🇺🇸
xmission.com
2026-09-13 03:46:04
(43 minutes ago)
Blocked by UFW (TCP on 8080)
Source port: 44672
TTL: 60
Packet length: 60
TOS: 0x00
This report (fo ...
show more
Blocked by UFW (TCP on 8080)
Source port: 44672
TTL: 60
Packet length: 60
TOS: 0x00
This report (for 34.20.244.33) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
Web App Attack
🇦🇺
FireGuard Server
2026-09-13 03:45:08
(44 minutes ago)
Blocked by os-abuseipdb; 4 hits, proto=tcp, ports=443,8080,8443
Port Scan
Hacking
🇺🇸
mutebot.net
2026-09-13 03:42:48
(46 minutes ago)
SRC=34.20.244.33, PROTO=TCP, SPT=54532, DPT=8080
Port Scan
🇳🇱
Alt255
2026-09-13 02:17:57
(2 hours ago)
[ti-24al] Web exploit scanning: 16 suspicious requests detected by fail2ban jail apache-scanner. Exa ...
show more
[ti-24al] Web exploit scanning: 16 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.20.244.33 - - [13/Sep/2026:04:17:56 +0200] "GET /@fs/.env?import&?raw?? HTTP/2.0" 404 2004 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
34.20.244.33 - - [13/Sep/2026:04:17:56 +0200] "GET /@fs/.env?url&raw?? HTTP/2.0" 404 2004 "-" "Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)"
34.20.244.33 - - [13/Sep/2026:04:17:56 +0200] "GET /@fs/.env?raw&url?? HTTP/2.0" 403 541 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1)"
34.20.244.33 - - [13/Sep/2026:04:17:56 +0200] "GET /__vite_rsc_findSourceMapURL?filename=file:///app/.env&environmentName=rsc HTTP/2.0" 404 2004 "-"
...
show less
Bad Web Bot
Web App Attack
🇳🇱
Savvii
2026-09-13 01:55:30
(2 hours ago)
20 attempts against mh-misbehave-ban on eris
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 01:36:40
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.20.244.33 (33.244.20.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.20.244.33 (33.244.20.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 21:36:35.163390 2026] [security2:error] [pid 2352333:tid 2352380] [client 34.20.244.33:45350] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||hnssales.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "hnssales.com"] [uri "/z9x8c7v6b5-debug-trigger-hnssales.com"] [unique_id "aqX-I4r23b_J63zEf2VRxQAAAZE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Hazzard
2026-09-13 01:33:17
(2 hours ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
🇬🇧
thetomtaylor.co.uk
2026-09-13 01:17:02
(3 hours ago)
Fail2Ban - [WAF]ModSecurity rule violation on modsecurity ... [wa01,wa02]
Hacking
SQL Injection
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 00:32:31
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.20.244.33 (33.244.20.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.20.244.33 (33.244.20.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 20:32:26.754763 2026] [security2:error] [pid 16754:tid 16754] [client 34.20.244.33:39274] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hker.org"] [uri "/@fs/.env"] [unique_id "aqXvGvUhhuSZMN_CtpOfRgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
debestelapp
2026-09-12 23:40:12
(4 hours ago)
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 23:34:04
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.20.244.33 (33.244.20.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.20.244.33 (33.244.20.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 19:33:56.762680 2026] [security2:error] [pid 9778:tid 9778] [client 34.20.244.33:45698] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||hiscreativedesign.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "hiscreativedesign.com"] [uri "/rclone.conf"] [unique_id "aqXhZCKgFkZjq-FD02-1ggAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇮
JimArchon72
2026-09-12 23:25:01
(5 hours ago)
2026/09/12 23:20:27 "GET /wp-admin/ HTTP/2.0"
Web App Attack
🇧🇪
cmbplf
2026-09-12 23:11:34
(5 hours ago)
12.556 requests from abuseipdb.com blacklisted IP (1yr10mos5d)
Brute-Force
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-12 23:10:19
(5 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.20.244.33 (33.244.20.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.20.244.33 (33.244.20.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 19:10:14.569959 2026] [security2:error] [pid 15777:tid 15777] [client 34.20.244.33:57000] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||hipstan.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "hipstan.com"] [uri "/z9x8c7v6b5-debug-trigger-hipstan.com"] [unique_id "aqXb1ti79kH-MQxhpf80ZAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-12 22:56:11
(5 hours ago)
Web attack/malicious scanning detected
Web App Attack