🇬🇧
Aetherweb Ark
2026-09-15 21:52:30
(51 minutes ago)
(mod_security) mod_security (id:949110) triggered by 34.26.83.2 (US/United States/2.83.26.34.bc.goog ...
show more
(mod_security) mod_security (id:949110) triggered by 34.26.83.2 (US/United States/2.83.26.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
🇫🇷
hghosting
2026-09-15 21:45:59
(57 minutes ago)
CrowdSec auto-report: crowdsecurity/http-path-traversal-probing — 4 events
Brute-Force
SSH
🇺🇸
Blue Pumpkin
2026-09-15 21:45:58
(57 minutes ago)
34.26.83.2 - - [15/Sep/2026:21:45:57 +0000] "GET /key.json HTTP/1.1" 302 579 "-" "Mozilla/5.0 (compa ...
show more
34.26.83.2 - - [15/Sep/2026:21:45:57 +0000] "GET /key.json HTTP/1.1" 302 579 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
...
show less
Brute-Force
🇩🇪
gadix
2026-09-15 21:18:26
(1 hour ago)
[15/Sep/2026:23:18:25.615840 +0200] aqm2IfA2Gtw-CyZHthZmCQAAAAU 34.26.83.2 42042 127.0.0.1 7081
[15/ ...
show more
[15/Sep/2026:23:18:25.615840 +0200] aqm2IfA2Gtw-CyZHthZmCQAAAAU 34.26.83.2 42042 127.0.0.1 7081
[15/Sep/2026:23:18:26.527711 +0200] aqm2IvA2Gtw-CyZHthZmEQAAAAw 34.26.83.2 42148 127.0.0.1 7081
[15/Sep/2026:23:18:26.530213 +0200] aqm2Iq6lt7tHgiN7w-iXqQAAAJg 34.26.83.2 42158 127.0.0.1 7081
...
show less
Web App Attack
🇵🇱
dzpk
2026-09-15 20:44:23
(1 hour ago)
[15/Sep/2026:22:44:22 +0200] 178950506260.253961 34.26.83.2 36202 HOST 443 [15/Sep/2026:22:44:23 +02 ...
show more
[15/Sep/2026:22:44:22 +0200] 178950506260.253961 34.26.83.2 36202 HOST 443 [15/Sep/2026:22:44:23 +0200] 17895050639.618227 34.26.83.2 36202 HOST 443 [15/Sep/2026:22:44:23 +0200] 178950506323.594356 34.26.83.2 36202 HOST 443
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-15 20:32:22
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.26.83.2 (2.83.26.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210730) triggered by 34.26.83.2 (2.83.26.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 16:32:15.617458 2026] [security2:error] [pid 6155:tid 6155] [client 34.26.83.2:47798] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||desertalfas.org|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "desertalfas.org"] [uri "/rclone.conf"] [unique_id "aqmrT6g6s3Mv7nDiLTIS2wAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇭🇺
szasa
2026-09-15 20:17:49
(2 hours ago)
2026/09/15 22:17:46 [error] 1637722#1637722: *4952007 access forbidden by rule, client: 34.26.83.2, ...
show more
2026/09/15 22:17:46 [error] 1637722#1637722: *4952007 access forbidden by rule, client: 34.26.83.2, server: datamentor.hu, request: "GET /api/uploads/%2e%2e%2f%2e%2e%2f.env HTTP/2.0", host: "datamentor.hu"
2026/09/15 22:17:48 [error] 1637722#1637722: *4952007 access forbidden by rule, client: 34.26.83.2, server: datamentor.hu, request: "GET /public../.env HTTP/2.0", host: "datamentor.hu"
2026/09/15 22:17:48 [error] 1637722#1637722: *4952007 access forbidden by rule, client: 34.26.83.2, server: datamentor.hu, request: "GET /dist../.env HTTP/2.0", host: "datamentor.hu"
2026/09/15 22:17:48 [error] 1637722#1637722: *4952007 access forbidden by rule, client: 34.26.83.2, server: datamentor.hu, request: "GET /build../.env HTTP/2.0", host: "datamentor.hu"
...
show less
Web App Attack
🇬🇧
consul.to
2026-09-15 19:18:54
(3 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-09-15 18:53:41
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.26.83.2 (2.83.26.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.26.83.2 (2.83.26.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 14:53:33.001441 2026] [security2:error] [pid 19317:tid 19317] [client 34.26.83.2:57680] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dartylife.com"] [uri "/@fs/.env"] [unique_id "aqmULaiSFmi-bHpJJj1yRwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Savvii
2026-09-15 18:53:15
(3 hours ago)
20 attempts against mh-misbehave-ban on chive
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
900cm
2026-09-15 18:03:56
(4 hours ago)
[Tue Sep 15 20:03:55.944422 2026] [access_compat:error] [pid 263931:tid 263931] [client 34.26.83.2:4 ...
show more
[Tue Sep 15 20:03:55.944422 2026] [access_compat:error] [pid 263931:tid 263931] [client 34.26.83.2:40500] AH01797: client denied by server configuration: /var/www/darkintruder/.git
[Tue Sep 15 20:03:55.949401 2026] [access_compat:error] [pid 1593116:tid 1593116] [client 34.26.83.2:40544] AH01797: client denied by server configuration: /var/www/darkintruder/.aws
[Tue Sep 15 20:03:56.049927 2026] [access_compat:error] [pid 1641812:tid 1641812] [client 34.26.83.2:40528] AH01797: client denied by server configuration: /var/www/darkintruder/.gitlab-ci.yml
...
show less
Port Scan
Brute-Force
SSH
🇳🇱
e.fierstra
2026-09-15 17:40:44
(5 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-15 17:37:19
(5 hours ago)
(mod_security) mod_security (id:210580) triggered by 34.26.83.2 (2.83.26.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210580) triggered by 34.26.83.2 (2.83.26.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 13:37:11.729546 2026] [security2:error] [pid 21527:tid 21527] [client 34.26.83.2:36888] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at ARGS:filename. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||daretownkindling.com|F|2"] [data "Matched Data: proc/self/environ found within ARGS:filename: file:/proc/self/environ"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "daretownkindling.com"] [uri "/__vite_rsc_findSourceMapURL"] [unique_id "aqmCR56QrHt8HVZxn9xnRwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-09-15 17:05:21
(5 hours ago)
Scanning/Probing (19)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-15 14:55:39
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.26.83.2 (2.83.26.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.26.83.2 (2.83.26.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 10:55:33.318736 2026] [security2:error] [pid 14226:tid 14226] [client 34.26.83.2:46078] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "danieljensen.org"] [uri "/.env.bak"] [unique_id "aqlcZRVNNcr9X-mYVLCsNAAAADw"]
show less
Brute-Force
Bad Web Bot
Web App Attack