Anonymous
2026-05-24 01:40:34
(3 months ago)
| [Dangerous/Singapore] Aggressive IP 34.21.136.2 (~30 hits). Type: DoS Defender- Web server 400 err ...
show more
| [Dangerous/Singapore] Aggressive IP 34.21.136.2 (~30 hits). Type: DoS Defender- Web server 400 error code
show less
Web App Attack
Hacking
SQL Injection
๐ณ๐ฑ
e.fierstra
2026-05-23 21:32:53
(3 months ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ณ๐ฑ
wlt-blocker
2026-05-23 18:35:46
(3 months ago)
Unauthorized access to webpage admin
Web App Attack
๐ฎ๐น
VHosting
2026-05-23 18:00:05
(3 months ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐ฉ๐ช
Hazzard
2026-05-23 17:47:43
(3 months ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-05-23 17:08:49
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 34.21.136.2 (2.136.21.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.21.136.2 (2.136.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 23 13:08:42.794402 2026] [security2:error] [pid 3334:tid 3334] [client 34.21.136.2:55960] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.thelastnoel.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.thelastnoel.com"] [uri "/.config/gcloud/credentials.db"] [unique_id "ahHfGk8Hv0vWhH1k-XxXPwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
markawes
2026-05-23 14:35:44
(3 months ago)
[markis] Auto banned by Fail2Ban. Reason: Malicious web scan / attempted access to sensitive paths. ...
show more
[markis] Auto banned by Fail2Ban. Reason: Malicious web scan / attempted access to sensitive paths. Evidence:
34.21.136.2 - - [23/May/2026:15:35:41 +0100] "GET /database.sql HTTP/1.1" 404 3063 "-" "Mozilla/5.0 (X11; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/48.0.2564.116 Safari/537.36"
34.21.136.2 - - [23/May/2026:15:35:42 +0100] "GET /db.sql HTTP/1.1" 404 3063 "-" "Mozilla/5.0 (compatible; MSIE 10.0; Windows Phone 8.0; Trident/6.0; IEMobile/10.0; ARM; Touch; NOKIA; Lumia 920)"
34.21.136.2 - - [23/May/2026:15:35:42 +0100] "GET /.aws/credentials HTTP/1.1" 404 3064 "-" "Opera/9.80 (Android 4.0.4; Linux; Opera Mobi/ADR-1205181138; U; pl) Presto/2.10.254 Version/12.00"
show less
Port Scan
Hacking
Web App Attack
๐ซ๐ท
Octopuce
2026-05-23 14:26:16
(3 months ago)
Aggressive web search of vulnerable pages: /parameters.php /db.php /app/config.php /app/database.php ...
show more
Aggressive web search of vulnerable pages: /parameters.php /db.php /app/config.php /app/database.php /app/settings.php /backend/config.php /bac ...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-23 14:25:18
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 34.21.136.2 (2.136.21.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.21.136.2 (2.136.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 23 10:25:10.824284 2026] [security2:error] [pid 29023:tid 29023] [client 34.21.136.2:51062] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/config/config.yml" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.patandmat.com"] [uri "/config/config.yml"] [unique_id "ahG4xmLwBGkahLRByPeKBAAAAG4"]
show less
Brute-Force
Bad Web Bot
Web App Attack