๐ง๐ช
taivas.nl
2026-10-09 04:33:07
(6 hours ago)
Many_bad_calls
Web App Attack
๐ธ๐ช
vaia.cloud
2026-10-09 02:10:02
(8 hours ago)
crowdsecurity/grafana-cve-2021-43798
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 01:52:01
(9 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.12.63.169 (169.63.12.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.12.63.169 (169.63.12.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 21:51:55.588583 2026] [security2:error] [pid 9198:tid 9198] [client 34.12.63.169:50744] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||candlesandwoodcrafts.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "candlesandwoodcrafts.com"] [uri "/z9x8c7v6b5-debug-trigger-candlesandwoodcrafts.com"] [unique_id "ashIu0VljQr-D6tAFD0ZEgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-09 01:39:35
(9 hours ago)
[ssd5.kdns.gr] httpd-config-scan: sites=www.cancelletto.gr; logs=/var/log/httpd/domains/cancelletto. ...
show more
[ssd5.kdns.gr] httpd-config-scan: sites=www.cancelletto.gr; logs=/var/log/httpd/domains/cancelletto.gr.log; samples=/.ssh/id_rsa | /.ssh/id_ed25519 | /.npmrc
show less
Hacking
Web App Attack
๐ฉ๐ช
maxpower
2026-10-09 01:34:18
(9 hours ago)
(PERMBLOCK) 34.12.63.169 (169.63.12.34.bc.googleusercontent.com) has had more than 4 temp blocks in ...
show more
(PERMBLOCK) 34.12.63.169 (169.63.12.34.bc.googleusercontent.com) has had more than 4 temp blocks in the last 86400 secs; Ports: *; Direction: inout; Trigger: LF_PERMBLOCK_COUNT; Logs:
show less
Port Scan
๐ฉ๐ช
maxpower
2026-10-09 00:39:40
(10 hours ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.12.63.169 (169.63.12.34.bc.googleuser ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.12.63.169 (169.63.12.34.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.12.63.169 - - [09/Oct/2026:02:39:35 +0200] "GET /@fs/root/.aws/credentials?raw?? HTTP/2.0" 429 41 "-" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)" "34.12.63.169" host=canarybusinesshhs.com
show less
Port Scan
๐ฎ๐น
mgarofano80
2026-10-08 23:40:39
(11 hours ago)
Brute-Force
Web App Attack
๐จ๐ฆ
Anytech
2026-10-08 23:34:49
(11 hours ago)
Blocked by ConnMonitor
Web App Attack
๐ง๐ช
taivas.nl
2026-10-08 23:32:09
(11 hours ago)
Bad_requests
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-08 23:31:29
(11 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.12.63.169 (169.63.12.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.12.63.169 (169.63.12.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 19:31:23.477519 2026] [security2:error] [pid 19928:tid 19928] [client 34.12.63.169:60498] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||campnecon.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "campnecon.com"] [uri "/z9x8c7v6b5-debug-trigger-campnecon.com"] [unique_id "asgnyynVBvAYKlsdRhiPSgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 22:50:25
(12 hours ago)
(mod_security) mod_security (id:210580) triggered by 34.12.63.169 (169.63.12.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210580) triggered by 34.12.63.169 (169.63.12.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 18:50:19.791405 2026] [security2:error] [pid 21417:tid 21417] [client 34.12.63.169:47540] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at ARGS:apis. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||caminorfoundation.org|F|2"] [data "Matched Data: proc/self/environ found within ARGS:apis: ../../../../../../proc/self/environ"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "caminorfoundation.org"] [uri "/api/console/api_server"] [unique_id "asgeKxxIQqoPIfrPYUqkQAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-10-08 22:39:58
(12 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 22:33:57
(12 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.12.63.169 (169.63.12.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.12.63.169 (169.63.12.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 18:33:50.498163 2026] [security2:error] [pid 23542:tid 23542] [client 34.12.63.169:37840] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||camouflagebikinis.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "camouflagebikinis.com"] [uri "/z9x8c7v6b5-debug-trigger-camouflagebikinis.com"] [unique_id "asgaTs8AyhQ2ZPrB-PjpjwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ณ
dineshskt4all
2026-10-08 22:31:58
(12 hours ago)
34.12.63.169 - - [08/Oct/2026:22:31:57 +0000] "GET /gpfqxmtnfpx5bj56yrjs HTTP/1.1" 404 8487 "-" "Moz ...
show more
34.12.63.169 - - [08/Oct/2026:22:31:57 +0000] "GET /gpfqxmtnfpx5bj56yrjs HTTP/1.1" 404 8487 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36"
...
show less
IoT Targeted
๐ง๐ท
radardatelecom
2026-10-08 22:27:05
(12 hours ago)
Blocked by Radar da Telecom firewall โ abuseipdb
Bad Web Bot
Web App Attack