π©πͺ
klaus_ph
2026-09-23 15:51:13
(7 hours ago)
2026-09-23 01:53:31,321 fail2ban.actions [535885]: NOTICE [ipblocklist] Ban 34.187.166.104
. ...
show more
2026-09-23 01:53:31,321 fail2ban.actions [535885]: NOTICE [ipblocklist] Ban 34.187.166.104
...
show less
Bad Web Bot
πΊπΈ
[email protected]
2026-09-21 16:42:52
(2 days ago)
CrowdSec ban: crowdsecurity/unifi-flood-detection (duration: 71h59m59s)
Port Scan
πΊπΈ
Charlesiv
2026-09-21 06:02:50
(2 days ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Pro ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/2 (GET method)
Endpoint: /gc-service.json
Timestamp: 2026-09-21T04:27:28Z
Ray ID: a3e6514f691cebd3
UA: CCBot/2.0 (https://commoncrawl.org/faq/)
show less
Bad Web Bot
π©πͺ
pscriptos
2026-09-21 06:00:15
(2 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/appsec-vpatch
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 05:57:50
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.187.166.104 (104.166.187.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.187.166.104 (104.166.187.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 01:57:45.093532 2026] [security2:error] [pid 1865:tid 1865] [client 34.187.166.104:39592] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.zavijava.net"] [uri "/.git/config"] [unique_id "arDHWXSeck4GCbUmXY1ODAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
itsolon
2026-09-21 05:50:36
(2 days ago)
[21/Sep/2026:07:50:35 +0200] 178996983595.003334 34.187.166.104 55144 217.154.7.177 443
[21/Sep/2026 ...
show more
[21/Sep/2026:07:50:35 +0200] 178996983595.003334 34.187.166.104 55144 217.154.7.177 443
[21/Sep/2026:07:50:35 +0200] 178996983547.383057 34.187.166.104 55144 217.154.7.177 443
[21/Sep/2026:07:50:35 +0200] 178996983545.624332 34.187.166.104 55144 217.154.7.177 443
[21/Sep/2026:07:50:35 +0200] 178996983540.836271 34.187.166.104 55144 217.154.7.177 443
[21/Sep/2026:07:50:35 +0200] 178996983560.496916 34.187.166.104 55144 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
π©πͺ
raph
2026-09-21 05:18:30
(2 days ago)
[PROTECTED PATHS] crawler credentials.ini, aws.ini, aws.yml, etc.
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 03:52:34
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.187.166.104 (104.166.187.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.187.166.104 (104.166.187.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 23:52:32.527389 2026] [security2:error] [pid 2347:tid 2347] [client 34.187.166.104:60116] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||gadgeteer.net|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "gadgeteer.net"] [uri "/rclone.conf"] [unique_id "arCqAKDQkXoUTyPdHGoCvAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
curiosity
2026-09-21 03:10:35
(2 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-bad-user-agent
Web App Attack
Bad Web Bot
π³π±
Alt255
2026-09-21 03:05:18
(2 days ago)
[ti-10al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-10al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.187.166.104 - - [21/Sep/2026:05:05:13 +0200] "GET /.aws/credentials HTTP/2.0" 401 532 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)"
...
show less
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 02:53:42
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.187.166.104 (104.166.187.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.187.166.104 (104.166.187.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 22:53:34.462367 2026] [security2:error] [pid 1814:tid 1814] [client 34.187.166.104:45846] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "geriart.net"] [uri "/.env.example"] [unique_id "arCcLtH13YOTl9x8W5pyXwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
wteiken
2026-09-21 02:53:39
(2 days ago)
2026-09-20T22:53:36.893577-04:00 nostromo.teiken.net kernel: [561448.154919] syn_limit:IN=en-wan OUT ...
show more
2026-09-20T22:53:36.893577-04:00 nostromo.teiken.net kernel: [561448.154919] syn_limit:IN=en-wan OUT= MAC=00:50:43:37:c2:00:88:a2:5e:1c:98:0c:08:00 SRC=34.187.166.104 DST=173.52.106.128 LEN=60 TOS=0x00 PREC=0x60 TTL=61 ID=41193 DF PROTO=TCP SPT=52338 DPT=443 WINDOW=65320 RES=0x00 SYN URGP=0
2026-09-20T22:53:36.893991-04:00 nostromo.teiken.net kernel: [561448.155011] syn_limit:IN=en-wan OUT= MAC=00:50:43:37:c2:00:88:a2:5e:1c:98:0c:08:00 SRC=34.187.166.104 DST=173.52.106.128 LEN=60 TOS=0x00 PREC=0x60 TTL=61 ID=11977 DF PROTO=TCP SPT=52340 DPT=443 WINDOW=65320 RES=0x00 SYN URGP=0
2026-09-20T22:53:36.899093-04:00 nostromo.teiken.net kernel: [561448.159868] syn_limit:IN=en-wan OUT= MAC=00:50:43:37:c2:00:88:a2:5e:1c:98:0c:08:00 SRC=34.187.166.104 DST=173.52.106.128 LEN=60 TOS=0x00 PREC=0x60 TTL=61 ID=17821 DF PROTO=TCP SPT=52346 DPT=443 WINDOW=65320 RES=0x00 SYN URGP=0
2026-09-20T22:53:36.970148-04:00 nostromo.teiken.net kernel: [561448.231487] syn_limit:IN=en-wan OUT= MAC=00:50:43:37:c2:
...
show less
Port Scan
π©πͺ
webanyone
2026-09-21 01:32:15
(2 days ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
π©πͺ
webanyone
2026-09-21 01:16:42
(2 days ago)
Repeated 404 errors, blocked by Fail2ban in custom-404 jail
Bad Web Bot
πΊπΈ
Omega Threat-ID
2026-09-21 00:38:28
(2 days ago)
Omega Point Threat ID honeypot sensor observed: abuse-reported
Port Scan