π«π·
IRISIO
2026-09-30 13:06:09
(7 hours ago)
scans/SQL injection/spam posts : 1568 queries
Web App Attack
SQL Injection
πΊπΈ
TPI-Abuse
2026-09-30 02:09:49
(17 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.39.217.228 (228.217.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.39.217.228 (228.217.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 22:09:45.245975 2026] [security2:error] [pid 11551:tid 11551] [client 34.39.217.228:48464] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||edscontracting.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "edscontracting.com"] [uri "/z9x8c7v6b5-debug-trigger-edscontracting.com"] [unique_id "arxvaa6KmF7Fboz7zqQJMgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-30 00:40:08
(19 hours ago)
Aggressive web scan
Web App Attack
π©πͺ
updown.io
2026-09-29 23:53:00
(20 hours ago)
{"level":"info","ts":1790725974.611635,"logger":"http.log.access.log0","msg":"handled request","requ ...
show more
{"level":"info","ts":1790725974.611635,"logger":"http.log.access.log0","msg":"handled request","request":{"remote_ip":"34.39.217.228","remote_port":"57294","client_ip":"34.39.217.228","proto":"HTTP/2.0","method":"GET","host":"ehyu.status.updown.io","uri":"/config/firebase-admin.json","headers":{"Accept-Encoding":["gzip"],"X-Middleware-Subrequest":["src/middleware:nowaf:src/middleware:src/middleware:src/middleware:src/middleware:middleware:middleware:nowaf:middleware:middleware:middleware:pages/_middleware"],"X-Nextjs-Data":["1"],"User-Agent":["Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36"],"Accept":["*/*"],"Cookie":["REDACTED"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"h2","server_name":"ehyu.status.updown.io","ech":false}},"bytes_read":0,"user_id":"","duration":0.000156969,"size":0,"status":429,"resp_headers":{"Server":["Caddy"],"Alt-Svc":["h3=\":443\"; ma=2592000"],"Retry-After":["1"]}}
{"level":"info","ts":1790725974
...
show less
DDoS Attack
Web App Attack
Anonymous
2026-09-29 21:14:33
(22 hours ago)
Sensitive file access attempt
Hacking
π«π·
IRISIO
2026-09-29 21:00:24
(23 hours ago)
scans/SQL injection/spam posts : 271 queries
Web App Attack
SQL Injection
Anonymous
2026-09-29 20:08:29
(23 hours ago)
Portscan: TCP/8443 (8x), TCP/8080 (8x), TCP/443, TCP/80 (2x)
Port Scan
πΊπΈ
TPI-Abuse
2026-09-29 19:02:39
(1 day ago)
(mod_security) mod_security (id:210580) triggered by 34.39.217.228 (228.217.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210580) triggered by 34.39.217.228 (228.217.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 15:02:34.866313 2026] [security2:error] [pid 19688:tid 19721] [client 34.39.217.228:59526] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at ARGS:apis. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||ehealthpass.com|F|2"] [data "Matched Data: proc/self/environ found within ARGS:apis: ../../../../../../proc/self/environ"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "ehealthpass.com"] [uri "/api/console/api_server"] [unique_id "arwLSpgw5SzfXYqLgQPBVAAAAI4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-29 18:44:03
(1 day ago)
IP matched detection query more than 2 hosts and only bad rq long ban.
Brute-Force
Web App Attack
Hacking
π«π·
GEDAL
2026-09-29 18:34:28
(1 day ago)
Fail2ban webexploits @ <hostname> : 34.39.217.228 - - [29/Sep/2026:20:34:27 +0200] "GET /.git/config ...
show more
Fail2ban webexploits @ <hostname> : 34.39.217.228 - - [29/Sep/2026:20:34:27 +0200] "GET /.git/config HTTP/2.0" 301 162 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)"
show less
Brute-Force
SSH
πΊπΈ
TPI-Abuse
2026-09-29 18:15:08
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.39.217.228 (228.217.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.217.228 (228.217.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 14:15:02.050679 2026] [security2:error] [pid 27043:tid 27043] [client 34.39.217.228:58688] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "edgecombe.net"] [uri "/.htpasswd"] [unique_id "arwAJvq0-eTo3D1YM8l3xAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
Bedios GmbH
2026-09-29 17:57:51
(1 day ago)
Login credentials theft attempt
Hacking
π³π±
WeCloudit-Anti-Abuse
2026-09-29 17:48:35
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
π©πͺ
FD-IX
2026-09-29 17:30:35
(1 day ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
Anonymous
2026-09-29 17:16:20
(1 day ago)
IP matched detection query 50 and more bad rqs apache.
Hacking
Bad Web Bot
Brute-Force
Web App Attack