๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-10-01 17:35:34
(8 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-01 16:06:08
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.179.246.246 (246.246.179.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.179.246.246 (246.246.179.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 12:06:04.043203 2026] [security2:error] [pid 17589:tid 17589] [client 34.179.246.246:56464] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.mintgames.com"] [uri "/files../.env"] [unique_id "ar6E7H_7wIqeiZ5QPMa3RwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-10-01 14:47:22
(11 hours ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-10-01 14:18:44
(11 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.179.246.246 (246.246.179.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.179.246.246 (246.246.179.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 10:18:38.971135 2026] [security2:error] [pid 20382:tid 20382] [client 34.179.246.246:57024] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||machineryenchantress.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "machineryenchantress.com"] [uri "/z9x8c7v6b5-debug-trigger-machineryenchantress.com"] [unique_id "ar5rvmghCGyNWFxhRjHHkQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-01 13:14:03
(13 hours ago)
[cb-06al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail ngin ...
show more
[cb-06al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail nginx-404. Example: 34.179.246.246 - - [01/Oct/2026:15:14:00 +0200] "GET /.vite/manifest.json HTTP/2.0" 404 1338 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Mobile Safari/537.36"
34.179.246.246 - - [01/Oct/2026:15:14:00 +0200] "GET /dist/.vite/manifest.json HTTP/2.0" 404 1338 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Mobile Safari/537.36"
34.179.246.246 - - [01/Oct/2026:15:14:00 +0200] "POST /icecoder/lib/terminal-xhr.php HTTP/2.0" 404 1338 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)"
34.179.246.246 - - [01/Oct/2026:15:14:00 +0200] "GET /build/manifest.json HTTP/2.0" 404 20361 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Mobile
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 12:16:48
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.179.246.246 (246.246.179.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.179.246.246 (246.246.179.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 08:16:40.176233 2026] [security2:error] [pid 31868:tid 31868] [client 34.179.246.246:58292] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.pappakotis.net"] [uri "/images../.env"] [unique_id "ar5PKOsezo88or91NcjcaAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 11:25:29
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.179.246.246 (246.246.179.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.179.246.246 (246.246.179.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 07:25:24.111764 2026] [security2:error] [pid 10603:tid 10603] [client 34.179.246.246:36324] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.legionellaexperts.org"] [uri "/.htpasswd"] [unique_id "ar5DJLadCU_Gpv5r2bsPcAAAACw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
masterguru
2026-10-01 11:19:55
(14 hours ago)
BAD BOT - Detected and Blocked.. Matched phrase "bytespider" at REQUEST_HEADERS:user-agent. (1100000 ...
show more
BAD BOT - Detected and Blocked.. Matched phrase "bytespider" at REQUEST_HEADERS:user-agent. (1100000-122)
show less
Bad Web Bot
๐ฟ๐ฆ
conure.sh
2026-10-01 11:13:46
(15 hours ago)
csagent: score 19.0: 404 noise floor x36, secrets grab x1; 1 domain(s) in 2s
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 10:50:42
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.179.246.246 (246.246.179.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.179.246.246 (246.246.179.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 06:50:35.807666 2026] [security2:error] [pid 15351:tid 15351] [client 34.179.246.246:53072] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.nomanszone.org"] [uri "/.htpasswd"] [unique_id "ar46-1Y9JsehsV9ZVbDs5AAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 10:31:36
(15 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.179.246.246 (246.246.179.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.179.246.246 (246.246.179.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 06:31:31.137360 2026] [security2:error] [pid 5631:tid 5703] [client 34.179.246.246:56860] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.maroontribe.com|F|2"] [data ".maroontribe.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.maroontribe.com"] [uri "/z9x8c7v6b5-debug-trigger-www.maroontribe.com"] [unique_id "ar42g6S9q4VW2KoeNpBtsgAAAUU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-01 10:20:02
(15 hours ago)
suspicious request in access.log
Web App Attack
๐ณ๐ฑ
Site.eu
2026-10-01 10:11:03
(16 hours ago)
Excessive 404/403 errors
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-10-01 10:08:58
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.179.246.246 (246.246.179.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.179.246.246 (246.246.179.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 06:08:52.606235 2026] [security2:error] [pid 2652:tid 2652] [client 34.179.246.246:60218] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/Web.config" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "martinez-morera.com"] [uri "/web.config"] [unique_id "ar4xNIQnm9luI_AWfyBcsAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 09:52:37
(16 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.179.246.246 (246.246.179.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.179.246.246 (246.246.179.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 05:52:32.658410 2026] [security2:error] [pid 29581:tid 29581] [client 34.179.246.246:40672] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.nationalnova.com|F|2"] [data ".nationalnova.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.nationalnova.com"] [uri "/z9x8c7v6b5-debug-trigger-www.nationalnova.com"] [unique_id "ar4tYIC6BaLqyanThmoBmQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack