๐บ๐ธ
[email protected]
2026-09-22 10:30:42
(6 days ago)
CrowdSec ban: crowdsecurity/unifi-flood-detection (duration: 71h59m54s)
Port Scan
๐บ๐ธ
Charlesiv
2026-09-22 02:09:08
(6 days ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Prot ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/2 (GET method)
Endpoint: /.ssh/id_ed25519
Timestamp: 2026-09-22T00:56:31Z
Ray ID: a3ed59accde2b0a5
UA: Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-21 22:27:45
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 34.148.82.144 (144.82.148.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.148.82.144 (144.82.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 18:27:37.849939 2026] [security2:error] [pid 32117:tid 32172] [client 34.148.82.144:39000] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.kaukabsiddique.net"] [uri "/.env.prod"] [unique_id "arGvWejPE2gcsqkHyJSt7QAAAEA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
monn45888
2026-09-21 22:20:27
(6 days ago)
$f2bV_matches
Web App Attack
๐ฉ๐ช
pscriptos
2026-09-21 22:19:59
(6 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/appsec-vpatch
Web App Attack
๐ฉ๐ช
itsolon
2026-09-21 22:18:24
(6 days ago)
[22/Sep/2026:00:18:24 +0200] 179002910421.099689 34.148.82.144 44262 217.154.7.177 443
[22/Sep/2026: ...
show more
[22/Sep/2026:00:18:24 +0200] 179002910421.099689 34.148.82.144 44262 217.154.7.177 443
[22/Sep/2026:00:18:24 +0200] 179002910464.790684 34.148.82.144 44262 217.154.7.177 443
[22/Sep/2026:00:18:24 +0200] 179002910444.428302 34.148.82.144 44262 217.154.7.177 443
[22/Sep/2026:00:18:24 +0200] 179002910431.508534 34.148.82.144 44262 217.154.7.177 443
[22/Sep/2026:00:18:24 +0200] 179002910419.206519 34.148.82.144 44262 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
๐ฆ๐บ
Terrier
2026-09-21 22:00:01
(6 days ago)
Blocked for HTTP vulnerability scanning (excessive 40x)
Web App Attack
๐ณ๐ฑ
oisecnet
2026-09-21 21:02:23
(6 days ago)
Automated report: Unauthorized vulnerability scanning detected on 2026-09-21. 507 requests from this ...
show more
Automated report: Unauthorized vulnerability scanning detected on 2026-09-21. 507 requests from this IP.
show less
Port Scan
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 21:01:55
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 34.148.82.144 (144.82.148.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.148.82.144 (144.82.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 17:01:49.356127 2026] [security2:error] [pid 26206:tid 26206] [client 34.148.82.144:44032] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.yeejia.net"] [uri "/.env.production"] [unique_id "arGbPU_xyZK39MTIsa8G6QAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
NewWavesApp
2026-09-21 20:51:58
(6 days ago)
(mod_security) mod_security triggered on hostname [redacted] 34.148.82.144 (US/United States/144.82. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.148.82.144 (US/United States/144.82.148.34.bc.googleusercontent.com): (CF_ENABLE)
show less
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-09-21 20:23:57
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 34.148.82.144 (144.82.148.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.148.82.144 (144.82.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 16:23:49.723483 2026] [security2:error] [pid 22508:tid 22508] [client 34.148.82.144:56152] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vrmapping.net"] [uri "/.git/config"] [unique_id "arGSVa5uR39hlq-jagwyXwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 19:25:03
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 34.148.82.144 (144.82.148.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.148.82.144 (144.82.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 15:24:56.629636 2026] [security2:error] [pid 6290:tid 6290] [client 34.148.82.144:55914] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.schoolsliaisoncommunity.net|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.schoolsliaisoncommunity.net"] [uri "/ssl/localhost.key"] [unique_id "arGEiKSh_NkAw_G6j_SLHgAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-21 19:19:12
(1 week ago)
http scanning for .env files
...
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 19:04:23
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.148.82.144 (144.82.148.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.148.82.144 (144.82.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 15:04:17.179232 2026] [security2:error] [pid 14862:tid 14862] [client 34.148.82.144:35896] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "arthuryeung.net"] [uri "/.git/config"] [unique_id "arF_sZRfToSCUCOhXaSNDAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
firestorm
2026-09-21 17:45:41
(1 week ago)
34.148.82.144 - - [21/Sep/2026:19:45:40 +0200] "GET /public/plugins/alertlist/../../../../../../../. ...
show more
34.148.82.144 - - [21/Sep/2026:19:45:40 +0200] "GET /public/plugins/alertlist/../../../../../../../../proc/self/environ HTTP/1.1" 400 150 "-" "-"
34.148.82.144 - - [21/Sep/2026:19:45:40 +0200] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fproc/self/environ HTTP/1.1" 400 150 "-" "-"
...
show less
Brute-Force
Web App Attack