๐บ๐ธ
chronos
2026-10-05 17:56:57
(16 hours ago)
[AUTORAVALT][[05/10/2026 - 14:56:56 -03:00 UTC]
Attack from [Google LLC]
[34.39.158.232][232.158.39. ...
show more
[AUTORAVALT][[05/10/2026 - 14:56:56 -03:00 UTC]
Attack from [Google LLC]
[34.39.158.232][232.158.39.34.bc.googleusercontent.com]
Action: BLocKed
DDoS Attack -> Participating in distributed denial-of-service.
Phishing -> Phishing websites and/or email.
Web Spam -> Comment/forum spam, HTTP referer spam, or other CMS spam.
Blog Spam -> CMS blog comment spam.
Web]
...
show less
DDoS Attack
Phishing
Web Spam
Blog Spam
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-10-05 14:42:34
(19 hours ago)
excessive HTTP 404 errors
Bad Web Bot
๐บ๐ธ
solantex
2026-10-05 13:04:11
(21 hours ago)
Unauthorized automated scanning and reconnaissance against Solantex resources. No crawl, scan or tes ...
show more
Unauthorized automated scanning and reconnaissance against Solantex resources. No crawl, scan or test permission has been granted to this source.
show less
Web App Attack
๐บ๐ธ
oralunal
2026-10-05 12:36:47
(21 hours ago)
IP banned by Fail2Ban in jail oral-suss access.log mvfnds
...
Bad Web Bot
Web App Attack
๐ฉ๐ช
konseptit
2026-10-05 11:29:32
(23 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.39.158.232 (BR/Brazil/232.158.39.34. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.39.158.232 (BR/Brazil/232.158.39.34.bc.googleusercontent.com)
show less
SQL Injection
๐ซ๐ฎ
sibahota
2026-10-05 10:42:36
(23 hours ago)
34.39.158.232 - - [05/Oct/2026:10:42:35 +0000] nidandiagnostic.com "POST / HTTP/2.0" 403 26 0.000 "- ...
show more
34.39.158.232 - - [05/Oct/2026:10:42:35 +0000] nidandiagnostic.com "POST / HTTP/2.0" 403 26 0.000 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )" - - - "http://nidandiagnostic.com"
34.39.158.232 - - [05/Oct/2026:10:42:35 +0000] nidandiagnostic.com "GET /f4p505huvoeayk6g9ula HTTP/2.0" 403 26 0.000 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )" - - - "http://nidandiagnostic.com"
...
show less
Bad Web Bot
๐จ๐ฆ
Mediashaker
2026-10-05 09:14:31
(1 day ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 34.39.158.232 (BR/Br ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 34.39.158.232 (BR/Brazil/232.158.39.34.bc.googleusercontent.com)
show less
Bad Web Bot
๐ง๐ช
cmbplf
2026-10-05 08:36:40
(1 day ago)
134 requests with url.path */@fs/*
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-05 08:28:58
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.39.158.232 (232.158.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.39.158.232 (232.158.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 04:28:50.992979 2026] [security2:error] [pid 3135:tid 3135] [client 34.39.158.232:50224] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||morganmotors.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "morganmotors.com"] [uri "/z9x8c7v6b5-debug-trigger-morganmotors.com"] [unique_id "asNfwo9T1Uk-hfpOH_l0QwAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 06:39:58
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.39.158.232 (232.158.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.39.158.232 (232.158.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 02:39:53.225707 2026] [security2:error] [pid 15128:tid 15128] [client 34.39.158.232:41480] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||markrikey.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "markrikey.com"] [uri "/z9x8c7v6b5-debug-trigger-markrikey.com"] [unique_id "asNGOa2zYAqiw376EqZ56gAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-05 05:26:22
(1 day ago)
Banned by Fail2Ban on server
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 05:08:42
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.39.158.232 (232.158.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.39.158.232 (232.158.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 01:08:39.373934 2026] [security2:error] [pid 4001:tid 4001] [client 34.39.158.232:55030] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||luxurymicrobikini.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "luxurymicrobikini.com"] [uri "/z9x8c7v6b5-debug-trigger-luxurymicrobikini.com"] [unique_id "asMw1xpyunOvPFRW2LYl1gAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-10-05 04:59:57
(1 day ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-10-05 04:47:24
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.39.158.232 (232.158.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.39.158.232 (232.158.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 00:47:16.362678 2026] [security2:error] [pid 22877:tid 22877] [client 34.39.158.232:49274] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||lucid-events.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "lucid-events.com"] [uri "/z9x8c7v6b5-debug-trigger-lucid-events.com"] [unique_id "asMr1FHs8MW41HC2NIEx9QAAAC8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 02:58:55
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.39.158.232 (232.158.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.158.232 (232.158.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 22:58:50.284118 2026] [security2:error] [pid 26476:tid 26476] [client 34.39.158.232:45420] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "linuxforpoets.com"] [uri "/assets../.env"] [unique_id "asMSaorhPeBvbe9ivDAU3AAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack