๐ฌ๐ง
andypiper
2026-10-02 01:01:06
(1 hour ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
๐ฉ๐ช
conseilgouz
2026-10-02 00:15:03
(2 hours ago)
ece-17 : Block hidden directories=>/.astro/manifest.json(/)
Hacking
Anonymous
2026-10-01 20:03:04
(6 hours ago)
Banned by Fail2Ban on server
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 17:54:20
(8 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.118.173.173 (173.173.118.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.118.173.173 (173.173.118.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 13:54:18.498544 2026] [security2:error] [pid 31024:tid 31024] [client 34.118.173.173:32966] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.ecruhairsalon.com|F|2"] [data ".ecruhairsalon.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.ecruhairsalon.com"] [uri "/z9x8c7v6b5-debug-trigger-www.ecruhairsalon.com"] [unique_id "ar6eSgokjXwd1AUI0rwKawAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
bensmithurst
2026-10-01 17:30:15
(8 hours ago)
34.118.173.173 - - [01/Oct/2026:17:30:14 +0000] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e% ...
show more
34.118.173.173 - - [01/Oct/2026:17:30:14 +0000] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fproc/self/environ HTTP/1.1" 400 150 "-" "-"
34.118.173.173 - - [01/Oct/2026:17:30:14 +0000] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f.env HTTP/1.1" 400 150 "-" "-"
34.118.173.173 - - [01/Oct/2026:17:30:14 +0000] "GET /uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f.env HTTP/1.1" 400 150 "-" "-"
34.118.173.173 - - [01/Oct/2026:17:30:14 +0000] "GET /..%2f.env HTTP/1.1" 400 150 "-" "-"
34.118.173.173 - - [01/Oct/2026:17:30:14 +0000] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f.env HTTP/1.1" 400 150 "-" "-"
... [host=LAN***]
show less
Web App Attack
๐ฆ๐น
penguin-solutions.at
2026-10-01 17:27:39
(8 hours ago)
Excessive 403/404 errors
...
Brute-Force
Web App Attack
Anonymous
2026-10-01 17:11:46
(9 hours ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
๐จ๐ญ
zynex
2026-10-01 16:21:21
(9 hours ago)
URL Probing: /static/app/.env
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-01 16:12:54
(10 hours ago)
[ti-12al] Web exploit scanning: 2 suspicious requests detected by fail2ban jail <name>. Example: 34. ...
show more
[ti-12al] Web exploit scanning: 2 suspicious requests detected by fail2ban jail <name>. Example: 34.118.173.173 - - [01/Oct/2026:18:12:52 +0200] "GET /static../.env HTTP/2.0" 404 1863 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)"
34.118.173.173 - - [01/Oct/2026:18:12:52 +0200] "GET /media../.env HTTP/2.0" 404 1863 "-" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/)"
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
Hazzard
2026-10-01 15:54:11
(10 hours ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted]): (CF_ENABLE)
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-01 14:42:05
(11 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.118.173.173 (173.173.118.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.118.173.173 (173.173.118.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 10:42:02.085482 2026] [security2:error] [pid 19157:tid 19157] [client 34.118.173.173:43116] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||4starpromotions.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "4starpromotions.com"] [uri "/z9x8c7v6b5-debug-trigger-4starpromotions.com"] [unique_id "ar5xOuZdCQwtj9ZTWW1V_QAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mad-abuseip
2026-10-01 14:40:08
(11 hours ago)
SCORE:99 REASON:suspicious-score:100 | "POST /api/templates/preview HTTP/1.1" SCORE:99 REASON:suspi ...
show more
SCORE:99 REASON:suspicious-score:100 | "POST /api/templates/preview HTTP/1.1" SCORE:99 REASON:suspicious-score:100 - "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)"
show less
Web App Attack
Anonymous
2026-10-01 13:41:02
(12 hours ago)
IP matched detection query more than 2 hosts and only bad rq long ban.
Brute-Force
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-01 12:57:13
(13 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.118.173.173 (173.173.118.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.118.173.173 (173.173.118.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 08:57:09.474984 2026] [security2:error] [pid 5010:tid 5010] [client 34.118.173.173:33120] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.eiltopofictioncritique.com|F|2"] [data ".eiltopofictioncritique.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.eiltopofictioncritique.com"] [uri "/z9x8c7v6b5-debug-trigger-www.eiltopofictioncritique.com"] [unique_id "ar5YpT5ThqVpEpu-Fpc4ewAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-01 12:52:56
(13 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack