๐บ๐ธ
TPI-Abuse
2026-08-27 09:10:50
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.34.229.33 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 34.34.229.33 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 05:10:46.146396 2026] [security2:error] [pid 27823:tid 27823] [client 34.34.229.33:53113] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.206"] [uri "/.htaccess51480bc53d1e4d6f8a268bceda1f5aa4"] [unique_id "ao__FgigSQ99r0XzklaXLQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-08-27 07:56:12
(5 hours ago)
20 attempts against mh-misbehave-ban on chard
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
paulo.apoloni
2026-08-27 04:56:30
(8 hours ago)
34.34.229.33 - - [27/Aug/2026:01:56:28 -0300] "GET /.htaccess6e2d3d8df1304fd68fc4ef9fa0ee86a7 HTTP/1 ...
show more
34.34.229.33 - - [27/Aug/2026:01:56:28 -0300] "GET /.htaccess6e2d3d8df1304fd68fc4ef9fa0ee86a7 HTTP/1.1" 404 146 "-" "feroxbuster/2.13.1"
34.34.229.33 - - [27/Aug/2026:01:56:28 -0300] "GET /.htaccess6f132c9f7a6b4e659e28bc08e295c0eaed63c2265e804855ba8a1c25e0c5f7336420a7fce7134740bcdf0bcab6f7051a HTTP/1.1" 404 146 "-" "feroxbuster/2.13.1"
34.34.229.33 - - [27/Aug/2026:01:56:29 -0300] "GET /wp-content HTTP/1.1" 404 146 "-" "feroxbuster/2.13.1"
34.34.229.33 - - [27/Aug/2026:01:56:29 -0300] "GET /setup HTTP/1.1" 404 146 "-" "feroxbuster/2.13.1"
34.34.229.33 - - [27/Aug/2026:01:56:29 -0300] "GET /install HTTP/1.1" 404 146 "-" "feroxbuster/2.13.1"
...
show less
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-08-27 04:00:55
(9 hours ago)
Active Response: IP 34.34.229.33 Blocked via Firewall Drop, Suspicious user agent detected Python-ur ...
show more
Active Response: IP 34.34.229.33 Blocked via Firewall Drop, Suspicious user agent detected Python-urllib/3.14. Threat Score: 3.9/10 (LOW). Confidence: 30%. CVSS v3.1: 0/10 (None). CVSS Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:N. Bayesian Probability: 57%. MITRE ATT&CK: T1016 (System Network Configuration Discovery). Tactic: TA0001. Freshness: Fresh. Source Reputation: UNKNOWN. Methodology: CVSS 3.1 + Bayesian + Temporal + Environmental + MITRE ATT&CK + OWASP. Standards: ISO/IEC 27065:2022, NIST SP 800-30, IEEE S&P 2020. Reported by TangerangKota-CSIRT
show less
Hacking
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-08-27 03:01:02
(10 hours ago)
Active Response: IP 34.34.229.33 Blocked via Firewall Drop, Suspicious user agent detected Python-ur ...
show more
Active Response: IP 34.34.229.33 Blocked via Firewall Drop, Suspicious user agent detected Python-urllib/3.14. Threat Score: 4/10 (MEDIUM). Confidence: 40%. CVSS v3.1: 0/10 (None). CVSS Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:N. Bayesian Probability: 57%. MITRE ATT&CK: T1016 (System Network Configuration Discovery). Tactic: TA0001. Freshness: Fresh. Source Reputation: UNKNOWN. Methodology: CVSS 3.1 + Bayesian + Temporal + Environmental + MITRE ATT&CK + OWASP. Standards: ISO/IEC 27065:2022, NIST SP 800-30, IEEE S&P 2020. Reported by TangerangKota-CSIRT. Status: MALICIOUS
show less
Hacking
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-08-27 02:00:15
(11 hours ago)
Active Response: IP 34.34.229.33 Blocked via Firewall Drop. Threat Score: 0/10 (INFORMATIONAL). Repo ...
show more
Active Response: IP 34.34.229.33 Blocked via Firewall Drop. Threat Score: 0/10 (INFORMATIONAL). Reported by TangerangKota-CSIRT
show less
Hacking
Web App Attack
๐ซ๐ฎ
pixiekat
2026-08-26 22:35:40
(14 hours ago)
[Wed Aug 26 23:35:35.679565 2026] [authz_core:error] [pid 1202:tid 1234] [client 34.34.229.33:32309] ...
show more
[Wed Aug 26 23:35:35.679565 2026] [authz_core:error] [pid 1202:tid 1234] [client 34.34.229.33:32309] AH01630: client denied by server configuration: /var/www/html/
[Wed Aug 26 23:35:37.660846 2026] [authz_core:error] [pid 1174:tid 1305] [client 34.34.229.33:61203] AH01630: client denied by server configuration: /var/www/html/
[Wed Aug 26 23:35:38.359239 2026] [authz_core:error] [pid 1202:tid 1252] [client 34.34.229.33:34747] AH01630: client denied by server configuration: /var/www/html/
[Wed Aug 26 23:35:39.356240 2026] [authz_core:error] [pid 1174:tid 1308] [client 34.34.229.33:47337] AH01630: client denied by server configuration: /var/www/html/robots.txt
[Wed Aug 26 23:35:39.564305 2026] [authz_core:error] [pid 1202:tid 1237] [client 34.34.229.33:34747] AH01630: client denied by server configuration: /var/www/html/
...
show less
Brute-Force
Anonymous
2026-08-26 15:32:53
(21 hours ago)
Web Server Enforcement Violation.
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-26 12:14:53
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.34.229.33 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 34.34.229.33 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 08:14:48.667512 2026] [security2:error] [pid 19418:tid 19418] [client 34.34.229.33:53644] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.103"] [uri "/.htaccess68e8fc9923fa4b03850dc58176332034"] [unique_id "ao7YuKyL5Wtz4S6A6li7IQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
grassau.com
2026-08-25 21:06:02
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted] 34.34.229.33 (US/United States/Californ ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.34.229.33 (US/United States/California/Los Angeles/-)
show less
SQL Injection
๐ณ๐ฟ
Antinson
2026-08-20 22:52:59
(6 days ago)
Requests to unauthorized or suspicious endpoints (.git, .well-known, .php, etc.)
Bad Web Bot
๐ณ๐ฟ
Antinson
2026-08-15 22:23:52
(1 week ago)
Requests to unauthorized or suspicious endpoints (.git, .well-known, .php, etc.)
Bad Web Bot
Anonymous
2026-08-08 16:51:51
(2 weeks ago)
Reconnaissance scan targeting sensitive backup path: '/config_backup.zip'.
Hacking
Web App Attack
๐บ๐ธ
brantknudson.org
2026-08-08 06:41:07
(2 weeks ago)
Not GET, path='HEAD / HTTP/1.1'
Web App Attack
Hacking
๐ณ๐ฟ
Antinson
2026-07-23 16:38:16
(1 month ago)
Requests to unauthorized or suspicious endpoints (.git, .well-known, .php, etc.)
Bad Web Bot