๐บ๐ธ
TPI-Abuse
2026-09-16 03:48:07
(28 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.31.231.203 (203.231.31.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.31.231.203 (203.231.31.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 23:48:03.566254 2026] [security2:error] [pid 22630:tid 22630] [client 34.31.231.203:42516] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "edgewatertaxidermy.com"] [uri "/%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env"] [unique_id "aqoRc2md9NctBjzGShrmAQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-16 03:36:17
(40 minutes ago)
(mod_security) mod_security triggered on hostname [redacted] 34.31.231.203 (US/United States/203.231 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.31.231.203 (US/United States/203.231.31.34.bc.googleusercontent.com)
show less
SQL Injection
๐ฉ๐ช
Petros Stefanakis
2026-09-16 02:48:58
(1 hour ago)
(mod_security) mod_security triggered on hostname [redacted] 34.31.231.203 (US/United States/203.231 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.31.231.203 (US/United States/203.231.31.34.bc.googleusercontent.com)
show less
SQL Injection
๐ณ๐ฑ
Savvii
2026-09-16 02:46:36
(1 hour ago)
20 attempts against mh-misbehave-ban on ozone
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 02:30:56
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 34.31.231.203 (203.231.31.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.31.231.203 (203.231.31.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 22:30:50.882037 2026] [security2:error] [pid 9188:tid 9188] [client 34.31.231.203:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||eddysgroup.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "eddysgroup.com"] [uri "/rclone.conf"] [unique_id "aqn_WhNmX3_cai3at17-vgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-16 01:45:04
(2 hours ago)
34.31.231.203 - - [16/Sep/2026:09:45:03 +0800] "GET /rclone.conf HTTP/1.1" 404 296486 "-" "Mozilla/5 ...
show more
34.31.231.203 - - [16/Sep/2026:09:45:03 +0800] "GET /rclone.conf HTTP/1.1" 404 296486 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot)"
34.31.231.203 - - [16/Sep/2026:09:45:04 +0800] "GET /dashboard%2F.env HTTP/1.1" 404 196 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)"
34.31.231.203 - - [16/Sep/2026:09:45:04 +0800] "GET /admin%2F.env HTTP/1.1" 404 196 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; OAI-SearchBot/1.0; +https://openai.com/searchbot)"
34.31.231.203 - - [16/Sep/2026:09:45:04 +0800] "GET /icons/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/proc/self/environ HTTP/1.1" 400 226 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot)"
34.31.231.203 - - [16/Sep/2026:09:45:04 +0800] "GET /assets/manifest.json HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) C
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 01:30:38
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.31.231.203 (203.231.31.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.31.231.203 (203.231.31.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 21:30:33.638996 2026] [security2:error] [pid 13960:tid 13960] [client 34.31.231.203:53490] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ecuablue.farm|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ecuablue.farm"] [uri "/rclone.conf"] [unique_id "aqnxOUETEXR1V6C25mytRQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
YF
2026-09-16 01:30:34
(2 hours ago)
Distributed subnet attack โ coordinated scanning from multiple IPs in the same /24
DDoS Attack
Web App Attack
๐ง๐พ
lns.bz
2026-09-16 01:12:19
(3 hours ago)
Too many 404 requests [BY]
Web App Attack
๐ฌ๐ง
andypiper
2026-09-16 01:01:54
(3 hours ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-16 00:51:59
(3 hours ago)
Excessive multi-domain requests
Brute-Force
๐ซ๐ท
masterguru
2026-09-16 00:12:37
(4 hours ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
๐ฎ๐ณ
evicky2002
2026-09-16 00:02:04
(4 hours ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ช๐ธ
robotstxt
2026-09-15 23:50:39
(4 hours ago)
34.31.231.203 - - [15/Sep/2026:23:49:49 +0000] "GET /.git/config HTTP/2.0" 403 49671 "-" "Mozilla/5. ...
show more
34.31.231.203 - - [15/Sep/2026:23:49:49 +0000] "GET /.git/config HTTP/2.0" 403 49671 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)" "-"
34.31.231.203 - - [15/Sep/2026:23:49:49 +0000] "GET /.github/workflows/deploy.yml HTTP/2.0" 403 49668 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )" "-"
34.31.231.203 - - [15/Sep/2026:23:49:49 +0000] "GET /.git/HEAD HTTP/2.0" 403 49671 "-" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)" "-"
34.31.231.203 - - [15/Sep/2026:23:49:49 +0000] "GET /.aws/credentials HTTP/2.0" 403 49668 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.3; +https://openai.com/gptbot)" "-"
34.31.231.203 - - [15/Sep/2026:23:49:50 +0000] "GET /.env HTTP/2.0" 403 49670 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)" "-"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 22:59:14
(5 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.31.231.203 (203.231.31.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.31.231.203 (203.231.31.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 18:59:08.530509 2026] [security2:error] [pid 21333:tid 21333] [client 34.31.231.203:37134] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ecomim.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ecomim.com"] [uri "/rclone.conf"] [unique_id "aqnNvMNpPiAXhxzxxbcuCwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack