๐ฉ๐ช
paissangroup
2026-10-05 20:11:29
(2 days ago)
Multiple WAF Violations
Web App Attack
๐ฆ๐บ
clapper
2026-10-05 18:50:36
(2 days ago)
(mod_security) mod_security (id:980001) triggered by 34.21.207.148 (SG/Singapore/148.207.21.34.bc.go ...
show more
(mod_security) mod_security (id:980001) triggered by 34.21.207.148 (SG/Singapore/148.207.21.34.bc.googleusercontent.com): 5 in the last 3600 secs; ID: Clar
show less
Brute-Force
Bad Web Bot
๐ณ๐ฑ
tmiland
2026-10-05 16:46:19
(3 days ago)
(nginx_444) Nginx 444 34.21.207.148 (SG/Singapore/148.207.21.34.bc.googleusercontent.com): 5 in the ...
show more
(nginx_444) Nginx 444 34.21.207.148 (SG/Singapore/148.207.21.34.bc.googleusercontent.com): 5 in the last 3600 secs; IP: 34.21.207.148; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.21.207.148 - - [05/Oct/2026:18:46:14 +0200] "GET /rrgc3iy3ed7nilxzfvbt HTTP/1.1" 444 0 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)" 34.21.207.148 - - [05/Oct/2026:18:46:14 +0200] "GET /.ssh/id_rsa HTTP/1.1" 444 0 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)" 34.21.207.148 - - [05/Oct/2026:18:46:14 +0200] "GET /.ssh/id_rsa HTTP/1.1" 444 0 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)" 34.21.207.148 - - [05/Oct/2026:18:46:15 +0200] "GET /.ssh/id_rsa HTTP/1.1" 444 0 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)" 34.21.207.148 - - [05/Oct/2026:18:46:15 +0200] "GET /.ssh/config HTTP/1.1" 444 0 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] )"
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-10-05 15:34:51
(3 days ago)
(mod_security) mod_security (id:949110) triggered by 34.21.207.148 (148.207.21.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:949110) triggered by 34.21.207.148 (148.207.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 11:34:44.868158 2026] [security2:error] [pid 16322:tid 16322] [client 34.21.207.148:39730] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "autodiscover.taxijunkremoval.com"] [uri "/document.php"] [unique_id "asPDlNExSYTFJU-IvT5BVAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐พ
Rizzy
2026-10-05 09:13:09
(3 days ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ฉ๐ช
bazter.pro
2026-10-05 09:07:30
(3 days ago)
Fail2Ban: plesk-bot-aggressive - 15 failures
Port Scan
Bad Web Bot
Web App Attack
๐น๐ท
ycoskun41
2026-10-05 08:59:44
(3 days ago)
fail2ban: plesk-modsecurity jail on genckocaeli.com
Web App Attack
๐ช๐ธ
robotstxt
2026-10-05 08:21:19
(3 days ago)
34.21.207.148 - - [05/Oct/2026:08:20:41 +0000] "GET /dist/manifest.json HTTP/2.0" 403 10490 "https:/ ...
show more
34.21.207.148 - - [05/Oct/2026:08:20:41 +0000] "GET /dist/manifest.json HTTP/2.0" 403 10490 "https://wpnoticias.com/dist/manifest.json" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "-" edge="34.21.207.148"
34.21.207.148 - - [05/Oct/2026:08:20:41 +0000] "GET /z9x8c7v6b5-debug-trigger-wpnoticias.com HTTP/2.0" 403 10988 "https://wpnoticias.com/z9x8c7v6b5-debug-trigger-wpnoticias.com" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)" "-" edge="34.21.207.148"
34.21.207.148 - - [05/Oct/2026:08:20:42 +0000] "GET /dist/.vite/manifest.json HTTP/2.0" 403 10511 "https://wpnoticias.com/dist/.vite/manifest.json" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "-" edge="34.21.207.148"
34.21.207.148 - - [05/Oct/2026:08:20:42 +0000] "GET /.vite/manifest.json HTTP/2.0" 403 10490 "https://wpnoticias.com/.vite/manifest.json" "Mozilla/5.0 (Windows NT
...
