๐บ๐ธ
oralunal
2026-10-03 02:09:12
(40 minutes ago)
IP banned by Fail2Ban in jail ah-suss access.log mvfnds
...
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-10-03 00:47:24
(2 hours ago)
Wordlist path sweep | method: GET | path: /fh29ugvfa87v5x5nv28e, /dist/manifest.json, /webpack-stats ...
show more
Wordlist path sweep | method: GET | path: /fh29ugvfa87v5x5nv28e, /dist/manifest.json, /webpack-stats.json | ua: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36; compatibl, Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Mobile Safari/537.36 EdgA/153.0.0.0 | 2026-10-03 00:47 UTC
show less
Port Scan
Web App Attack
๐ณ๐ฑ
ConsulHosting
2026-10-02 20:35:40
(6 hours ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
Anonymous
2026-10-02 18:35:03
(8 hours ago)
Bot / scanning and/or hacking attempts: POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/. ...
show more
Bot / scanning and/or hacking attempts: POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e, POST /cgi-bin/php?-d+allow_url_include%3don+-d+auto_prepend_fil, POST /api/designer/v1/file-content HTTP/2.0, POST /api/v1/validate/code HTTP/2.0, POST /feast/read-document HTTP/2.0, POST /index.php?%ADd+allow_url_include%3d1+%ADd+auto_prepend_fi, POST /cgi-bin/php-cgi.exe?%ADd+allow_url_include%3d1+%ADd+auto_, POST /index.php?-d+allow_url_include%3don+-d+auto_prepend_file%, POST /langflow/api/v1/validate/code HTTP/2.0, POST /cgi-bin/php-cgi?-d+allow_url_include%3don+-d+auto_prepend, POST /cgi-bin/php?%ADd+allow_url_include%3d1+%ADd+auto_prepend_, POST /api/templates/preview HTTP/2.0, POST /api/fs/exec HTTP/2.0
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 17:43:41
(9 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.42.144.45 (45.144.42.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.42.144.45 (45.144.42.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 13:43:36.489862 2026] [security2:error] [pid 20733:tid 20733] [client 34.42.144.45:42862] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||realjasonchance.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "realjasonchance.com"] [uri "/z9x8c7v6b5-debug-trigger-realjasonchance.com"] [unique_id "ar_tSIjONHoDeF-pOS5u3AAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 14:46:28
(12 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.42.144.45 (45.144.42.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.42.144.45 (45.144.42.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 10:46:23.799086 2026] [security2:error] [pid 332:tid 332] [client 34.42.144.45:55646] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.rememberingemily.pswebsite.com|F|2"] [data ".rememberingemily.pswebsite.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.rememberingemily.pswebsite.com"] [uri "/z9x8c7v6b5-debug-trigger-www.rememberingemily.pswebsite.com"] [unique_id "ar_Dv7kcXsO3XPsm3aaMWgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 12:51:58
(13 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.42.144.45 (45.144.42.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.42.144.45 (45.144.42.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 08:51:54.712089 2026] [security2:error] [pid 819051:tid 819051] [client 34.42.144.45:54102] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||raynernet.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "raynernet.com"] [uri "/z9x8c7v6b5-debug-trigger-raynernet.com"] [unique_id "ar-o6uYjk9zUAPMGUy-NRgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 12:23:49
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.42.144.45 (45.144.42.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.42.144.45 (45.144.42.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 08:23:42.880653 2026] [security2:error] [pid 8015:tid 8074] [client 34.42.144.45:44906] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.raxelon.com"] [uri "/.env.dev"] [unique_id "ar-iTsBybKqkO8bjgvKpcAAAAJA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-02 10:41:29
(16 hours ago)
34.42.144.45 - - [02/Oct/2026:05:41:26 -0500] "GET /.env.development?raw HTTP/1.1" 301 281 "-" "Mozi ...
show more
34.42.144.45 - - [02/Oct/2026:05:41:26 -0500] "GET /.env.development?raw HTTP/1.1" 301 281 "-" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)" 172.69.58.225
34.42.144.45 - - [02/Oct/2026:05:41:26 -0500] "GET /.env.local?.svg?.wasm?init HTTP/1.1" 301 287 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)" 172.70.127.217
34.42.144.45 - - [02/Oct/2026:05:41:27 -0500] "GET /.env.dev HTTP/1.1" 301 269 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)" 172.70.126.95
34.42.144.45 - - [02/Oct/2026:05:41:27 -0500] "GET /.env.local HTTP/1.1" 301 271 "-" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)" 108.162.216.196
34.42.144.45 - - [02/Oct/2026:05:41:27 -0500] "GET /.env.example HTTP/1.1" 301 273 "-" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)" 172.70.179.42
34.42.144.45 - - [02/Oct/2026:05:41:27 -0500] "GET /.env.bak HTTP/1.1" 301 269 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)" 104.22.62.154
34.42
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 09:53:56
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.42.144.45 (45.144.42.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.42.144.45 (45.144.42.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 05:53:49.059262 2026] [security2:error] [pid 6048:tid 6048] [client 34.42.144.45:51324] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.readyremotely.com"] [uri "/static../.env"] [unique_id "ar9_LS91zRKzrzUi9GaKlwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-02 09:33:04
(17 hours ago)
34.42.144.45 - - [02/Oct/2026:11:32:52 +0200] "GET /.well-known/jwks.json HTTP/2.0" 403 272 "-" "Moz ...
show more
34.42.144.45 - - [02/Oct/2026:11:32:52 +0200] "GET /.well-known/jwks.json HTTP/2.0" 403 272 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0;
show less
Web Spam
Blog Spam
Brute-Force
Web App Attack
๐ณ๐ฑ
Savvii
2026-10-02 09:09:48
(17 hours ago)
33 attempts against mh_ha-misbehave-ban on boron
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-02 08:29:56
(18 hours ago)
[mx01aln] Web exploit scanning: 2 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[mx01aln] Web exploit scanning: 2 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.42.144.45 - - [02/Oct/2026:10:29:40 +0200] "GET /.env.development HTTP/2.0" 404 2004 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)"
34.42.144.45 - - [02/Oct/2026:10:29:40 +0200] "GET /.env.test HTTP/2.0" 404 2004 "-" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/)"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 08:24:10
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.42.144.45 (45.144.42.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.42.144.45 (45.144.42.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 04:24:02.205443 2026] [security2:error] [pid 986:tid 986] [client 34.42.144.45:50460] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.321q.com"] [uri "/assets../.env"] [unique_id "ar9qImNQQD-uJQh2u9VNBQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-02 07:54:34
(18 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking