๐บ๐ธ
TPI-Abuse
2026-09-30 04:38:03
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 34.118.155.89 (89.155.118.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.118.155.89 (89.155.118.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 00:37:59.789366 2026] [security2:error] [pid 19373:tid 19391] [client 34.118.155.89:47468] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||zammconstruction.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "zammconstruction.com"] [uri "/z9x8c7v6b5-debug-trigger-zammconstruction.com"] [unique_id "arySJ5qz7n9sPUFyL5an2wAAAU8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Grossmann-Gruppe
2026-09-30 04:27:31
(3 days ago)
Plesk Fail2Ban: plesk-modsecurity
Hacking
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-30 04:18:54
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 34.118.155.89 (89.155.118.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.118.155.89 (89.155.118.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 00:18:48.947106 2026] [security2:error] [pid 22526:tid 22526] [client 34.118.155.89:59526] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||cgautomatizacion.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "cgautomatizacion.com"] [uri "/z9x8c7v6b5-debug-trigger-cgautomatizacion.com"] [unique_id "aryNqBVS41bOWhsnFNPujAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ช
AutosOnShow
2026-09-30 04:14:05
(3 days ago)
blocked for webapp attack | path requested: /cgi-bin/php | seen at 2026-09-30 04:13:40.961 |
Web App Attack
Anonymous
2026-09-30 03:10:01
(3 days ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 03:00:28
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 34.118.155.89 (89.155.118.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.118.155.89 (89.155.118.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 23:00:25.315318 2026] [security2:error] [pid 21264:tid 21264] [client 34.118.155.89:44202] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||avmcyber.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "avmcyber.com"] [uri "/z9x8c7v6b5-debug-trigger-avmcyber.com"] [unique_id "arx7SY787ezHCqZxkHyVkAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
rh24
2026-09-30 02:55:38
(3 days ago)
(badbots) Bad bot user-agent [redacted] from 34.118.155.89 (CA/Canada/89.155.118.34.bc.googleusercon ...
show more
(badbots) Bad bot user-agent [redacted] from 34.118.155.89 (CA/Canada/89.155.118.34.bc.googleusercontent.com)
show less
Hacking
๐ง๐ช
cmbplf
2026-09-30 02:36:14
(3 days ago)
1.249 requests with url.path *.env
113 requests with url.path */proc/*
Brute-Force
Bad Web Bot
Anonymous
2026-09-30 02:27:45
(3 days ago)
34.118.155.89 - - [30/Sep/2026:04:27:45 +0200] "GET /%2e%2e/%2e%2e/%2e%2e/%2e%2e/.env HTTP/2.0" 400 ...
show more
34.118.155.89 - - [30/Sep/2026:04:27:45 +0200] "GET /%2e%2e/%2e%2e/%2e%2e/%2e%2e/.env HTTP/2.0" 400 295 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)"
34.118.155.89 - - [30/Sep/2026:04:27:45 +0200] "GET /%2e%2e/%2e%2e/%2e%2e/%2e%2e/proc/self/environ HTTP/2.0" 400 295 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)"
34.118.155.89 - - [30/Sep/2026:04:27:45 +0200] "GET /public/plugins/grafana-clock-panel/../../../../../../../../proc/self/environ HTTP/2.0" 400 295 "-" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)"
34.118.155.89 - - [30/Sep/2026:04:27:45 +0200] "GET /public/plugins/alertlist/../../../../../../../../proc/self/environ HTTP/2.0" 400 295 "-" "Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)"
34.118.155.89 - - [30/Sep/2026:04:27:45 +0200] "GET /public/plugins/text/../../../../../../../../proc/self/environ HTTP/2.0" 400 295 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
...
show less
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-09-30 02:02:33
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 34.118.155.89 (89.155.118.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.118.155.89 (89.155.118.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 22:02:25.824582 2026] [security2:error] [pid 25632:tid 25632] [client 34.118.155.89:37442] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ayudaclic.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ayudaclic.com"] [uri "/z9x8c7v6b5-debug-trigger-ayudaclic.com"] [unique_id "arxtseIYyFm77wtqHJ15xwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
EGP Abuse Dept
2026-09-30 01:48:14
(3 days ago)
Scanning for web/db/file exploits on www.metalak.nl
SQL Injection
Bad Web Bot
Web App Attack
Anonymous
2026-09-30 01:18:43
(3 days ago)
34.118.155.89 - - [30/Sep/2026:03:18:40 +0200] "GET /api/attachments/img/avatar/..%2F..%2F..%2F..%2F ...
show more
34.118.155.89 - - [30/Sep/2026:03:18:40 +0200] "GET /api/attachments/img/avatar/..%2F..%2F..%2F..%2F..%2Fproc%2Fself%2Fenviron HTTP/2.0" 404 265 "-" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)"
34.118.155.89 - - [30/Sep/2026:03:18:40 +0200] "GET /static/../../../a/../../../../.env HTTP/2.0" 400 295 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
34.118.155.89 - - [30/Sep/2026:03:18:40 +0200] "GET /static/../../../a/../../../../proc/self/environ HTTP/2.0" 400 295 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)"
34.118.155.89 - - [30/Sep/2026:03:18:42 +0200] "GET /%2e%2e/%2e%2e/%2e%2e/%2e%2e/.env HTTP/2.0" 400 295 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] )"
34.118.155.89 - - [30/Sep/2026:03:18:42 +0200] "GET /%2e%2e/%2e%2e/%2e%2e/%2e%2e/proc/self/environ HTTP/2.0" 400 295 "-" "Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)"
...
show less
Brute-Force
SSH
๐จ๐ฆ
john doe
2026-09-30 00:37:25
(3 days ago)
SentinelBot: Secret-path hunting (5 distinct paths): Env File Hunting (score: 63)
Bad Web Bot
๐ณ๐ฑ
Alt255
2026-09-30 00:18:36
(3 days ago)
[ti-tinov] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 34 ...
show more
[ti-tinov] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 34.118.155.89 - - \[30/Sep/2026:02:18:32 +0200\] "GET /.env.bak HTTP/1.1" 404 3440 "-" "Mozilla/5.0 \(compatible\; Amazonbot/0.1\; +https://developer.amazon.com/support/amazonbot\)"
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-09-29 23:52:36
(3 days ago)
Wordlist path sweep | method: GET, POST | path: /build/manifest.json, /lib/terminal-xhr.php, /dist/m ...
show more
Wordlist path sweep | method: GET, POST | path: /build/manifest.json, /lib/terminal-xhr.php, /dist/manifest.json (+3 more) | ua: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36, Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot), DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)
show less
Port Scan
Web App Attack