๐ฎ๐ณ
evicky2002
2026-09-14 06:00:01
(5 days ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
Anonymous
2026-09-13 23:04:55
(6 days ago)
IP matched detection query more than 2 hosts and only bad rq long ban.
Brute-Force
Web App Attack
Hacking
Anonymous
2026-09-13 22:34:54
(6 days ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
Anonymous
2026-09-13 20:39:31
(6 days ago)
Aggressive web scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-13 09:21:01
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 34.135.87.41 (41.87.135.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.135.87.41 (41.87.135.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 05:20:57.701593 2026] [security2:error] [pid 2352405:tid 2352455] [client 34.135.87.41:51962] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wijaya.biz"] [uri "/appearance/../../.env"] [unique_id "aqZq-Vng0jQb4Nc3Dg1dlQAAAEg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-13 09:11:17
(6 days ago)
34.135.87.41 detected on srv01
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-13 08:38:39
(6 days ago)
(mod_security) mod_security (id:210730) triggered by 34.135.87.41 (41.87.135.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.135.87.41 (41.87.135.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 04:38:34.686285 2026] [security2:error] [pid 845695:tid 845695] [client 34.135.87.41:45956] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||tckgbookkeeping.biz|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "tckgbookkeeping.biz"] [uri "/rclone.conf"] [unique_id "aqZhCkaI487Q-E164bk3lgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-13 08:35:34
(6 days ago)
Excessive multi-domain requests
Brute-Force
๐ฎ๐น
CoreTech srl
2026-09-13 08:33:56
(6 days ago)
cloudlinux2 fail2ban: 2026-09-13 10:29:15,427 fail2ban.filter [1591]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-13 10:29:15,427 fail2ban.filter [1591]: INFO [plesk-modsecurity] Found 175.137.4.25 - 2026-09-13 10:29:15cloudlinux2 fail2ban: 2026-09-13 10:29:20,512 fail2ban.actions [1591]: NOTICE [plesk-modsecurity] Unban 34.187.157.191cloudlinux2 fail2ban: 2026-09-13 10:29:43,797 fail2ban.filter [1591]: INFO [plesk-modsecurity] Found 34.135.87.41 - 2026-09-13 10:29:43cloudlinux2 fail2ban: 2026-09-13 10:29:43,768 fail2ban.filter [1591]: INFO [plesk-modsecurity] Found 34.135.87.41 - 2026-09-13 10:29:43cloudlinux2 fail2ban: 2026-09-13 10:29:43,828 fail2ban.filter [1591]: INFO [plesk-modsecurity] Found 34.135.87.41 - 2026-09-13 10:29:43cloudlinux2 fail2ban: 2026-09-13 10:29:43,811 fail2ban.filter [1591]: INFO [plesk-modsecurity] Found 34.135.87.41 - 2026-09-13 10:29:43cloudlinux2 fail2ban: 2026-09-13 10:29:43,819 fail2ban.filter [1591]: INFO [plesk-modsecurity] Found 34.135.87.41 - 2026-09-13 10:29:43cloudlinux2 fail2ban:
show less
Brute-Force
๐ณ๐ฑ
melroy89
2026-09-13 08:19:01
(6 days ago)
34.135.87.41 - - [13/Sep/2026:10:18:46 +0200] "POST / HTTP/2.0" 403 93 "-" "Mozilla/5.0 (compatible ...
show more
34.135.87.41 - - [13/Sep/2026:10:18:46 +0200] "POST / HTTP/2.0" 403 93 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)" "softstack.biz" 0.001
34.135.87.41 - - [13/Sep/2026:10:18:46 +0200] "GET /wp-json HTTP/2.0" 403 93 "-" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)" "softstack.biz" 0.000
34.135.87.41 - - [13/Sep/2026:10:18:46 +0200] "GET /ngsw.json HTTP/2.0" 403 93 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )" "softstack.biz" 0.000
34.135.87.41 - - [13/Sep/2026:10:18:46 +0200] "GET /__/firebase/init.json HTTP/2.0" 403 93 "-" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)" "softstack.biz" 0.000
34.135.87.41 - - [13/Sep/2026:10:18:46 +0200] "GET /manifest.json HTTP/2.0" 404 196 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36" "softstack.biz" 0.001
34.135.87.41 - - [13
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-13 07:51:31
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 34.135.87.41 (41.87.135.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.135.87.41 (41.87.135.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 03:51:23.577474 2026] [security2:error] [pid 13988:tid 13988] [client 34.135.87.41:60714] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rkm.biz"] [uri "/.git/config"] [unique_id "aqZV-_iDZMQXBLBeWBHvIwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
scaballe
2026-09-13 07:42:45
(6 days ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-13 07:35:42
(6 days ago)
(mod_security) mod_security (id:210730) triggered by 34.135.87.41 (41.87.135.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.135.87.41 (41.87.135.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 03:35:37.347712 2026] [security2:error] [pid 28673:tid 28673] [client 34.135.87.41:57406] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||prcs.biz|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "prcs.biz"] [uri "/rclone.conf"] [unique_id "aqZSSQ_vKZOX8ikB5d6s2wAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-13 07:14:10
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 34.135.87.41 (41.87.135.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.135.87.41 (41.87.135.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 03:14:07.031095 2026] [security2:error] [pid 16174:tid 16184] [client 34.135.87.41:32930] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "oconnorpest.biz"] [uri "/.env.backup"] [unique_id "aqZNP5HbDbVLEtWSz80r8gAAAEk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-13 07:02:11
(6 days ago)
[ti-17al] Web exploit scanning: 2 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-17al] Web exploit scanning: 2 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.135.87.41 - - [13/Sep/2026:09:02:11 +0200] "GET /.env.old HTTP/2.0" 301 486 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; OAI-SearchBot/1.0; +https://openai.com/searchbot)"
34.135.87.41 - - [13/Sep/2026:09:02:11 +0200] "GET /admin/.env HTTP/2.0" 301 490 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )"
...
show less
Bad Web Bot
Web App Attack