๐ช๐ธ
robotstxt
2026-10-02 15:34:03
(2 days ago)
2026/10/02 15:34:01 [error] 1588554#1588554: *1420896 [client 34.179.253.232] ModSecurity: Access de ...
show more
2026/10/02 15:34:01 [error] 1588554#1588554: *1420896 [client 34.179.253.232] ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Ge' with parameter `5' against variable `TX:BLOCKING_INBOUND_ANOMALY_SCORE' (Value: `5' ) [file "/var/lib/angie/modsecurity/coreruleset/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "222"] [id "949110"] [rev ""] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [data ""] [severity "0"] [ver "OWASP_CRS/4.29.0"] [maturity "0"] [accuracy "0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "www.nascapers.es"] [uri "/assets/manifest.json"] [unique_id "179095524198.543494"] [ref ""], client: "34.179.253.232", server: "www.nascapers.es", request_line: "GET /assets/manifest.json HTTP/2.0", host: "www.nascapers.es", referrer: "https://nascapers.es/assets/manifest.json"
2026/10/02 15:34:01 [error] 1588554#1588554: *1420896 [client 34.179.253.232] ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Ge' with param
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 15:21:49
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.179.253.232 (232.253.179.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.179.253.232 (232.253.179.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 11:21:46.858426 2026] [security2:error] [pid 28560:tid 28611] [client 34.179.253.232:37052] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nesso.es"] [uri "/__vite_rsc_findSourceMapURL"] [unique_id "ar_MCoGE1rBu_ds00DFDaAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
robotstxt
2026-10-02 14:16:20
(2 days ago)
34.179.253.232 - - [02/Oct/2026:14:15:37 +0000] "-" 400 193 "-" "-" "-" edge="34.179.253.232"
34.179 ...
show more
34.179.253.232 - - [02/Oct/2026:14:15:37 +0000] "-" 400 193 "-" "-" "-" edge="34.179.253.232"
34.179.253.232 - - [02/Oct/2026:14:15:37 +0000] "-" 400 193 "-" "-" "-" edge="34.179.253.232"
34.179.253.232 - - [02/Oct/2026:14:15:37 +0000] "-" 400 193 "-" "-" "-" edge="34.179.253.232"
34.179.253.232 - - [02/Oct/2026:14:15:37 +0000] "-" 400 193 "-" "-" "-" edge="34.179.253.232"
34.179.253.232 - - [02/Oct/2026:14:15:37 +0000] "-" 400 193 "-" "-" "-" edge="34.179.253.232"
...
show less
Web Spam
Web App Attack
๐ช๐ธ
robotstxt
2026-10-02 13:56:45
(2 days ago)
34.179.253.232 - - [02/Oct/2026:13:55:43 +0000] "-" 400 193 "-" "-" "-" edge="34.179.253.232"
34.179 ...
show more
34.179.253.232 - - [02/Oct/2026:13:55:43 +0000] "-" 400 193 "-" "-" "-" edge="34.179.253.232"
34.179.253.232 - - [02/Oct/2026:13:55:43 +0000] "-" 400 193 "-" "-" "-" edge="34.179.253.232"
34.179.253.232 - - [02/Oct/2026:13:55:43 +0000] "-" 400 193 "-" "-" "-" edge="34.179.253.232"
34.179.253.232 - - [02/Oct/2026:13:55:43 +0000] "-" 400 193 "-" "-" "-" edge="34.179.253.232"
34.179.253.232 - - [02/Oct/2026:13:55:43 +0000] "-" 400 193 "-" "-" "-" edge="34.179.253.232"
...
show less
Web Spam
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 11:58:21
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.179.253.232 (232.253.179.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.179.253.232 (232.253.179.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 07:58:18.228197 2026] [security2:error] [pid 22089:tid 22089] [client 34.179.253.232:33532] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.sitexpress.es|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.sitexpress.es"] [uri "/server.key"] [unique_id "ar-cWpSQJFkRnX-tLS7_GwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
robotstxt
2026-10-02 10:45:52
(2 days ago)
34.179.253.232 - - [02/Oct/2026:10:44:50 +0000] "GET /z9x8c7v6b5-debug-trigger-librerias.paulinas.es ...
show more
34.179.253.232 - - [02/Oct/2026:10:44:50 +0000] "GET /z9x8c7v6b5-debug-trigger-librerias.paulinas.es HTTP/2.0" 403 21314 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)" "-" edge="34.179.253.232"
34.179.253.232 - - [02/Oct/2026:10:44:50 +0000] "GET /dist/manifest.json HTTP/2.0" 403 20501 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "-" edge="34.179.253.232"
34.179.253.232 - - [02/Oct/2026:10:44:50 +0000] "GET /dist/.vite/manifest.json HTTP/2.0" 403 20485 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "-" edge="34.179.253.232"
34.179.253.232 - - [02/Oct/2026:10:44:50 +0000] "GET /build/manifest.json HTTP/2.0" 403 20498 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "-" edge="34.179.253.232"
34.179.253.232 - - [02/Oct/2026:10:44:50 +0000] "GET /.vite/
...
