🇫🇷
cityhunter_rhone
2026-09-11 17:55:02
(4 hours ago)
Mercurius trap auto report | source=APACHE_DENIED_AGGREGATE | last_seen=2026-09-11 19:53:38 | hits_4 ...
show more
Mercurius trap auto report | source=APACHE_DENIED_AGGREGATE | last_seen=2026-09-11 19:53:38 | hits_403=66 | hits_404=0 | ip=34.20.176.143 | sample_uri=(overflow - URI distinctes supplementaires regroupees)
show less
Port Scan
Hacking
Web App Attack
🇫🇷
masterguru
2026-09-11 17:44:18
(4 hours ago)
Restricted File Access Attempt. Matched phrase ".ssh/" at REQUEST_FILENAME. (930130-196)
Hacking
Web App Attack
🇳🇱
Site.eu
2026-09-11 17:40:21
(4 hours ago)
Excessive multi-domain requests
Brute-Force
Anonymous
2026-09-11 17:32:59
(4 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-11 17:32:03
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.20.176.143 (143.176.20.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.20.176.143 (143.176.20.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 13:31:56.195535 2026] [security2:error] [pid 8781:tid 8810] [client 34.20.176.143:34472] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mentzlaw.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mentzlaw.com"] [uri "/z9x8c7v6b5-debug-trigger-mentzlaw.com"] [unique_id "aqQ7DLx8ge20RWbi5xUZcgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-11 17:31:37
(4 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 17:00:07
(5 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.20.176.143 (143.176.20.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.20.176.143 (143.176.20.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 12:59:57.675234 2026] [security2:error] [pid 28114:tid 28114] [client 34.20.176.143:33192] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||memotronic.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "memotronic.com"] [uri "/z9x8c7v6b5-debug-trigger-memotronic.com"] [unique_id "aqQzjXH2ttEgUOg6Rk9uxAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
ghostwarriors
2026-09-11 16:50:09
(5 hours ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
🇦🇺
2000cn.com.au
2026-09-11 16:45:16
(5 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-11 16:44:27
(5 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.20.176.143 (143.176.20.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.20.176.143 (143.176.20.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 12:44:22.040689 2026] [security2:error] [pid 12047:tid 12047] [client 34.20.176.143:50612] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||meltonspace.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "meltonspace.com"] [uri "/rclone.conf"] [unique_id "aqQv5j1YGTDmgBvqxx0ucwAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
yitzhaq
2026-09-11 16:38:46
(5 hours ago)
34.20.176.143 - - [11/Sep/2026:18:38:41 +0200] "GET /dashboard%2F.env HTTP/2.0" 404 306 "-" "Mozilla ...
show more
34.20.176.143 - - [11/Sep/2026:18:38:41 +0200] "GET /dashboard%2F.env HTTP/2.0" 404 306 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email])"
34.20.176.143 - - [11/Sep/2026:18:38:41 +0200] "GET /icons/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/proc/self/environ HTTP/2.0" 400 336 "-" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)"
34.20.176.143 - - [11/Sep/2026:18:38:41 +0200] "GET /api%2F.env HTTP/2.0" 404 306 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)"
34.20.176.143 - - [11/Sep/2026:18:38:42 +0200] "GET /__vite_rsc_findSourceMapURL?filename=file:///proc/self/environ&environmentName=rsc HTTP/2.0" 404 329 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)"
34.20.176.143 - - [11/Sep/2026:18:38:42 +0200] "GET /@fs/.env?raw&url?? HTTP/2.0" 404 306 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)"
34.20.176.143 - - [11/Sep/2026:18:38:42 +0200] "GET /__vite_r
show less
Web App Attack
Hacking
Anonymous
2026-09-11 16:11:32
(5 hours ago)
34.20.176.143 - - [11/Sep/2026:18:11:30 +0200] "GET / HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Windows NT ...
show more
34.20.176.143 - - [11/Sep/2026:18:11:30 +0200] "GET / HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36"
34.20.176.143 - - [11/Sep/2026:18:11:31 +0200] "GET /z9x8c7v6b5-debug-trigger-mekkbeautystudio.com HTTP/1.1" 403 124 "-" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)"
34.20.176.143 - - [11/Sep/2026:18:11:31 +0200] "GET /.htpasswd HTTP/1.1" 403 124 "-" "Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)"
34.20.176.143 - - [11/Sep/2026:18:11:31 +0200] "GET /.svn/entries HTTP/1.1" 403 124 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; OAI-SearchBot/1.0; +https://openai.com/searchbot)"
34.20.176.143 - - [11/Sep/2026:18:11:31 +0200] "GET /.boto HTTP/1.1" 403 124 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)"
34.20.176.143 - - [11/Sep/2026:18:11:31 +0200] "GET /rclone.conf HTTP/1.1" 403 124 "-" "Mozilla/5.0 (compatibl
...
show less
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-11 16:09:36
(6 hours ago)
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encod ...
show more
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encoding/ /proxy/ /lock-token/ /content-range/ /if/ /x-http-method-override/ /x-http-method/ /x-method-override/ /x-middleware-subrequest/ /expect/" at TX:header_name_920450_x-middleware-subrequest. (920450-197)
show less
Bad Web Bot
🇺🇸
mnsf
2026-09-11 16:06:13
(6 hours ago)
Abuse Detected (3)
Brute-Force
Web App Attack
🇫🇷
dynamix
2026-09-11 16:00:17
(6 hours ago)
Multiple WAF Violations
Web App Attack