🇲🇽
octageeks.com
2026-09-12 04:22:14
(15 hours ago)
Wordpress malicious attack:[octablocked]
Web App Attack
🇺🇸
Lee Daniel
2026-09-11 18:24:58
(1 day ago)
34.148.101.98 - - [11/Sep/2026:14:24:57 -0400] "GET /.aws/credentials HTTP/1.1" 403 6287 "https://el ...
show more
34.148.101.98 - - [11/Sep/2026:14:24:57 -0400] "GET /.aws/credentials HTTP/1.1" 403 6287 "https://ellcorentals.com/.aws/credentials" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] )"
...
show less
DDoS Attack
Web Spam
Email Spam
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 18:24:39
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.148.101.98 (98.101.148.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.148.101.98 (98.101.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 14:24:31.791588 2026] [security2:error] [pid 17427:tid 17427] [client 34.148.101.98:48148] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ellavandeven.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ellavandeven.com"] [uri "/z9x8c7v6b5-debug-trigger-ellavandeven.com"] [unique_id "aqRHX4WYQB4gDFjtHJqaeAAAADA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 17:43:18
(1 day ago)
(mod_security) mod_security (id:210580) triggered by 34.148.101.98 (98.101.148.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210580) triggered by 34.148.101.98 (98.101.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 13:43:12.085702 2026] [security2:error] [pid 1434:tid 1434] [client 34.148.101.98:60842] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at ARGS:filename. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||elizabeth-furlow.com|F|2"] [data "Matched Data: proc/self/environ found within ARGS:filename: file:/proc/self/environ"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "elizabeth-furlow.com"] [uri "/__vite_rsc_findSourceMapURL"] [unique_id "aqQ9sKDoOfpgYOWWEc6CuwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇱🇹
Evag Touf
2026-09-11 17:42:23
(1 day ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 34.148.101.98 (US/Un ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 34.148.101.98 (US/United States/98.101.148.34.bc.googleusercontent.com)
show less
Bad Web Bot
🇺🇸
mnsf
2026-09-11 17:05:38
(1 day ago)
Scanning/Probing (12)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 17:01:30
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.148.101.98 (98.101.148.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.148.101.98 (98.101.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 13:01:22.862015 2026] [security2:error] [pid 27576:tid 27576] [client 34.148.101.98:51092] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||elissazeches.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "elissazeches.com"] [uri "/z9x8c7v6b5-debug-trigger-elissazeches.com"] [unique_id "aqQz4oYipwBMl-MFQbROfgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-11 16:48:03
(1 day ago)
Excessive multi-domain requests
Brute-Force
🇳🇱
Savvii
2026-09-11 16:45:50
(1 day ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-11 16:40:02
(1 day ago)
suspicious request in access.log
Web App Attack
🇳🇱
middelkoopcc
2026-09-11 16:36:01
(1 day ago)
2026-09-11 18:34:50 AH10244: invalid URI path (/public/plugins/grafana-clock-panel/../../../../../.. ...
show more
2026-09-11 18:34:50 AH10244: invalid URI path (/public/plugins/grafana-clock-panel/../../../../../../../../proc/self/environ) && 2026-09-11 18:34:50 AH10244: invalid URI path (/public/plugins/text/../../../../../../../../proc/self/environ) && 2026-09-11 18:34:51 AH10244: invalid URI path (/%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env) && 189 more within 20 minutes
show less
Web App Attack
🇬🇧
consul.to
2026-09-11 16:33:48
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
🇫🇷
masterguru
2026-09-11 16:31:50
(1 day ago)
BAD BOT - Detected and Blocked.. Matched phrase "baidu" at REQUEST_HEADERS:User-Agent. (1100000-196)
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-11 16:26:31
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.148.101.98 (98.101.148.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.148.101.98 (98.101.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 12:26:25.781180 2026] [security2:error] [pid 3867:tid 3867] [client 34.148.101.98:40454] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||elevese.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "elevese.com"] [uri "/z9x8c7v6b5-debug-trigger-elevese.com"] [unique_id "aqQrsRD6B3t168BdlF9u-gAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-11 16:14:24
(1 day ago)
34.148.101.98 - - [11/Sep/2026:11:14:22 -0500] "GET /.env?import&raw HTTP/1.1" 403 199 "-" "Mozilla/ ...
show more
34.148.101.98 - - [11/Sep/2026:11:14:22 -0500] "GET /.env?import&raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" 34.148.101.98
34.148.101.98 - - [11/Sep/2026:11:14:22 -0500] "GET /.env?import&url&inline HTTP/1.1" 403 199 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)" 34.148.101.98
34.148.101.98 - - [11/Sep/2026:11:14:22 -0500] "GET /.env?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)" 34.148.101.98
34.148.101.98 - - [11/Sep/2026:11:14:22 -0500] "GET /.env.local?import&raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 34.148.101.98
34.148.101.98 - - [11/Sep/2026:11:14:22 -0500] "GET /.env.production?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 34.148.101.98
34.148.101.98 - - [11/Sep/2026:11:14:22 -0500] "GE
...
show less
Brute-Force
Bad Web Bot
Web App Attack