show less
Web App Attack
Anonymous
2026-10-05 08:06:15
(3 days ago)
34.21.207.148 - - [05/Oct/2026:16:06:14 +0800] "POST /lib/terminal-xhr.php HTTP/1.1" 404 196 "-" "Mo ...
show more
34.21.207.148 - - [05/Oct/2026:16:06:14 +0800] "POST /lib/terminal-xhr.php HTTP/1.1" 404 196 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.4; +https://openai.com/gptbot"
34.21.207.148 - - [05/Oct/2026:16:06:14 +0800] "GET /assets/manifest.json HTTP/1.1" 404 196 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
34.21.207.148 - - [05/Oct/2026:16:06:14 +0800] "GET /z9x8c7v6b5-debug-trigger-witgang.com HTTP/1.1" 404 196 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)"
34.21.207.148 - - [05/Oct/2026:16:06:14 +0800] "GET /h9rhqwfwzp4h61xtxh1p HTTP/1.1" 404 196 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)"
34.21.207.148 - - [05/Oct/2026:16:06:15 +0800] "GET /mnvrnvnl7azb2r4gdt10 HTTP/1.1" 404 196 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] )"
34.21.207.148 - - [05/Oct/2026:16:06:15 +0800] "GE
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 08:04:53
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 34.21.207.148 (148.207.21.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.21.207.148 (148.207.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 04:04:45.206453 2026] [security2:error] [pid 20551:tid 20551] [client 34.21.207.148:58592] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||wisconsinstatehuntingexpo.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "wisconsinstatehuntingexpo.com"] [uri "/z9x8c7v6b5-debug-trigger-wisconsinstatehuntingexpo.com"] [unique_id "asNaHQIMrpoE2wapWiIXHgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-10-05 07:33:39
(3 days ago)
465 requests with url.path */@fs/*
131 requests with url.path */proc/*
Brute-Force
Bad Web Bot
๐ฟ๐ฆ
conure.sh
2026-10-05 06:40:03
(3 days ago)
csagent: score 21.8: 404 noise floor x7, secrets grab x2; 1 domain(s) in 1s
Web App Attack
๐จ๐ฆ
polycoda
2026-10-05 05:56:25
(3 days ago)
AutoBlock: ๐ฏ Vulnerability Scanner (Non Decay-Based) - ๐ก Port Scan (Non Decay-Based) - โ Excessive 4 ...
show more
AutoBlock: ๐ฏ Vulnerability Scanner (Non Decay-Based) - ๐ก Port Scan (Non Decay-Based) - โ Excessive 40X Errors (Decay-Based)
show less
Port Scan
Hacking
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-10-05 03:43:08
(3 days ago)
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .back/ .b ...
show more
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .back/ .backup/ .bak/ .bck/ .bk/ .bkp/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .cnf/ .com/ .compositefont/ .config/ .conf/ .copy/ .crt/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dist/ .dll/ .dos/ .dpkg-dist/ .drv/ .gadget/ .hta/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .inf/ .ini/ .jks/ .jse/ .key/ .licx/ .lnk/ .log/ .mdb/ .msc/ .ocx/ .old/ .pass/ .pdb/ .pfx/ .pif/ .pem/ .pol/ .prf/ .printer/ .pwd/ .rdb/ .rdp/ .reg/ .resources/ .resx/ .sav/ .save/ .scr/ .sct/ .sh/ .shs/ .sql/ .sqlite/ .sqlite3/ .swap/ .swo/ .swp/ .sys/ .temp/ .tfstate/ .tlb/ .tmp/ .vb/ .vbe/ .vbs/ .vbproj/ .vsdisco/ .vxd/ .webinfo/ .ws/ .wsc/ .wsf/ .wsh/ .xsd/ .xsx/" at TX:extension. (920440-193)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-05 03:07:13
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 34.21.207.148 (148.207.21.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.21.207.148 (148.207.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 23:07:08.215835 2026] [security2:error] [pid 26211:tid 26211] [client 34.21.207.148:59214] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||title26.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "title26.com"] [uri "/z9x8c7v6b5-debug-trigger-title26.com"] [unique_id "asMUXFut0rpJ7py9BoxsGgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack