๐บ๐ธ
TPI-Abuse
2026-08-27 17:14:57
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.201.241.173 (ec2-34-201-241-173.compute-1.am ...
show more
(mod_security) mod_security (id:210492) triggered by 34.201.241.173 (ec2-34-201-241-173.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 13:14:51.052829 2026] [security2:error] [pid 22183:tid 22183] [client 34.201.241.173:32852] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ea2cdy.es"] [uri "/.git/config"] [unique_id "apBwi7wCai4JCJQ0S7O-lQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
arnisolutions
2026-08-27 16:42:08
(1 hour ago)
Vulnerability scanning (requests for admin panels, shells, backup files etc.) against a production s ...
show more
Vulnerability scanning (requests for admin panels, shells, backup files etc.) against a production server. Observed on 1 day(s) between 2026-08-27 and 2026-08-27 (UTC). Sample request: GET /handy-angebote-und-zubehoer/ HTTP/2.0
show less
Web App Attack
Hacking
๐จ๐ญ
zynex
2026-08-27 14:15:04
(4 hours ago)
URL Probing: /.env
Web App Attack
๐ฉ๐ช
macrob
2026-08-27 13:15:54
(5 hours ago)
2026/08/27 13:15:51 [error] 2898858#2898858: *526570981 access forbidden by rule, client: 34.201.241 ...
show more
2026/08/27 13:15:51 [error] 2898858#2898858: *526570981 access forbidden by rule, client: 34.201.241.173, server: ca5h.win, request: "GET /admin HTTP/1.1", host: "ca5h.win"
2026/08/27 13:15:51 [error] 2898859#2898859: *526570985 access forbidden by rule, client: 34.201.241.173, server: ca5h.win, request: "GET /admin/login HTTP/1.1", host: "ca5h.win"
2026/08/27 13:15:52 [error] 2898859#2898859: *526570987 access forbidden by rule, client: 34.201.241.173, server: ca5h.win, request: "GET /.vite/manifest.json HTTP/1.1", host: "ca5h.win"
...
show less
Web App Attack
Anonymous
2026-08-27 12:34:04
(5 hours ago)
Bot / scanning and/or hacking attempts: GET /register HTTP/2.0, GET /.env.example HTTP/2.0, GET /.gi ...
show more
Bot / scanning and/or hacking attempts: GET /register HTTP/2.0, GET /.env.example HTTP/2.0, GET /.git-credentials HTTP/2.0, GET /users/login HTTP/2.0, GET /sign-in HTTP/2.0, GET /.env.production HTTP/2.0, GET /forgot-password HTTP/2.0, GET /signup HTTP/2.0, GET /dashboard HTTP/2.0, GET /.gitconfig HTTP/2.0, GET /reset-password HTTP/2.0
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 12:09:50
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.201.241.173 (ec2-34-201-241-173.compute-1.am ...
show more
(mod_security) mod_security (id:210492) triggered by 34.201.241.173 (ec2-34-201-241-173.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 08:09:42.719167 2026] [security2:error] [pid 26370:tid 26370] [client 34.201.241.173:54974] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.fiestadj.com.mx"] [uri "/.git/HEAD"] [unique_id "apApBgqrW8n99DCfVYNurQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-08-27 12:00:11
(6 hours ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 11:32:12
(6 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.201.241.173 (ec2-34-201-241-173.compute-1.am ...
show more
(mod_security) mod_security (id:210730) triggered by 34.201.241.173 (ec2-34-201-241-173.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 07:32:07.604027 2026] [security2:error] [pid 4508:tid 4508] [client 34.201.241.173:57050] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||creartest.com|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "creartest.com"] [uri "/ssl/server.key"] [unique_id "apAgN5BgAwyCvx4Jn7OrgAAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
DRI
2026-08-27 10:55:38
(7 hours ago)
Web attack/Malicious activity detected
Web App Attack
๐ฌ๐ง
cybersteve99
2026-08-27 10:54:50
(7 hours ago)
Too many 4xx Requests -
Brute-Force
Web App Attack
๐ช๐ธ
pipeline.es
2026-08-27 10:28:03
(8 hours ago)
Web scanning / probing for vulnerable paths | URL: /manifest.json | Evidence: bestravel.pt 34.201.24 ...
show more
Web scanning / probing for vulnerable paths | URL: /manifest.json | Evidence: bestravel.pt 34.201.241.173 - - [27/Aug/2026:12:26:36 +0200] \"GET /manifest.json HTTP/2.0\" 404 38369 \"-\" \"Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Mobile Safari/537.36 EdgA/149.0.0.0\" GEOIP_COUNTRY_CODE=US | ASN: AMAZON-AES | Country: US
show less
Port Scan
Web App Attack
๐บ๐ธ
mnsf
2026-08-27 09:05:48
(9 hours ago)
Abuse Detected (7)
Brute-Force
Web App Attack
๐ง๐ช
taivas.nl
2026-08-27 09:02:10
(9 hours ago)
Bad_requests
Bad Web Bot
Anonymous
2026-08-27 08:57:43
(9 hours ago)
Multiple web server 400 error codes from same source ip
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-08-27 08:34:04
(9 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking