πΊπΈ
MatCat
2026-10-09 15:05:17
(4 hours ago)
Banned by fail2ban: apache-noscript, apache-webprobe
Port Scan
Hacking
Bad Web Bot
Web App Attack
πΊπΈ
NXTwoThou
2026-10-09 14:42:51
(4 hours ago)
api
Web App Attack
π©πͺ
Hazzard
2026-10-09 14:17:04
(4 hours ago)
(PERMBLOCK) 34.39.214.224 (BR/Brazil/SΓ£o Paulo/SΓ£o Paulo/224.214.39.34.bc.googleusercontent.com/[red ...
show more
(PERMBLOCK) 34.39.214.224 (BR/Brazil/SΓ£o Paulo/SΓ£o Paulo/224.214.39.34.bc.googleusercontent.com/[redacted]) has had more than 4 temp blocks
show less
Hacking
Anonymous
2026-10-09 14:05:06
(5 hours ago)
WAF repeated trigger detected by Fail2Ban
Web App Attack
π©πͺ
Hazzard
2026-10-09 12:58:17
(6 hours ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
π³π±
i-turnradio.nl
2026-10-09 12:37:07
(6 hours ago)
2026-10-09 @ 14:37:06 (CET) ~ Blocked for trying to access: /lib/terminal-xhr.php
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-09 11:54:26
(7 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.39.214.224 (224.214.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.39.214.224 (224.214.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 07:54:21.973583 2026] [security2:error] [pid 21714:tid 21714] [client 34.39.214.224:40686] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||wisdomsco.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "wisdomsco.com"] [uri "/z9x8c7v6b5-debug-trigger-wisdomsco.com"] [unique_id "asjV7epLFNMA48crdlrvDwAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
Tha_14
2026-10-09 11:48:21
(7 hours ago)
Multiple erroneous requests
Web App Attack
π¨π¦
Anytech
2026-10-09 10:40:08
(8 hours ago)
Blocked by Conn-Monitor: env-probing
Web App Attack
Hacking
π·π΄
clauss
2026-10-09 10:12:36
(8 hours ago)
34.39.214.224 - - [09/Oct/2026:13:12:35 +0300] "GET /__vite_rsc_findSourceMapURL?filename=file:///ro ...
show more
34.39.214.224 - - [09/Oct/2026:13:12:35 +0300] "GET /__vite_rsc_findSourceMapURL?filename=file:///root/.aws/credentials&environmentName=rsc HTTP/2.0" 301 0 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)"
34.39.214.224 - - [09/Oct/2026:13:12:36 +0300] "GET /__vite_rsc_findSourceMapURL?filename=file:///root/.aws/credentials&environmentName=rsc HTTP/2.0" 404 14312 "https://remusazoitei.com/__vite_rsc_findSourceMapURL?filename=file:///root/.aws/credentials&environmentName=rsc" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)"
...
show less
Web App Attack
π³π±
e.fierstra
2026-10-09 09:35:03
(9 hours ago)
excessive HTTP 404 errors
Bad Web Bot
π«π·
baphomet
2026-10-09 09:28:00
(9 hours ago)
Probed planted web canary URI (not a real app path).
HTTP request completed against planted URIs (.e ...
show more
Probed planted web canary URI (not a real app path).
HTTP request completed against planted URIs (.env/wp-login/xmlrpc/phpmyadmin/.git).
jail=nginx-canary proto=tcp port=80,443 failures>=2 class=web-app-probe
these paths are not real apps on this host; hit is hostile recon
when=2026-10-09T09:28:00Z sensor=fail2ban role=web-canary
src=34.39.214.224
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-09 09:14:21
(9 hours ago)
(mod_security) mod_security (id:210580) triggered by 34.39.214.224 (224.214.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210580) triggered by 34.39.214.224 (224.214.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 05:14:16.043408 2026] [security2:error] [pid 1371:tid 1412] [client 34.39.214.224:48098] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at ARGS:apis. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||realauthentic.coffee|F|2"] [data "Matched Data: proc/self/environ found within ARGS:apis: ../../../../../../proc/self/environ"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "realauthentic.coffee"] [uri "/api/console/api_server"] [unique_id "asiwaCHKS9XPRB3wHBbXWwAAAEg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-09 08:57:11
(10 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.39.214.224 (224.214.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.39.214.224 (224.214.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 04:57:07.736017 2026] [security2:error] [pid 27770:tid 27836] [client 34.39.214.224:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||raytbrown.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "raytbrown.com"] [uri "/z9x8c7v6b5-debug-trigger-raytbrown.com"] [unique_id "asisY1mfzckY-V9gZNmPywAAAEM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
consul.to
2026-10-09 08:36:50
(10 hours ago)
Web attack/malicious scanning detected
Web App Attack