show less
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-02 10:21:17
(2 days ago)
[cb-11al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apac ...
show more
[cb-11al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apache-404. Example: 34.179.253.232 - - [02/Oct/2026:12:21:09 +0200] "GET /z9x8c7v6b5-debug-trigger-staging.zusterinhuis.es HTTP/2.0" 404 1878 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)"
34.179.253.232 - - [02/Oct/2026:12:21:09 +0200] "GET /users/login HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
34.179.253.232 - - [02/Oct/2026:12:21:09 +0200] "GET /u53i8mqm0ixn278pjajy HTTP/2.0" 404 1855 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] )"
34.179.253.232 - - [02/Oct/2026:12:21:09 +0200] "GET /login HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (X11; Linux x8
...
show less
Bad Web Bot
Web App Attack
๐ช๐ธ
robotstxt
2026-10-02 10:20:04
(2 days ago)
34.179.253.232 - - [02/Oct/2026:10:19:17 +0000] "GET /storage/.env HTTP/2.0" 403 10128 "-" rt="0.111 ...
show more
34.179.253.232 - - [02/Oct/2026:10:19:17 +0000] "GET /storage/.env HTTP/2.0" 403 10128 "-" rt="0.111" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.4; +https://openai.com/gptbot" "-" h="docs.robotstxt.es" sn="docs.robotstxt.es" ru="/storage/.env" u="/index.php" ucs="-" ua="unix:/var/run/php/docs82.sock" us="404" uct="0.000" urt="0.110"
34.179.253.232 - - [02/Oct/2026:10:19:18 +0000] "GET /.env.dev HTTP/2.0" 403 10128 "-" rt="0.207" "Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)" "-" h="docs.robotstxt.es" sn="docs.robotstxt.es" ru="/.env.dev" u="/index.php" ucs="-" ua="unix:/var/run/php/docs82.sock" us="404" uct="0.000" urt="0.208"
34.179.253.232 - - [02/Oct/2026:10:19:18 +0000] "GET /.env.swp HTTP/2.0" 403 10128 "-" rt="0.323" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36" "-" h="docs.robotstxt.es" sn="docs.robotstxt.es" ru="/.env.swp" u="/index.php" ucs="-" ua="unix:/var/run/php/docs82.sock" us="4
...
show less
Web App Attack
๐ณ๐ฑ
Savvii
2026-10-02 10:17:08
(2 days ago)
20 attempts against mh-misbehave-ban on frost
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
robotstxt
2026-10-02 10:04:30
(2 days ago)
34.179.253.232 - - [02/Oct/2026:10:04:28 +0000] "GET /public/plugins/text/../../../../../../../../pr ...
show more
34.179.253.232 - - [02/Oct/2026:10:04:28 +0000] "GET /public/plugins/text/../../../../../../../../proc/self/environ HTTP/1.1" 400 193 "-" "-" "-" edge="34.179.253.232"
34.179.253.232 - - [02/Oct/2026:10:04:28 +0000] "GET /public/plugins/grafana-clock-panel/../../../../../../../../proc/self/environ HTTP/1.1" 400 193 "-" "-" "-" edge="34.179.253.232"
34.179.253.232 - - [02/Oct/2026:10:04:28 +0000] "GET /public/plugins/grafana-clock-panel/../../../../../../../../proc/self/environ HTTP/1.1" 400 193 "-" "-" "-" edge="34.179.253.232"
34.179.253.232 - - [02/Oct/2026:10:04:28 +0000] "GET /public/plugins/alertlist/../../../../../../../../proc/self/environ HTTP/1.1" 400 193 "-" "-" "-" edge="34.179.253.232"
34.179.253.232 - - [02/Oct/2026:10:04:28 +0000] "GET /public/plugins/alertlist/../../../../../../../../proc/self/environ HTTP/1.1" 400 193 "-" "-" "-" edge="34.179.253.232"
...
show less
Web Spam
Web App Attack
๐ช๐ธ
netfactotum
2026-10-02 09:10:17
(2 days ago)
Hacking
Web App Attack
๐ณ๐ฑ
Savvii
2026-10-02 09:04:50
(2 days ago)
20 attempts against mh-misbehave-ban on cedar
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-10-02 08:53:10
(2 days ago)
BAD BOT - Detected and Blocked.. Matched phrase "baidu" at REQUEST_HEADERS:User-Agent. (1100000-131)
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-02 08:31:06
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.179.253.232 (232.253.179.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.179.253.232 (232.253.179.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 04:30:59.602193 2026] [security2:error] [pid 29546:tid 29546] [client 34.179.253.232:49282] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.aticom.es"] [uri "/.htpasswd"] [unique_id "ar9rw72735oZcWB6cyeBcwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
yvoictra
2026-10-02 08:27:04
(2 days ago)
Bloqueado automรกticamente por CrowdSec. Escenario: crowdsecurity/http-path-traversal-probing
Web App Attack