๐ง๐ช
cmbplf
2026-09-25 20:45:18
(2 hours ago)
118 requests with url.path */@fs/*
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-25 19:50:56
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.143.153.177 (177.153.143.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.143.153.177 (177.153.143.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 25 15:50:49.614633 2026] [security2:error] [pid 24279:tid 24306] [client 34.143.153.177:46292] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||peoplewith.ai|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "peoplewith.ai"] [uri "/config/master.key"] [unique_id "arbQmY9Jvj62DXcG7pRiCgAAAE8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-25 19:35:18
(3 hours ago)
Excessive 404/403 errors
Brute-Force
๐ธ๐ช
vaia.cloud
2026-09-25 17:40:01
(5 hours ago)
crowdsecurity/http-path-traversal-probing
Brute-Force
Web App Attack
๐ฌ๐ง
consul.to
2026-09-25 17:22:09
(6 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐ช๐ธ
pipeline.es
2026-09-24 08:59:15
(1 day ago)
Web scanning / probing for vulnerable paths
Port Scan
Web App Attack
๐ฉ๐ช
updown.io
2026-09-24 02:52:15
(1 day ago)
{"level":"info","ts":1790218324.2476385,"logger":"http.log.access.log1","msg":"handled request","req ...
show more
{"level":"info","ts":1790218324.2476385,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.143.153.177","remote_port":"52560","client_ip":"34.143.153.177","proto":"HTTP/2.0","method":"GET","host":"status.paratira.ai","uri":"/dist/manifest.json","headers":{"Sec-Ch-Ua-Platform":["\"Windows\""],"X-Middleware-Subrequest":["src/middleware:nowaf:src/middleware:src/middleware:src/middleware:src/middleware:middleware:middleware:nowaf:middleware:middleware:middleware:pages/_middleware"],"Accept":["text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8"],"Accept-Encoding":["gzip, deflate, br, zstd"],"Sec-Ch-Ua":["\"Chromium\";v=\"152\", \"Not?A_Brand\";v=\"24\", \"Brave\";v=\"152\""],"Sec-Fetch-Dest":["document"],"Sec-Fetch-User":["?1"],"Upgrade-Insecure-Requests":["1"],"Sec-Ch-Ua-Mobile":["?0"],"X-Nextjs-Data":["1"],"Accept-Language":["en-US,en;q=0.9"],"User-Agent":["Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTM
...
show less
DDoS Attack
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-24 00:55:23
(1 day ago)
[ti-17al] Web exploit scanning: 2 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-17al] Web exploit scanning: 2 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.143.153.177 - - [24/Sep/2026:02:55:11 +0200] "GET /.ssh/id_ed25519 HTTP/2.0" 404 2004 "-" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)"
34.143.153.177 - - [24/Sep/2026:02:55:11 +0200] "GET /.ssh/config HTTP/2.0" 404 2004 "-" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 00:38:09
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.143.153.177 (177.153.143.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.143.153.177 (177.153.143.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 20:38:06.160509 2026] [security2:error] [pid 794:tid 794] [client 34.143.153.177:55650] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "woaa.ospectra.ai"] [uri "/.htpasswd"] [unique_id "arRw7vq96jwu8KOePL0fjwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
pipeline.es
2026-09-24 00:26:39
(1 day ago)
Web scanning / probing for vulnerable paths | URL: /.env.production?raw | Evidence: www.ysiviajas.es ...
show more
Web scanning / probing for vulnerable paths | URL: /.env.production?raw | Evidence: www.ysiviajas.es 34.143.153.177 - - [24/Sep/2026:02:26:12 +0200] \"GET /.env.production?raw HTTP/1.1\" 404 10472 \"-\" \"Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email])\" GEOIP_COUNTRY_CODE=SG | ASN: GOOGLE-CLOUD-PLATFORM | Country: SG
show less
Port Scan
Web App Attack
Anonymous
2026-09-23 22:44:43
(2 days ago)
Repeated unauthorized connection attempts to restricted service observed.
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-23 22:13:21
(2 days ago)
Excessive 404/403 errors
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-23 21:47:34
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.143.153.177 (177.153.143.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.143.153.177 (177.153.143.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 17:47:27.591469 2026] [security2:error] [pid 13573:tid 13573] [client 34.143.153.177:42508] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.madisonmedia.ai"] [uri "/@fs/src/.env"] [unique_id "arRI737Na9Q5k-udGz8FIgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 19:58:44
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.143.153.177 (177.153.143.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.143.153.177 (177.153.143.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 15:58:40.975201 2026] [security2:error] [pid 8904:tid 8904] [client 34.143.153.177:41524] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.chatari.ai|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.chatari.ai"] [uri "/configuration.php.bak"] [unique_id "arQvcFBBdJgFZX3XnFpKzwAAACs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 18:28:36
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.143.153.177 (177.153.143.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.143.153.177 (177.153.143.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 14:28:32.725171 2026] [security2:error] [pid 25206:tid 25206] [client 34.143.153.177:46054] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.ameliaschaaf.lawyer"] [uri "/.env.example"] [unique_id "arQaUB7Q27FqdFmMLNLQaQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack