π§π·
radardatelecom
2026-09-30 22:26:03
(2 days ago)
Blocked by Radar da Telecom firewall β abuseipdb
Bad Web Bot
Web App Attack
π³π±
homeshowdomain.nl
2026-09-30 22:01:30
(2 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-29.
show less
Web App Attack
SSH
Hacking
π©πͺ
FeG Deutschland
2026-09-30 03:31:22
(3 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1248
Exploited Host
Web App Attack
Anonymous
2026-09-30 00:29:39
(3 days ago)
Aggressive web scan
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-30 00:21:49
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.34.70.114 (114.70.34.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.34.70.114 (114.70.34.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 20:21:43.034776 2026] [security2:error] [pid 7147:tid 7162] [client 34.34.70.114:48466] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lex.nederbragt.net"] [uri "/userfiles/x"] [unique_id "arxWF2JLoUnRVIHkJwOT8wAAAIE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¦πΊ
paulshipley.com.au
2026-09-30 00:20:57
(3 days ago)
[Wed Sep 30 10:20:56.849820 2026] [security2:error] [pid 317399] [client 34.34.70.114:51432] [client ...
show more
[Wed Sep 30 10:20:56.849820 2026] [security2:error] [pid 317399] [client 34.34.70.114:51432] [client 34.34.70.114] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "levellagiftware.com.au"] [uri "/.ssh/config"] [unique_id "arxV6Om2YNYsv-FsYm0uugAAABc"]
...
show less
Web App Attack
π³π±
Savvii
2026-09-29 23:59:07
(3 days ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
π§πͺ
cmbplf
2026-09-29 23:35:26
(3 days ago)
644 requests with url.path */@fs/*
213 requests with url.path */proc/*
163 requests with url.path ...
show more
644 requests with url.path */@fs/*
213 requests with url.path */proc/*
163 requests with url.path *credentials.json
162 requests with url.path *.aws/*
149 requests with url.path *config.json
142 requests with url.path *.ssh/*
131 requests with url.path *.php.bak
show less
Brute-Force
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-09-29 22:31:46
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 34.34.70.114 (114.70.34.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.34.70.114 (114.70.34.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 18:31:39.502129 2026] [security2:error] [pid 15745:tid 15745] [client 34.34.70.114:45702] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||letyourlightshineout.systemcapacityoptimization.com|F|2"] [data ".systemcapacityoptimization.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "letyourlightshineout.systemcapacityoptimization.com"] [uri "/z9x8c7v6b5-debug-trigger-letyourlightshineout.systemcapacityoptimization.com"] [unique_id "arw8S24X6MLmDNvmhpAIjwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-29 22:12:32
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.34.70.114 (114.70.34.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.34.70.114 (114.70.34.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 18:12:28.460519 2026] [security2:error] [pid 29015:tid 29015] [client 34.34.70.114:45154] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "leveeboard.org"] [uri "/storage/.env"] [unique_id "arw3zD2_fkWvkXZDG-ZxPQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
raph
2026-09-29 21:54:55
(3 days ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-29 20:22:05
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 34.34.70.114 (114.70.34.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.34.70.114 (114.70.34.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 16:22:00.949715 2026] [security2:error] [pid 1374:tid 1374] [client 34.34.70.114:47572] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||levijoneslegal.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "levijoneslegal.com"] [uri "/z9x8c7v6b5-debug-trigger-levijoneslegal.com"] [unique_id "arwd6OWjpN0dpnr3t-0GugAAACs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
WellSpring
2026-09-29 20:07:07
(4 days ago)
env leak on letspaws.org/public/.env β WellSpr.ing/NetSentinel civic-AI security layer
Web App Attack
π©πͺ
LRob
2026-09-29 19:51:21
(4 days ago)
Crawler ignoring refusals | ua: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Geck ...
show more
Crawler ignoring refusals | ua: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36, Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.4; +https://openai.com/gptbot, Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36; compatibl (+2 more) | path: /dist/manifest.json, /asset-manifest.json, /hrkiuh4do80pij01q5si (+6 more)
show less
Bad Web Bot
π«π·
dynamix
2026-09-29 18:10:39
(4 days ago)
Multiple WAF Violations
Web App Attack