๐ณ๐ฑ
Savvii
2026-05-27 18:19:36
(1 week ago)
20 attempts against mh-misbehave-ban on eris
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-05-27 16:10:17
(1 week ago)
20 attempts against mh-misbehave-ban on kiwi
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-27 12:53:44
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 34.156.47.194 (194.47.156.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.156.47.194 (194.47.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 27 08:53:37.054122 2026] [security2:error] [pid 30477:tid 30477] [client 34.156.47.194:50468] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.walkenfeld.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.walkenfeld.com"] [uri "/.config/gcloud/credentials.db"] [unique_id "ahbpUX2ztsV5zxccVbRstwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-27 11:47:06
(1 week ago)
34.156.47.194 detected on srv01
Brute-Force
๐ฉ๐ช
XICTRON
2026-05-27 11:00:07
(1 week ago)
ModSecurity rule violation detected by Fail2Ban
Web App Attack
๐ฉ๐ช
grassau.com
2026-05-27 10:29:38
(1 week ago)
*Port Scan* detected from 34.156.47.194 (BE/Belgium/Brussels Capital/Brussels/194.47.156.34.bc.googl ...
show more
*Port Scan* detected from 34.156.47.194 (BE/Belgium/Brussels Capital/Brussels/194.47.156.34.bc.googleusercontent.com).
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-05-27 07:48:42
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.156.47.194 (194.47.156.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.156.47.194 (194.47.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 27 03:48:35.402496 2026] [security2:error] [pid 26093:tid 26093] [client 34.156.47.194:45122] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/config/parameters.yml" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.zebax.com"] [uri "/config/parameters.yml"] [unique_id "ahah02F-gPlQrKRsKurvAgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
ConsulHosting
2026-05-27 06:22:38
(1 week ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
Anonymous
2026-05-27 06:06:08
(1 week ago)
WAF repeated trigger detected by Fail2Ban
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-27 04:29:43
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 34.156.47.194 (194.47.156.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.156.47.194 (194.47.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 27 00:29:37.535165 2026] [security2:error] [pid 5758:tid 5758] [client 34.156.47.194:51222] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.instantanything.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.instantanything.com"] [uri "/.config/gcloud/credentials.db"] [unique_id "ahZzMdVec4tioHxQ1t9ivAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-26 23:41:13
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 34.156.47.194 (194.47.156.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.156.47.194 (194.47.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 26 19:41:07.384089 2026] [security2:error] [pid 28710:tid 28710] [client 34.156.47.194:47444] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.perkowski.net|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.perkowski.net"] [uri "/.config/gcloud/credentials.db"] [unique_id "ahYvk90ZzQ2MK-ziAJv9TwAAAC8"]
show less
Brute-Force
Bad Web Bot
Web App Attack