Anonymous
2026-09-11 20:19:28
(1 hour ago)
Fuzzing/Looking for credentials files.
Brute-Force
Web App Attack
🇳🇴
Bots.go.to.hell
2026-09-11 18:07:12
(3 hours ago)
This IP was detected by CrowdSec triggering custom/http-bad-crawler-ban
Web App Attack
Bad Web Bot
Anonymous
2026-09-11 18:00:02
(3 hours ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection
🇺🇸
TPI-Abuse
2026-09-11 17:58:57
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.182.159.113 (113.159.182.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.182.159.113 (113.159.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 13:58:49.681008 2026] [security2:error] [pid 9972:tid 9972] [client 34.182.159.113:48456] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||justicehoward.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "justicehoward.com"] [uri "/rclone.conf"] [unique_id "aqRBWQzL6KctQHBFk3VAFQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-11 17:55:02
(4 hours ago)
suspicious request in access.log
Web App Attack
🇫🇷
masterguru
2026-09-11 17:41:17
(4 hours ago)
BAD BOT - Detected and Blocked.. Matched phrase "baidu" at REQUEST_HEADERS:User-Agent. (1100000-193)
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-11 17:36:42
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.182.159.113 (113.159.182.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.182.159.113 (113.159.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 13:36:37.985640 2026] [security2:error] [pid 15741:tid 15845] [client 34.182.159.113:59086] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jupitermaturin.com"] [uri "/%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env"] [unique_id "aqQ8JWnbH8m3pyXAgPOh0QAAAI8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-11 17:15:37
(4 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
mnsf
2026-09-11 17:05:34
(4 hours ago)
Abuse Detected (7)
Brute-Force
Web App Attack
🇬🇧
Aetherweb Ark
2026-09-11 16:50:24
(5 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.182.159.113 (US/United States/113.159.182.34 ...
show more
(mod_security) mod_security (id:949110) triggered by 34.182.159.113 (US/United States/113.159.182.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 16:38:15
(5 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.182.159.113 (113.159.182.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.182.159.113 (113.159.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 12:38:11.122409 2026] [security2:error] [pid 5542:tid 5588] [client 34.182.159.113:56750] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||julianositalianrestaurant.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "julianositalianrestaurant.com"] [uri "/z9x8c7v6b5-debug-trigger-julianositalianrestaurant.com"] [unique_id "aqQuc9Qu3Ff9ZK7A7tq4mgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇬
naveeddaros
2026-09-11 16:12:44
(5 hours ago)
HTTP Flood DDoS attack detected
Brute-Force
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-11 16:12:03
(5 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.182.159.113 (113.159.182.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.182.159.113 (113.159.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 12:11:55.023184 2026] [security2:error] [pid 30840:tid 30840] [client 34.182.159.113:47378] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||judithchallender.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "judithchallender.com"] [uri "/z9x8c7v6b5-debug-trigger-judithchallender.com"] [unique_id "aqQoS5lE18jBOnmUfpOsEwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-11 15:51:45
(6 hours ago)
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encod ...
show more
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encoding/ /proxy/ /lock-token/ /content-range/ /if/ /x-http-method-override/ /x-http-method/ /x-method-override/ /x-middleware-subrequest/ /expect/" at TX:header_name_920450_x-middleware-subrequest. (920450-201)
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-11 15:45:55
(6 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.182.159.113 (113.159.182.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.182.159.113 (113.159.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 11:45:52.431711 2026] [security2:error] [pid 29620:tid 29642] [client 34.182.159.113:43808] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||jtjservices.com|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "jtjservices.com"] [uri "/ssl/localhost.key"] [unique_id "aqQiMJkK79tO42ZOXE-JCQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack