๐ฎ๐ณ
evicky2002
2026-08-09 06:00:00
(1 month ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ฉ๐ช
tvipper.com
2026-08-08 22:27:02
(1 month ago)
Auto reported by IDS
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-08 22:25:39
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 34.146.69.172 (172.69.146.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.146.69.172 (172.69.146.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 08 18:25:35.091230 2026] [security2:error] [pid 651915:tid 651915] [client 34.146.69.172:59282] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||goatedlottosecrets.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "goatedlottosecrets.com"] [uri "/z9x8c7v6b5-debug-trigger-goatedlottosecrets.com"] [unique_id "anes3y_NFVYbZWDgTU7-iAAAAFw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-08-08 21:29:29
(1 month ago)
3.538 requests from abuseipdb.com blacklisted IP (10mos2w6d)
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-08 21:06:41
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 34.146.69.172 (172.69.146.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.146.69.172 (172.69.146.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 08 17:06:37.245676 2026] [security2:error] [pid 927026:tid 927026] [client 34.146.69.172:60924] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||good4sound.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "good4sound.com"] [uri "/z9x8c7v6b5-debug-trigger-good4sound.com"] [unique_id "aneaXTQyYvQMtuxCtx4SDwAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-08 20:41:24
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 34.146.69.172 (172.69.146.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.146.69.172 (172.69.146.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 08 16:41:17.555439 2026] [security2:error] [pid 3969:tid 3969] [client 34.146.69.172:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "globetechsecurities.com"] [uri "/.git/config"] [unique_id "aneUbU7nfmn5NYWiEIlAawAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-08 20:35:21
(1 month ago)
Blocked by ModSec and CSF
Port Scan
๐บ๐ธ
TPI-Abuse
2026-08-08 20:17:56
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 34.146.69.172 (172.69.146.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.146.69.172 (172.69.146.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 08 16:17:52.013586 2026] [security2:error] [pid 980515:tid 980515] [client 34.146.69.172:46398] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.bigholegolf.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.bigholegolf.com"] [uri "/rclone.conf"] [unique_id "aneO8EdVQCOt4FmzwsYbZgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-08-08 20:11:21
(1 month ago)
Restricted File Access Attempt. Matched phrase ".aws/" at REQUEST_FILENAME. (930130-196)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-08 19:56:05
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 34.146.69.172 (172.69.146.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.146.69.172 (172.69.146.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 08 15:56:01.845216 2026] [security2:error] [pid 161878:tid 161878] [client 34.146.69.172:43110] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.gowithevergreen.com|F|2"] [data ".gowithevergreen.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.gowithevergreen.com"] [uri "/z9x8c7v6b5-debug-trigger-www.gowithevergreen.com"] [unique_id "aneJ0fymIOLVLROQ8ugXhwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Lee Daniel
2026-08-08 19:52:05
(1 month ago)
34.146.69.172 - - [08/Aug/2026:15:52:05 -0400] "GET /.aws/credentials HTTP/1.1" 403 6281 "-" "anthro ...
show more
34.146.69.172 - - [08/Aug/2026:15:52:05 -0400] "GET /.aws/credentials HTTP/1.1" 403 6281 "-" "anthropic-ai"
...
show less
DDoS Attack
Web Spam
Email Spam
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-08-08 19:29:44
(1 month ago)
CrowdSec: crowdsecurity/http-probing | req: /.git/config | 11 distinct paths | UA: Mozilla/5.0 Apple ...
show more
CrowdSec: crowdsecurity/http-probing | req: /.git/config | 11 distinct paths | UA: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; Claude-User/1.0; +mailto:[email protected]
show less
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-08 19:25:20
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 34.146.69.172 (172.69.146.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.146.69.172 (172.69.146.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 08 15:25:12.473823 2026] [security2:error] [pid 832674:tid 832674] [client 34.146.69.172:46420] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||globalaccessau.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "globalaccessau.com"] [uri "/z9x8c7v6b5-debug-trigger-globalaccessau.com"] [unique_id "aneCmP_OXr9wm66xYHlxngAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-08 18:57:36
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 34.146.69.172 (172.69.146.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.146.69.172 (172.69.146.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 08 14:57:31.336013 2026] [security2:error] [pid 6218:tid 6218] [client 34.146.69.172:43958] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "goodfrequencies.com"] [uri "/.git/HEAD"] [unique_id "and8G2fIKIvCrDiR5nhA_QAAAEs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-08 18:22:41
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 34.146.69.172 (172.69.146.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.146.69.172 (172.69.146.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 08 14:22:36.519635 2026] [security2:error] [pid 176283:tid 176283] [client 34.146.69.172:40330] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "glencottagemusic.com"] [uri "/.git/HEAD"] [unique_id "andz7Csuh4YYSEs2hIxXrAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack