🇫🇷
SpaceHost-Server
2026-09-12 22:18:47
(2 hours ago)
Brute-Force
Web App Attack
🇳🇱
Site.eu
2026-09-12 18:55:32
(5 hours ago)
Excessive 404/403 errors
Brute-Force
🇬🇧
consul.to
2026-09-12 18:09:54
(6 hours ago)
Web attack/malicious scanning detected
Web App Attack
Anonymous
2026-09-12 17:10:49
(7 hours ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
🇺🇸
TPI-Abuse
2026-09-12 05:35:12
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.156.55.12 (12.55.156.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.156.55.12 (12.55.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 01:35:05.098420 2026] [security2:error] [pid 2145:tid 2145] [client 34.156.55.12:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.grainavi.com"] [uri "/@fs/../.env"] [unique_id "aqTkiSpjDckunawBv30dFQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
ghostwarriors
2026-09-11 18:20:08
(1 day ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
🇩🇪
yitzhaq
2026-09-11 17:51:36
(1 day ago)
34.156.55.12 - - [11/Sep/2026:19:51:31 +0200] "GET /__/firebase/init.json HTTP/2.0" 404 299 "-" "Moz ...
show more
34.156.55.12 - - [11/Sep/2026:19:51:31 +0200] "GET /__/firebase/init.json HTTP/2.0" 404 299 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)"
34.156.55.12 - - [11/Sep/2026:19:51:31 +0200] "GET /values.yaml HTTP/2.0" 404 299 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)"
34.156.55.12 - - [11/Sep/2026:19:51:31 +0200] "GET /web.config HTTP/2.0" 404 299 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot)"
34.156.55.12 - - [11/Sep/2026:19:51:31 +0200] "GET /local.settings.json HTTP/2.0" 404 299 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
34.156.55.12 - - [11/Sep/2026:19:51:31 +0200] "GET /appsettings.Production.json HTTP/2.0" 404 299 "-" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)"
34.156.55.12 - - [11/Sep/2026:19:51:31 +0200] "GET /api/config HTTP/2.0" 404 299 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; P
show less
Web App Attack
Hacking
🇩🇪
akasolutions.de
2026-09-11 17:47:14
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted] 34.156.55.12 (BE/Belgium/12.55.156.34.b ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.156.55.12 (BE/Belgium/12.55.156.34.bc.googleusercontent.com)
show less
SQL Injection
🇲🇾
Rizzy
2026-09-11 17:38:43
(1 day ago)
Multiple WAF Violations
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 17:32:04
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.156.55.12 (12.55.156.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.156.55.12 (12.55.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 13:31:59.047541 2026] [security2:error] [pid 5542:tid 5567] [client 34.156.55.12:48632] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||greencitymethods.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "greencitymethods.com"] [uri "/rclone.conf"] [unique_id "aqQ7D9Qu3Ff9ZK7A7tq9hgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-11 17:22:25
(1 day ago)
Excessive 404/403 errors
Brute-Force
🇺🇸
TPI-Abuse
2026-09-11 17:15:07
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.156.55.12 (12.55.156.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.156.55.12 (12.55.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 13:14:59.172099 2026] [security2:error] [pid 8489:tid 8489] [client 34.156.55.12:57168] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||greatwesternfirearms.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "greatwesternfirearms.com"] [uri "/rclone.conf"] [unique_id "aqQ3Ez8Wo2e0GkIYHHXPYAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
RJ
2026-09-11 17:00:04
(1 day ago)
fail2ban: wiederholte missbraeuchliche Zugriffe auf greatconflict.com (HTTP rate-limit abuse) - auto ...
show more
fail2ban: wiederholte missbraeuchliche Zugriffe auf greatconflict.com (HTTP rate-limit abuse) - automatische Meldung.
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 16:50:51
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.156.55.12 (12.55.156.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.156.55.12 (12.55.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 12:50:47.196317 2026] [security2:error] [pid 22151:tid 22151] [client 34.156.55.12:40616] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||grdigitaldesigns.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "grdigitaldesigns.com"] [uri "/rclone.conf"] [unique_id "aqQxZ9mnok0yUZCUorcIfQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-11 16:44:48
(1 day ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack