๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-23 16:46:20
(13 minutes ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐จ๐ฆ
polycoda
2026-09-23 16:29:41
(29 minutes ago)
AutoBlock: ๐ก Port Scan (Non Decay-Based) - โ Excessive 40X Errors (Decay-Based) - โช๏ธ Excessive 30X E ...
show more
AutoBlock: ๐ก Port Scan (Non Decay-Based) - โ Excessive 40X Errors (Decay-Based) - โช๏ธ Excessive 30X Errors (Decay-Based)
show less
Port Scan
Bad Web Bot
๐ณ๐ฑ
GabrielJST
2026-09-23 16:15:45
(43 minutes ago)
(mod_security) mod_security triggered on hostname [redacted] 34.38.167.212 (BE/Belgium/212.167.38.34 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.38.167.212 (BE/Belgium/212.167.38.34.bc.googleusercontent.com): (CF_ENABLE)
show less
SQL Injection
๐ซ๐ท
dynamix
2026-09-23 16:06:17
(53 minutes ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
TheDjRider
2026-09-23 16:01:38
(57 minutes ago)
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban tri ...
show more
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban triggered. Detection time (UTC): 2026-09-23T16:01:35.938109522Z. Context: http_status=301, http_status=200
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 16:00:15
(59 minutes ago)
(mod_security) mod_security (id:210730) triggered by 34.38.167.212 (212.167.38.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.38.167.212 (212.167.38.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 12:00:08.629370 2026] [security2:error] [pid 24928:tid 24928] [client 34.38.167.212:47860] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ewingmissouri.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ewingmissouri.com"] [uri "/z9x8c7v6b5-debug-trigger-ewingmissouri.com"] [unique_id "arP3iPn0GHmjSpGjjV1gDAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-23 15:55:23
(1 hour ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-23 15:34:01
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.38.167.212 (212.167.38.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.38.167.212 (212.167.38.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 11:33:55.886504 2026] [security2:error] [pid 31262:tid 31271] [client 34.38.167.212:35098] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hdtv55.com"] [uri "/.env.development"] [unique_id "arPxY1V87XB76I5mpwd-MAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 14:58:47
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.38.167.212 (212.167.38.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.38.167.212 (212.167.38.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 10:58:39.933065 2026] [security2:error] [pid 7577:tid 7577] [client 34.38.167.212:39840] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||lsd36.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "lsd36.com"] [uri "/z9x8c7v6b5-debug-trigger-lsd36.com"] [unique_id "arPpH0XcaAGRIwkclJuMKwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 14:16:36
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.38.167.212 (212.167.38.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.38.167.212 (212.167.38.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 10:16:31.732403 2026] [security2:error] [pid 28416:tid 28416] [client 34.38.167.212:58566] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "piratecostumesonline.com"] [uri "/.env"] [unique_id "arPfPzSy2WD7eQ5Mxf5q1AAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-23 14:15:42
(2 hours ago)
Port scan against our edge firewall, detected by Wazuh: Regel 31151 | abuseipdb 42% (6 Meldungen, BE ...
show more
Port scan against our edge firewall, detected by Wazuh: Regel 31151 | abuseipdb 42% (6 Meldungen, BE)
show less
Port Scan
Anonymous
2026-09-23 13:30:22
(3 hours ago)
34.38.167.212 - - [23/Sep/2026:08:30:02 -0500] "GET /.env?raw HTTP/1.1" 403 199 "http://synapseresul ...
show more
34.38.167.212 - - [23/Sep/2026:08:30:02 -0500] "GET /.env?raw HTTP/1.1" 403 199 "http://synapseresults.com/.env?raw" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)" 172.71.131.103
34.38.167.212 - - [23/Sep/2026:08:30:02 -0500] "GET /.env?import&raw HTTP/1.1" 403 199 "http://synapseresults.com/.env?import&raw" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot" 172.71.131.103
34.38.167.212 - - [23/Sep/2026:08:30:02 -0500] "GET /.env?import&url&inline HTTP/1.1" 403 199 "http://synapseresults.com/.env?import&url&inline" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )" 172.71.131.103
34.38.167.212 - - [23/Sep/2026:08:30:02 -0500] "GET /.env.local?raw HTTP/1.1" 403 199 "http://synapseresults.com/.env.local?raw" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)" 172.71.131.103
34.38.167.212 - - [23/Sep/2026:08:30:02 -0500] "GET /.env.local?import&raw HTTP/1.1" 403 1
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 13:01:23
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.38.167.212 (212.167.38.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.38.167.212 (212.167.38.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 09:01:18.162938 2026] [security2:error] [pid 25128:tid 25128] [client 34.38.167.212:43840] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||unified-dispatch.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "unified-dispatch.com"] [uri "/z9x8c7v6b5-debug-trigger-unified-dispatch.com"] [unique_id "arPNnucaUSgqoiyG67uQYAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
[email protected]
2026-09-23 12:58:02
(4 hours ago)
CrowdSec ban: crowdsecurity/http-path-traversal-probing (duration: 71h59m54s)
Web App Attack
๐ง๐ฌ
HighWay
2026-09-23 12:42:39
(4 hours ago)
34.38.167.212 - - [23/Sep/2026:12:42:23 +0000] "GET /fhqbrhxcb1lauucdnur2 HTTP/1.1" 404 4758 "-" "Mo ...
show more
34.38.167.212 - - [23/Sep/2026:12:42:23 +0000] "GET /fhqbrhxcb1lauucdnur2 HTTP/1.1" 404 4758 "-" "Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)"
34.38.167.212 - - [23/Sep/2026:12:42:23 +0000] "GET /oucd2i6h168lkg7xko6k HTTP/1.1" 404 4757 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)"
34.38.167.212 - - [23/Sep/2026:12:42:23 +0000] "POST /graphql HTTP/1.1" 404 770 "https://vhelectronics.com" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36"
34.38.167.212 - - [23/Sep/2026:12:42:24 +0000] "POST /api/graphql HTTP/1.1" 404 770 "https://vhelectronics.com" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36"
34.38.167.212 - - [23/Sep/2026:12:42:25 +0000] "GET /sign-in HTTP/1.1" 404 770 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36"
34.38.167.212 - - [23/Sep/202
...
show less
Bad Web Bot
Web App Attack