๐ฎ๐ณ
evicky2002
2026-07-31 06:00:00
(1 day ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ฉ๐ช
Hazzard
2026-07-30 07:22:19
(2 days ago)
*Port Scan* detected from 34.22.134.23 (BE/Belgium/Brussels Capital/Brussels/23.134.22.34.bc.googleu ...
show more
*Port Scan* detected from 34.22.134.23 (BE/Belgium/Brussels Capital/Brussels/23.134.22.34.bc.googleusercontent.com/[redacted]).
show less
Port Scan
๐ฉ๐ช
33three
2026-07-30 05:41:20
(2 days ago)
Fail2Ban jail WebAttack triggered
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-30 05:33:40
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.22.134.23 (23.134.22.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.22.134.23 (23.134.22.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 30 01:33:32.908204 2026] [security2:error] [pid 13341:tid 13341] [client 34.22.134.23:55044] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||members.oxfordgliding.com|F|2"] [data ".oxfordgliding.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "members.oxfordgliding.com"] [uri "/z9x8c7v6b5-debug-trigger-members.oxfordgliding.com"] [unique_id "amriLDHjHfgxe9dpA0oXUwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
MatCat
2026-07-30 05:05:07
(2 days ago)
Banned by fail2ban: apache-webprobe
Port Scan
Bad Web Bot
๐บ๐ธ
Matthew Ping
2026-07-30 05:00:02
(2 days ago)
ModSecurity rule 949110 triggered on server. Web application attack blocked by CSF/LFD.
Web App Attack
Hacking
๐ฉ๐ช
zumbo.net
2026-07-30 04:37:38
(2 days ago)
[Thu Jul 30 07:37:37.629118 2026] [proxy_fcgi:error] [pid 2093741:tid 2093784] [client 34.22.134.23: ...
show more
[Thu Jul 30 07:37:37.629118 2026] [proxy_fcgi:error] [pid 2093741:tid 2093784] [client 34.22.134.23:0] AH01071: Got error 'Primary script unknown'
[Thu Jul 30 07:37:37.629423 2026] [proxy_fcgi:error] [pid 2093741:tid 2093782] [client 34.22.134.23:0] AH01071: Got error 'Primary script unknown'
[Thu Jul 30 07:37:37.645480 2026] [proxy_fcgi:error] [pid 2093741:tid 2093759] [client 34.22.134.23:0] AH01071: Got error 'Primary script unknown'
[Thu Jul 30 07:37:37.667888 2026] [proxy_fcgi:error] [pid 2093741:tid 2093792] [client 34.22.134.23:0] AH01071: Got error 'Primary script unknown'
[Thu Jul 30 07:37:37.669392 2026] [proxy_fcgi:error] [pid 2093741:tid 2093749] [client 34.22.134.23:0] AH01071: Got error 'Primary script unknown'
...
show less
Brute-Force
Web App Attack
Anonymous
2026-07-30 03:52:59
(2 days ago)
Aggressive web scan
Web App Attack
Anonymous
2026-07-30 03:43:14
(2 days ago)
(mod_security) mod_security triggered on hostname [redacted] 34.22.134.23 (BE/Belgium/23.134.22.34.b ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.22.134.23 (BE/Belgium/23.134.22.34.bc.googleusercontent.com)
show less
SQL Injection
Anonymous
2026-07-30 02:05:05
(2 days ago)
WAF repeated trigger detected by Fail2Ban
Web App Attack
๐ช๐ธ
alferez
2026-07-30 00:19:15
(2 days ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-30 00:11:52
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.22.134.23 (23.134.22.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.22.134.23 (23.134.22.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 20:11:47.747158 2026] [security2:error] [pid 3287071:tid 3287071] [client 34.22.134.23:56482] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "oauth.progressivefileshare.org"] [uri "/.git/config"] [unique_id "amqWw6Ejd4o1LIeFaXoVEgAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-30 00:06:06
(2 days ago)
Trying to access config files
Web App Attack
๐ซ๐ท
Octopuce
2026-07-29 23:45:38
(2 days ago)
Aggressive web search of vulnerable pages: /.env /.env.local /backend/.env /api/.env /config/.env . ...
show more
Aggressive web search of vulnerable pages: /.env /.env.local /backend/.env /api/.env /config/.env ...
show less
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-07-29 23:30:08
(2 days ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack