๐ณ๐ฑ
Site.eu
2026-06-14 15:20:28
(1 day ago)
Excessive multi-domain requests
Brute-Force
๐ฉ๐ช
ghostwarriors
2026-06-13 15:50:02
(2 days ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-13 15:49:13
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.131.221.41 (41.221.131.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.131.221.41 (41.221.131.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 11:49:06.544378 2026] [security2:error] [pid 3624:tid 3624] [client 34.131.221.41:54526] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.turboswim.chevronparkett.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.turboswim.chevronparkett.com"] [uri "/.config/gcloud/credentials.db"] [unique_id "ai178pocRfEfsVVci0RUTwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-06-13 14:21:33
(2 days ago)
Excessive multi-domain requests
Brute-Force
๐ต๐ฑ
dcnet
2026-06-13 14:00:19
(2 days ago)
FortiGate detected DOS attack from IPv4 address 34.131.221.41
DDoS Attack
๐ณ๐ฑ
ConsulHosting
2026-06-13 13:36:35
(2 days ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
๐ฉ๐ช
Melle
2026-06-13 13:28:54
(2 days ago)
Blocked by CrowdSec | Scenario: crowdsecurity/http-probing | 34.131.221.41 triggered 11 events | Det ...
show more
Blocked by CrowdSec | Scenario: crowdsecurity/http-probing | 34.131.221.41 triggered 11 events | Detected: 2026-06-13T13:28:53.06065778Z
show less
Web App Attack
Hacking
๐บ๐ธ
mnsf
2026-06-13 13:07:01
(2 days ago)
Too many Status 40X (17)
Scanning/Probing (61)
Request Overload (383)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-13 12:59:30
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.131.221.41 (41.221.131.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.131.221.41 (41.221.131.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 08:59:25.478176 2026] [security2:error] [pid 3329:tid 3329] [client 34.131.221.41:54234] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.go.azultigre.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.go.azultigre.com"] [uri "/dump.sql"] [unique_id "ai1ULS2BxbfXKGXaAozPCQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
rh24
2026-06-13 12:41:33
(2 days ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 34.131.221.41 (IN/In ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 34.131.221.41 (IN/India/41.221.131.34.bc.googleusercontent.com): (CF_ENABLE)
show less
Bad Web Bot
๐ฌ๐ง
consul.to
2026-06-13 10:49:31
(2 days ago)
Web attack/malicious scanning detected
Web App Attack
๐ณ๐ฑ
Site.eu
2026-06-13 10:43:03
(2 days ago)
Excessive 404/403 errors
Brute-Force
Anonymous
2026-06-13 10:29:11
(2 days ago)
[redacted] 34.131.221.41 - - [13/Jun/2026:12:28:59 +0200] "GET /mysqldump.sql HTTP/1.1" 404 56448 "- ...
show more
[redacted] 34.131.221.41 - - [13/Jun/2026:12:28:59 +0200] "GET /mysqldump.sql HTTP/1.1" 404 56448 "-" "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)"
[redacted] 34.131.221.41 - - [13/Jun/2026:12:28:59 +0200] "GET /db.sql HTTP/1.1" 404 56448 "-" "Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3875.0 Safari/537.36"
[redacted] 34.131.221.41 - - [13/Jun/2026:12:28:59 +0200] "GET /db.sql.gz HTTP/1.1" 404 56448 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36"
[redacted] 34.131.221.41 - - [13/Jun/2026:12:28:59 +0200] "GET /db.zip HTTP/1.1" 404 56448 "-" "Opera/9.80 (Windows NT 6.1; U; es-ES) Presto/2.9.181 Version/12.00"
[redacted] 34.131.221.41 - - [13/Jun/2026:12:28:59 +0200] "GET /admin/phpinfo.php HTTP/1.1" 404 56448 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.6; rv:25.0) Gecko/20100101 Firefox/25.0"
[redacted]
...
show less
Hacking
Web App Attack
๐ซ๐ท
masterguru
2026-06-13 10:27:08
(2 days ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.131.221.41 (IN/India/41.221.131.34 ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.131.221.41 (IN/India/41.221.131.34.bc.googleusercontent.com): 1 in the last 3600 secs (0-195)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-13 08:24:05
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 34.131.221.41 (41.221.131.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.131.221.41 (41.221.131.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 04:23:57.533653 2026] [security2:error] [pid 6621:tid 6621] [client 34.131.221.41:47622] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||webcam.oxfordgliding.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "webcam.oxfordgliding.com"] [uri "/.config/gcloud/credentials.db"] [unique_id "ai0TncgAL2y1fygMvIK-sgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack