๐บ๐ธ
markawes
2026-05-27 16:30:12
(3 months ago)
[markis] Auto banned by Fail2Ban. Reason: Malicious web scan / attempted access to sensitive paths. ...
show more
[markis] Auto banned by Fail2Ban. Reason: Malicious web scan / attempted access to sensitive paths. Evidence:
34.159.62.202 - - [27/May/2026:17:30:10 +0100] "GET /actuator/sessions HTTP/1.1" 404 3064 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chromium/71.0.3578.98 Chrome/71.0.3578.98 Safari/537.36"
34.159.62.202 - - [27/May/2026:17:30:10 +0100] "GET /actuator/trace HTTP/1.1" 404 3064 "-" "Mozilla/5.0 (Linux; Android 7.1.2; FP2) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3880.0 Mobile Safari/537.36"
34.159.62.202 - - [27/May/2026:17:30:10 +0100] "GET /actuator/env HTTP/1.1" 404 3064 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/73.0.3683.75 Safari/537.36"
show less
Port Scan
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-27 10:13:55
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 34.159.62.202 (202.62.159.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.159.62.202 (202.62.159.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 27 06:13:50.033346 2026] [security2:error] [pid 852:tid 852] [client 34.159.62.202:44868] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/config/parameters.yml" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.henrietteg.com"] [uri "/app/config/parameters.yml"] [unique_id "ahbD3r41tlpj6E8KwL0HTAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-05-27 09:37:45
(3 months ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
ConsulHosting
2026-05-27 07:17:36
(3 months ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-27 07:11:39
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 34.159.62.202 (202.62.159.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.159.62.202 (202.62.159.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 27 03:11:32.470464 2026] [security2:error] [pid 18288:tid 18288] [client 34.159.62.202:60044] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||ftp.cmcnow.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ftp.cmcnow.com"] [uri "/.config/gcloud/credentials.db"] [unique_id "ahaZJPbkeVBJ04udNxQnLQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-27 04:56:10
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 34.159.62.202 (202.62.159.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.159.62.202 (202.62.159.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 27 00:56:02.548546 2026] [security2:error] [pid 13942:tid 13942] [client 34.159.62.202:58562] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/config/config.yml" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.sexycyborg.net"] [uri "/config/config.yml"] [unique_id "ahZ5Ykekgy_IQTg386CGjgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Matthew Ping
2026-05-27 04:45:01
(3 months ago)
ModSecurity rule 949110 triggered on dedicated4785. Web application attack blocked by CSF/LFD.
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-05-27 04:40:03
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 34.159.62.202 (202.62.159.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.159.62.202 (202.62.159.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 27 00:39:56.409361 2026] [security2:error] [pid 23384:tid 23384] [client 34.159.62.202:55354] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.khoner.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.khoner.com"] [uri "/.config/gcloud/credentials.db"] [unique_id "ahZ1nOTPNC_pOUbAFiMxxgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2026-05-27 04:33:26
(3 months ago)
Attempted access to sensitive endpoint (/config/aws.json) detected. Automated scan or unauthorized p ...
show more
Attempted access to sensitive endpoint (/config/aws.json) detected. Automated scan or unauthorized probing.
show less
Web App Attack
๐ฉ๐ช
jasperedv.de
2026-05-27 03:37:46
(3 months ago)
Apache Login - Brutforcing
Web App Attack
Brute-Force
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-05-27 03:30:05
(3 months ago)
SPAM - Bruteforce Attack - DDOS 2
Email Spam
Brute-Force
Anonymous
2026-05-27 02:10:07
(3 months ago)
Automated report from Fail2Ban firewall ban
Brute-Force
SSH
IoT Targeted
๐บ๐ธ
ipblock.com
2026-05-27 00:17:00
(3 months ago)
IPBlock protected site ID [1365-l].
Exploit request, vulnerability scanner.
Hacking
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-05-27 00:14:28
(3 months ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
Anonymous
2026-05-27 00:05:30
(3 months ago)
WAF repeated trigger detected by Fail2Ban
Web App Attack