๐ซ๐ท
IRISIO
2026-10-01 08:26:48
(11 hours ago)
scans/SQL injection/spam posts : 2089 queries
Web App Attack
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-09-30 16:11:01
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.178.191.87 (87.191.178.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.178.191.87 (87.191.178.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 12:10:56.404415 2026] [security2:error] [pid 14188:tid 14188] [client 34.178.191.87:35914] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.pixals.net"] [uri "/files../.env"] [unique_id "ar00kOO6TUS-P8dOkbcjgwAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-30 16:10:52
(1 day ago)
[ti-01al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apac ...
show more
[ti-01al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apache-404. Example: 34.178.191.87 - - [30/Sep/2026:18:10:47 +0200] "GET /model/info HTTP/2.0" 404 1855 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] )"
34.178.191.87 - - [30/Sep/2026:18:10:47 +0200] "GET /secure HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
34.178.191.87 - - [30/Sep/2026:18:10:47 +0200] "GET /users/login HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
34.178.191.87 - - [30/Sep/2026:18:10:47 +0200] "GET /login HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like
...
show less
Bad Web Bot
Web App Attack
๐ซ๐ท
IRISIO
2026-09-30 16:10:30
(1 day ago)
scans/SQL injection/spam posts : 938 queries
Web App Attack
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-09-30 15:38:14
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.178.191.87 (87.191.178.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.178.191.87 (87.191.178.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 11:38:10.499711 2026] [security2:error] [pid 31590:tid 31590] [client 34.178.191.87:42482] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "antech.net"] [uri "/files../.env"] [unique_id "ar0s4kGOO4BgWC3rG2_9GAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 15:22:38
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.178.191.87 (87.191.178.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.178.191.87 (87.191.178.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 11:22:32.299071 2026] [security2:error] [pid 5159:tid 5159] [client 34.178.191.87:46696] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "elpaco.net"] [uri "/.env.development"] [unique_id "ar0pODnSfXA9V1Pij1_ZnAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-30 15:19:07
(1 day ago)
[Wed Sep 30 07:17:24.140944 2026] [authz_core:error] [pid 20232] [client 34.178.191.87:60474] AH0163 ...
show more
[Wed Sep 30 07:17:24.140944 2026] [authz_core:error] [pid 20232] [client 34.178.191.87:60474] AH01630: client denied by server configuration: /var/www/api/.htpasswd
[Wed Sep 30 07:17:25.061570 2026] [authz_core:error] [pid 15939] [client 34.178.191.87:60436] AH01630: client denied by server configuration: /var/www/api/server-status
[Wed Sep 30 08:57:04.603480 2026] [authz_core:error] [pid 1355] [client 34.178.191.87:36144] AH01630: client denied by server configuration: /var/www/api/.htpasswd
[Wed Sep 30 08:57:05.372455 2026] [authz_core:error] [pid 32665] [client 34.178.191.87:36138] AH01630: client denied by server configuration: /var/www/api/server-status
[Wed Sep 30 11:19:03.367260 2026] [authz_core:error] [pid 22516] [client 34.178.191.87:43444] AH01630: client denied by server configuration: /var/www/api/server-status
[Wed Sep 30 11:19:07.246617 2026] [authz_core:error] [pid 23372] [client 34.178.191.87:43538] AH01630: client denied by server configuration: /var/www/api/.htpasswd
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
sernate
2026-09-30 15:13:11
(1 day ago)
(404blocker) 404 trigger 34.178.191.87 (87.191.178.34.bc.googleusercontent.com): 80 in the last 3600 ...
show more
(404blocker) 404 trigger 34.178.191.87 (87.191.178.34.bc.googleusercontent.com): 80 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER
show less
Brute-Force
๐ณ๐ฑ
Site.eu
2026-09-30 14:54:22
(1 day ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-30 14:32:54
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.178.191.87 (87.191.178.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.178.191.87 (87.191.178.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 10:32:48.185119 2026] [security2:error] [pid 24569:tid 24569] [client 34.178.191.87:38226] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||804web.net|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "804web.net"] [uri "/rclone.conf"] [unique_id "ar0dkHVjD9wvrshM0JIhhwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
IRISIO
2026-09-30 13:04:55
(1 day ago)
scans/SQL injection/spam posts : 456 queries
Web App Attack
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-09-30 12:46:26
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.178.191.87 (87.191.178.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.178.191.87 (87.191.178.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 08:46:22.775368 2026] [security2:error] [pid 30496:tid 30496] [client 34.178.191.87:52584] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bartholow.net"] [uri "/.htpasswd"] [unique_id "ar0EnvNPOCKHWIobQe4oSQAAACo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 12:11:35
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.178.191.87 (87.191.178.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.178.191.87 (87.191.178.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 08:11:31.907759 2026] [security2:error] [pid 26380:tid 26380] [client 34.178.191.87:59320] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.crazycoin.net"] [uri "/static../.env"] [unique_id "arz8c_LTVcTrD4bGLdv2MQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 11:37:21
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.178.191.87 (87.191.178.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.178.191.87 (87.191.178.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 07:37:13.775141 2026] [security2:error] [pid 6977:tid 6977] [client 34.178.191.87:49760] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "antiradares.net"] [uri "/.git/HEAD"] [unique_id "arz0aabzwPsRTIFumonnFwAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
Mediashaker
2026-09-30 11:12:45
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted] 34.178.191.87 (87.191.178.34.bc.googleu ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.178.191.87 (87.191.178.34.bc.googleusercontent.com)
show less
SQL Injection