๐ณ๐ฑ
Alt255
2026-09-16 21:19:48
(3 weeks ago)
[ti-10al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-10al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.122.88.167 - - [16/Sep/2026:23:19:47 +0200] "GET /.github/.env HTTP/2.0" 404 14493 "-" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)"
...
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-09-16 21:06:15
(3 weeks ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2026-09-16 20:51:01
(3 weeks ago)
block ruleset WAF detection and high score on abuseIPDB 149EB1B42C242111FADBBC2EF8F90219570691E1
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-16 20:47:20
(3 weeks ago)
(mod_security) mod_security (id:210730) triggered by 34.122.88.167 (167.88.122.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.122.88.167 (167.88.122.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 16:47:13.219099 2026] [security2:error] [pid 12632:tid 12632] [client 34.122.88.167:40960] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bahamascruisersguide.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bahamascruisersguide.com"] [uri "/rclone.conf"] [unique_id "aqsAUYNpT3fSuxLYeHe6QAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
pipeline.es
2026-09-16 20:34:41
(3 weeks ago)
Web scanning / probing for vulnerable paths | URL: /..%2f..%2f.env | Evidence: atlas-viagens.pt 34.1 ...
show more
Web scanning / probing for vulnerable paths | URL: /..%2f..%2f.env | Evidence: atlas-viagens.pt 34.122.88.167 - - [16/Sep/2026:22:32:49 +0200] \"GET /..%2f..%2f.env HTTP/2.0\" 404 196 \"-\" \"Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email])\" GEOIP_COUNTRY_CODE=US | ASN: GOOGLE-CLOUD-PLATFORM | Country: US
show less
Port Scan
Web App Attack
๐ฌ๐ง
noise.agency
2026-09-16 20:20:30
(3 weeks ago)
34.122.88.167 (US/United States/167.88.122.34.bc.googleusercontent.com), more than 30 Apache 404 hit ...
show more
34.122.88.167 (US/United States/167.88.122.34.bc.googleusercontent.com), more than 30 Apache 404 hits
show less
Hacking
๐บ๐ธ
mnsf
2026-09-16 20:06:31
(3 weeks ago)
Scanning/Probing (12)
Brute-Force
Web App Attack
Anonymous
2026-09-16 19:45:39
(3 weeks ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-16 19:40:04
(3 weeks ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
๐ฎ๐น
VHosting
2026-09-16 19:15:04
(3 weeks ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
agenciahypelab.com.br
2026-09-16 19:13:19
(3 weeks ago)
WordPress login brute-force detectado e bloqueado pelo CSF/LFD. Trigger: LF_TRIGGER
Brute-Force
SSH
๐ฉ๐ช
maxpower
2026-09-16 19:13:03
(3 weeks ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.122.88.167 (US/United States/167.88.1 ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.122.88.167 (US/United States/167.88.122.34.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.122.88.167 - - [16/Sep/2026:21:13:02 +0200] "GET /.aws/credentials HTTP/2.0" 404 7729 "-" "Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)" "34.122.88.167" host=abruzzotour.it
show less
Port Scan
๐ซ๐ท
Octopuce
2026-09-16 19:03:29
(3 weeks ago)
Aggressive web search of vulnerable pages: /userfiles?path=../../.env /userfiles?path=../../../.env ...
show more
Aggressive web search of vulnerable pages: /userfiles?path=../../.env /userfiles?path=../../../.env /userfiles?path=../../../../.env /userfiles ...
show less
Web App Attack
๐ซ๐ท
dynamix
2026-09-16 18:59:41
(3 weeks ago)
Multiple WAF Violations
Web App Attack
๐ต๐ฑ
gandaflux
2026-09-16 18:58:04
(3 weeks ago)
34.122.88.167 [redacted-domain] - [16/Sep/2026:20:58:02 +0200] "GET /.git-credentials HTTP/2.0" 403 ...
show more
34.122.88.167 [redacted-domain] - [16/Sep/2026:20:58:02 +0200] "GET /.git-credentials HTTP/2.0" 403 158 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +[redacted-url]/)"
34.122.88.167 [redacted-domain] - [16/Sep/2026:20:58:02 +0200] "GET /.aws/credentials HTTP/2.0" 403 158 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +[redacted-url]/)"
34.122.88.167 [redacted-domain] - [16/Sep/2026:20:58:02 +0200] "GET /.aws/config HTTP/2.0" 403 158 "-" "Mozilla/5.0 (compatible; cohere-ai; +[redacted-url]/crawler)"
show less
Web App Attack