Anonymous
2026-10-09 03:30:04
(4 hours ago)
CrowdSec decision: crowdsecurity/http-admin-interface-probing (origin: crowdsec)
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-10-09 02:20:26
(5 hours ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FD-IX
2026-10-09 02:05:11
(5 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-09 01:55:26
(5 hours ago)
[ti-01sc] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apac ...
show more
[ti-01sc] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apache-404. Example: 34.21.148.170 - - [09/Oct/2026:03:55:20 +0200] "GET /secure HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
34.21.148.170 - - [09/Oct/2026:03:55:20 +0200] "GET /sd2i6nsud4csj7s6kzps HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)"
34.21.148.170 - - [09/Oct/2026:03:55:20 +0200] "GET /auth HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
34.21.148.170 - - [09/Oct/2026:03:55:20 +0200] "GET /users/login HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/5
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 01:19:51
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.21.148.170 (170.148.21.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.21.148.170 (170.148.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 21:19:48.408374 2026] [security2:error] [pid 23845:tid 23845] [client 34.21.148.170:46344] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thinksite.net"] [uri "/.htpasswd"] [unique_id "ashBNIiCF6cKcx71W59dpwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
sigurg
2026-10-09 01:02:26
(6 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-10-09 01:01:24
(6 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐ฌ๐ง
andypiper
2026-10-09 01:00:28
(6 hours ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
Anonymous
2026-10-09 00:53:20
(6 hours ago)
Blocked by fail2ban on a public web server.
Web App Attack
๐ฉ๐ช
Roper123
2026-10-09 00:40:03
(6 hours ago)
Web exploits - access forbidden
Web App Attack
๐ฉ๐ช
paissangroup
2026-10-09 00:38:44
(6 hours ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-10-09 00:20:22
(7 hours ago)
[Fri Oct 09 00:20:21.541529 2026] [authz_core:error] [pid 496533:tid 496540] [remote 34.21.148.170:5 ...
show more
[Fri Oct 09 00:20:21.541529 2026] [authz_core:error] [pid 496533:tid 496540] [remote 34.21.148.170:56804] AH01630: client denied by server configuration: /srv/www/shop.gassycat.be/htdocs/admin
[Fri Oct 09 00:20:21.814738 2026] [authz_core:error] [pid 496533:tid 496536] [remote 34.21.148.170:56804] AH01630: client denied by server configuration: /srv/www/shop.gassycat.be/htdocs/admin
[Fri Oct 09 00:20:21.906703 2026] [authz_core:error] [pid 496533:tid 496537] [remote 34.21.148.170:56814] AH01630: client denied by server configuration: /srv/www/shop.gassycat.be/htdocs/admin
[Fri Oct 09 00:20:22.054901 2026] [authz_core:error] [pid 496533:tid 496542] [remote 34.21.148.170:56804] AH01630: client denied by server configuration: /srv/www/shop.gassycat.be/htdocs/api
[Fri Oct 09 00:20:22.064047 2026] [authz_core:error] [pid 496533:tid 496535] [remote 34.21.148.170:56804] AH01630: client denied by server configuration: /srv/www/shop.gassycat.be/htdocs/app
...
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-10-09 00:16:31
(7 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.21.148.170 (170.148.21.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.21.148.170 (170.148.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 20:16:26.506968 2026] [security2:error] [pid 31181:tid 31181] [client 34.21.148.170:47108] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||owenmail.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "owenmail.com"] [uri "/z9x8c7v6b5-debug-trigger-owenmail.com"] [unique_id "asgyWurbkRN8_x7EvoLM0AAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 23:54:48
(7 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.21.148.170 (170.148.21.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.21.148.170 (170.148.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 19:54:41.831962 2026] [security2:error] [pid 1277:tid 1277] [client 34.21.148.170:54852] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||overlandpublishing.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "overlandpublishing.com"] [uri "/z9x8c7v6b5-debug-trigger-overlandpublishing.com"] [unique_id "asgtQeldZQBqDdryN3aAMwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
debestelapp
2026-10-08 23:45:08
(7 hours ago)
Web App Attack