๐บ๐ธ
TPI-Abuse
2026-10-07 06:48:57
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.179.248.72 (72.248.179.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.179.248.72 (72.248.179.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 02:48:53.077952 2026] [security2:error] [pid 30321:tid 30321] [client 34.179.248.72:50648] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.rohanbyles.com.au"] [uri "/.htpasswd"] [unique_id "asXrVcOhQqkMO3mFtayHeAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
robotstxt
2026-10-07 05:10:01
(3 hours ago)
34.179.248.72 - - [07/Oct/2026:05:09:00 +0000] "-" 400 193 "-" rt="0.000" "-" "-" edge="34.179.248.7 ...
show more
34.179.248.72 - - [07/Oct/2026:05:09:00 +0000] "-" 400 193 "-" rt="0.000" "-" "-" edge="34.179.248.72" h="magazine.kavehome.com.au" sn="magazine.kavehome.com.au" ru="-" u="" ucs="-" ua="-" us="-" uct="-" urt="-"
34.179.248.72 - - [07/Oct/2026:05:09:00 +0000] "-" 400 193 "-" rt="0.000" "-" "-" edge="34.179.248.72" h="magazine.kavehome.com.au" sn="magazine.kavehome.com.au" ru="-" u="" ucs="-" ua="-" us="-" uct="-" urt="-"
34.179.248.72 - - [07/Oct/2026:05:09:01 +0000] "-" 400 193 "-" rt="0.000" "-" "-" edge="34.179.248.72" h="magazine.kavehome.com.au" sn="magazine.kavehome.com.au" ru="-" u="" ucs="-" ua="-" us="-" uct="-" urt="-"
34.179.248.72 - - [07/Oct/2026:05:09:01 +0000] "-" 400 193 "-" rt="0.000" "-" "-" edge="34.179.248.72" h="magazine.kavehome.com.au" sn="magazine.kavehome.com.au" ru="-" u="" ucs="-" ua="-" us="-" uct="-" urt="-"
34.179.248.72 - - [07/Oct/2026:05:09:01 +0000] "-" 400 193 "-" rt="0.000" "-" "-" edge="34.179.248.72" h="magazine.kavehome.com.au" sn="magazine.kavehom
...
show less
Web Spam
Web App Attack
๐ฆ๐บ
CalmBrain
2026-10-07 01:35:05
(7 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-path-traversal-probing
Web App Attack
Hacking
๐ธ๐ฌ
simpeg-adm.bandung.go.id
2026-10-07 00:32:40
(8 hours ago)
07/Oct/2026:00:32:39 +0000;34.179.248.72;"/xx6bszlbfg3mcvd4okus"
07/Oct/2026:00:32:39 +0000;34.179.2 ...
show more
07/Oct/2026:00:32:39 +0000;34.179.248.72;"/xx6bszlbfg3mcvd4okus"
07/Oct/2026:00:32:39 +0000;34.179.248.72;"/signup"
07/Oct/2026:00:32:39 +0000;34.179.248.72;"/account/login"
07/Oct/2026:00:32:39 +0000;34.179.248.72;"/auth/login"
07/Oct/2026:00:32:39 +0000;34.179.248.72;"/lib/terminal-xhr.php"
07/Oct/2026:00:32:39 +0000;34.179.248.72;"/users/login"
07/Oct/2026:00:32:39 +0000;34.179.248.72;"/signin"
...
show less
Web Spam
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 22:20:32
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.179.248.72 (72.248.179.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.179.248.72 (72.248.179.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 18:20:25.561865 2026] [security2:error] [pid 5272:tid 5272] [client 34.179.248.72:43016] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.whipchecks.com.au"] [uri "/images../.env"] [unique_id "asV0KT_QoE6iNxpnTINJmgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
CalmBrain
2026-10-06 18:21:57
(14 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐ฆ๐บ
CalmBrain
2026-10-06 18:05:47
(14 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-bad-user-agent
Web App Attack
Bad Web Bot
๐ฆ๐บ
A.i.D.A.N.N
2026-10-06 16:23:05
(16 hours ago)
A.i.D.A.N.N: Anomaly Detected - Signature match Web Service - Web vulnerability scanning detected
Web App Attack
๐ฆ๐บ
2000cn.com.au
2026-10-06 15:02:27
(17 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ฆ๐บ
Klaverstyn
2026-10-06 14:00:23
(18 hours ago)
Excessive HTTP request rate
Web App Attack
๐ฆ๐บ
Asimar
2026-10-06 13:25:10
(19 hours ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted]): (CF_ENABLE)
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-06 12:36:36
(20 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.179.248.72 (72.248.179.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.179.248.72 (72.248.179.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 08:36:29.796753 2026] [security2:error] [pid 12617:tid 12617] [client 34.179.248.72:55204] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||heritagecityblinds.com.au|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "heritagecityblinds.com.au"] [uri "/server.key"] [unique_id "asTrTeJ-PxHvT2w0o6q5_QAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-10-06 11:43:46
(21 hours ago)
[Tue Oct 06 22:43:45.788365 2026] [security2:error] [pid 233690] [client 34.179.248.72:37110] [clien ...
show more
[Tue Oct 06 22:43:45.788365 2026] [security2:error] [pid 233690] [client 34.179.248.72:37110] [client 34.179.248.72] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "furst.com.au"] [uri "/static../.env"] [unique_id "asTe8QAxHKHEUVKUxUG81gAAAAI"]
...
show less
Web App Attack
๐ฌ๐ง
consul.to
2026-10-06 09:45:07
(23 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 09:34:28
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.179.248.72 (72.248.179.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.179.248.72 (72.248.179.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 05:34:24.347466 2026] [security2:error] [pid 31932:tid 31932] [client 34.179.248.72:38666] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "comsew.com.au"] [uri "/static../.env"] [unique_id "asTAoPRHz-0DmWndrfaMmAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack