๐บ๐ธ
TPI-Abuse
2026-09-29 20:46:42
(49 minutes ago)
(mod_security) mod_security (id:949110) triggered by 34.42.182.101 (101.182.42.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:949110) triggered by 34.42.182.101 (101.182.42.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 16:46:38.894636 2026] [security2:error] [pid 11237:tid 11237] [client 34.42.182.101:38630] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "i-dataph.com"] [uri "/z9x8c7v6b5-debug-trigger-i-dataph.com"] [unique_id "arwjrsp9MfZWQr_AKtZDrAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
paissangroup
2026-09-29 19:53:38
(1 hour ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 19:35:25
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.42.182.101 (101.182.42.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.42.182.101 (101.182.42.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 15:35:18.100624 2026] [security2:error] [pid 9900:tid 10089] [client 34.42.182.101:59896] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "iheb.org"] [uri "/.env.old"] [unique_id "arwS9nwfBSnFj0BmckuCZAAAAYA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
dot.mg
2026-09-29 19:31:22
(2 hours ago)
Scan of vulnerable files
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-29 19:10:34
(2 hours ago)
[ti-11al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-11al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.42.182.101 - - [29/Sep/2026:21:10:20 +0200] "GET /.env.example HTTP/2.0" 403 395 "-" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-09-29 19:05:36
(2 hours ago)
Scanning/Probing (25)
Request Overload (106)
Brute-Force
Web App Attack
๐ซ๐ฎ
JRID
2026-09-29 18:23:39
(3 hours ago)
Detected by CrowdSec + Suricata IDS: automated attack/scan against web servers.
Brute-Force
Web App Attack
๐ฎ๐น
VHosting
2026-09-29 18:05:03
(3 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ฉ๐ช
Hazzard
2026-09-29 17:44:35
(3 hours ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
๐ณ๐ฑ
Alt255
2026-09-29 17:38:35
(3 hours ago)
[ti-24al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apac ...
show more
[ti-24al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apache-404. Example: 34.42.182.101 - - [29/Sep/2026:19:38:15 +0200] "GET /z9x8c7v6b5-debug-trigger-catalog.ihc-dezorgmakelaar.nl HTTP/2.0" 404 2004 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)"
34.42.182.101 - - [29/Sep/2026:19:38:15 +0200] "GET /vte4abk495vk050sv64f HTTP/2.0" 404 2004 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)"
34.42.182.101 - - [29/Sep/2026:19:38:15 +0200] "POST /graphql HTTP/2.0" 404 2004 "https://catalog.ihc-dezorgmakelaar.nl" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Mobile Safari/537.36"
34.42.182.101 - - [29/Sep/2026:19:38:15 +0200] "GET /settings.json HTTP/2.0" 404 2004 "-" "Mozilla/5.0 (compatible
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-29 17:23:39
(4 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐ซ๐ท
dynamix
2026-09-29 17:18:55
(4 hours ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-09-29 17:15:17
(4 hours ago)
2026/09/29 17:15:15 [error] 2479716#2479716: *443004 [client 34.42.182.101] ModSecurity: Access deni ...
show more
2026/09/29 17:15:15 [error] 2479716#2479716: *443004 [client 34.42.182.101] ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Ge' with parameter `5' against variable `TX:BLOCKING_INBOUND_ANOMALY_SCORE' (Value: `40' ) [file "/usr/local/owasp-modsecurity-crs-4.11.0/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "222"] [id "949110"] [rev ""] [msg "Inbound Anomaly Score Exceeded (Total Score: 40)"] [data ""] [severity "0"] [ver "OWASP_CRS/4.29.0"] [maturity "0"] [accuracy "0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "idealfmgh.com"] [uri "/"] [unique_id "179070211550.900940"] [ref ""], client: 34.42.182.101, server: idealfmgh.com, request: "POST / HTTP/2.0", host: "idealfmgh.com"
2026/09/29 17:15:15 [error] 2479716#2479716: *443004 [client 34.42.182.101] ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Ge' with parameter `5' against variable `TX:BLOCKING_INBOUND_ANOMALY_SCORE' (Value: `5' ) [file "/usr/local/owasp-modsecurity-crs-4.11
...
show less
Brute-Force
๐ฉ๐ช
iNetWorker
2026-09-29 15:04:46
(6 hours ago)
trying to access non-authorized port
Port Scan