Length 2198] [Gzip 2.17] [Sent-to 10.1.1.41] "Mozilla/5.0 (Linux;
...
show less
Web Spam
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-10 07:13:33
(15 hours ago)
[Wed Jun 10 09:13:31.537886 2026] [authz_core:error] [pid 1069688:tid 1069688] [client 34.106.82.162 ...
show more
[Wed Jun 10 09:13:31.537886 2026] [authz_core:error] [pid 1069688:tid 1069688] [client 34.106.82.162:49322] AH01630: client denied by server configuration: /var/www/html/wordpress/.htaccess
[Wed Jun 10 09:13:31.541595 2026] [authz_core:error] [pid 835558:tid 835558] [client 34.106.82.162:49316] AH01630: client denied by server configuration: /var/www/html/wordpress/.htpasswd
...
show less
Hacking
Brute-Force
๐ง๐ช
cmbplf
2026-06-10 03:59:49
(18 hours ago)
2.501 requests from abuseipdb.com blacklisted IP (1yr5mos1d)
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-10 03:36:56
(19 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.106.82.162 (162.82.106.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.106.82.162 (162.82.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 23:36:51.511502 2026] [security2:error] [pid 11649:tid 11649] [client 34.106.82.162:42150] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||transitionclass.jam-pak.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "transitionclass.jam-pak.com"] [uri "/.config/gcloud/credentials.db"] [unique_id "aijb07VXN04eoXczuoGvEAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
EGP Abuse Dept
2026-06-10 02:26:42
(20 hours ago)
Scanning for web/db/file exploits on perron95.tafelconfigurator.nl
SQL Injection
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Cloud86 B.V.
2026-06-10 01:26:04
(21 hours ago)
categories: DDoS Attack
DDoS Attack
๐บ๐ธ
mnsf
2026-06-10 00:11:18
(22 hours ago)
Scanning/Probing (51)
Request Overload (244)
Brute-Force
Web App Attack
Anonymous
2026-06-09 23:21:47
(23 hours ago)
Multiple web server 400 error codes from same source ip
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 23:09:19
(23 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.106.82.162 (162.82.106.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.106.82.162 (162.82.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 19:09:11.169854 2026] [security2:error] [pid 3840:tid 3840] [client 34.106.82.162:46340] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||shadowfree.souldata.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "shadowfree.souldata.com"] [uri "/.config/gcloud/credentials.db"] [unique_id "aiidF6s-e-YtW4AK3W1iOwAAAE8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 13:32:59
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.106.82.162 (162.82.106.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.106.82.162 (162.82.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 09:32:55.079154 2026] [security2:error] [pid 11587:tid 11671] [client 34.106.82.162:40392] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||stone-doyle.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "stone-doyle.com"] [uri "/.config/gcloud/credentials.db"] [unique_id "aigWB8UYm7KiAYu6zcqpQQAAAIw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-06-09 12:49:05
(1 day ago)
Excessive 404/403 errors
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-09 12:47:28
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.106.82.162 (162.82.106.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.106.82.162 (162.82.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 08:47:23.111959 2026] [security2:error] [pid 25364:tid 25364] [client 34.106.82.162:51542] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||sweetpeachcupcakes.shawnlayne.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "sweetpeachcupcakes.shawnlayne.com"] [uri "/.config/gcloud/credentials.db"] [unique_id "aigLW9z3ejxyIEOrtSk3gwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack