๐ฎ๐ณ
evicky2002
2026-07-21 06:00:00
(8 hours ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
Anonymous
2026-07-21 00:00:00
(14 hours ago)
"Security violation, excess traffic against library/education infrastructure"
Brute-Force
๐ฎ๐ฉ
Burayot
2026-07-20 12:55:31
(1 day ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 34.16.143.237 (US/United States/237 ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 34.16.143.237 (US/United States/237.143.16.34.bc.googleusercontent.com): 2 in the last 3600 secs
show less
Web App Attack
Anonymous
2026-07-20 12:35:57
(1 day ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-07-20 12:11:55
(1 day ago)
COMODO WAF: URL file extension is restricted by policy. Match of "pmFromFile userdata_wl_extensions" ...
show more
COMODO WAF: URL file extension is restricted by policy. Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. (210730-143)
show less
Hacking
๐จ๐ญ
backslash
2026-07-20 10:27:00
(1 day ago)
Bad Web Bot
Anonymous
2026-07-20 10:25:58
(1 day ago)
"GET /config/.env HTTP/1.1"
Hacking
Web App Attack
๐ณ๐ฟ
Antinson
2026-07-20 09:58:56
(1 day ago)
Scraping with a high error ratio and request rate
Bad Web Bot
๐ซ๐ท
IRISIO
2026-07-20 09:39:26
(1 day ago)
scans/SQL injection/spam posts : 158 queries
Web App Attack
SQL Injection
๐ซ๐ท
LoneRider
2026-07-20 09:23:37
(1 day ago)
[20/Jul/2026:11:23:36.715085 +0200] al3pGAGL0jM_LnVhMW3tzQAAAAg 34.16.143.237 42606 127.0.0.1 7081
[ ...
show more
[20/Jul/2026:11:23:36.715085 +0200] al3pGAGL0jM_LnVhMW3tzQAAAAg 34.16.143.237 42606 127.0.0.1 7081
[20/Jul/2026:11:23:36.854721 +0200] al3pGNGqo1qvsyHvCP207QAAAAY 34.16.143.237 42624 127.0.0.1 7081
[20/Jul/2026:11:23:36.868422 +0200] al3pGBWSsUYRbTwpz6TAFAAAAAU 34.16.143.237 42658 127.0.0.1 7081
...
show less
Hacking
๐ณ๐ฑ
ConsulHosting
2026-07-20 09:19:06
(1 day ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 09:01:17
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.16.143.237 (237.143.16.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.16.143.237 (237.143.16.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 05:01:11.099324 2026] [security2:error] [pid 3084:tid 3084] [client 34.16.143.237:41376] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.justinrudd.com"] [uri "/.git/HEAD"] [unique_id "al3j19oRGheW_05yzqGTLgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
NotCool
2026-07-20 08:32:24
(1 day ago)
[7200] (CRAWLDELAY,ABUSIVEBOT,DOTENVPROBE) Login failure/trigger from 34.16.143.237 (US/United State ...
show more
[7200] (CRAWLDELAY,ABUSIVEBOT,DOTENVPROBE) Login failure/trigger from 34.16.143.237 (US/United States/237.143.16.34.bc.googleusercontent.com): 50 in the last 3600 secs
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-20 08:13:39
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.16.143.237 (237.143.16.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.16.143.237 (237.143.16.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 04:13:31.272518 2026] [security2:error] [pid 22187:tid 22187] [client 34.16.143.237:47780] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "grabagame.com"] [uri "/.git/config"] [unique_id "al3Yq9OA9VIaGLbPgcJVUgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 07:28:12
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.16.143.237 (237.143.16.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.16.143.237 (237.143.16.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 03:28:06.385353 2026] [security2:error] [pid 3666782:tid 3666782] [client 34.16.143.237:51940] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.donutlocations.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.donutlocations.com"] [uri "/rclone.conf"] [unique_id "al3OBtaiu7Z0ioop0mbAwwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack