๐ณ๐ฑ
homeshowdomain.nl
2026-06-13 22:03:07
(1 day ago)
Auto-ban: >3000 req/min op 2026-06-13
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-13 15:56:37
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.47.123.55 (55.123.47.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.47.123.55 (55.123.47.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 11:56:32.076072 2026] [security2:error] [pid 19139:tid 19139] [client 34.47.123.55:53880] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.manosentuayuda.imerka.com.mx|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.manosentuayuda.imerka.com.mx"] [uri "/.config/gcloud/credentials.db"] [unique_id "ai19sN-LPDXpkRGWKN8FEQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฟ
Countryman
2026-06-13 15:43:53
(1 day ago)
repeated unauthorized connection attempts, host sweep, port scan
Port Scan
๐ณ๐ฑ
e.fierstra
2026-06-13 15:38:32
(1 day ago)
Apache-badbot jail block
Bad Web Bot
๐ซ๐ฎ
inlink.ltd
2026-06-13 13:39:26
(1 day ago)
dot file probe
Web App Attack
๐ฉ๐ช
LRob.fr
2026-06-13 12:30:03
(1 day ago)
Repeated 404 errors, blocked by Fail2ban in custom-404 jail
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-13 12:26:30
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.47.123.55 (55.123.47.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.47.123.55 (55.123.47.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 08:26:26.061403 2026] [security2:error] [pid 23786:tid 23786] [client 34.47.123.55:36844] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||visitcampbellford.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "visitcampbellford.com"] [uri "/.config/gcloud/credentials.db"] [unique_id "ai1McmX2aq5UxAg22lIjowAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-06-13 12:18:28
(1 day ago)
Excessive 404/403 errors
Brute-Force
๐ท๐ด
iulianh
2026-06-13 10:06:11
(2 days ago)
*
Brute-Force
SSH
๐ง๐ช
cmbplf
2026-06-13 09:41:09
(2 days ago)
128 requests with url.path *config.json
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-13 08:41:20
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.47.123.55 (55.123.47.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.47.123.55 (55.123.47.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 04:41:13.299863 2026] [security2:error] [pid 4621:tid 4621] [client 34.47.123.55:59038] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||varalla.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "varalla.com"] [uri "/.config/gcloud/credentials.db"] [unique_id "ai0XqbmHL5Tzr5kjqYpR5AAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
updown.io
2026-06-13 07:59:42
(2 days ago)
{"level":"info","ts":1781337581.1912673,"logger":"http.log.access.log1","msg":"handled request","req ...
show more
{"level":"info","ts":1781337581.1912673,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.47.123.55","remote_port":"35990","client_ip":"34.47.123.55","proto":"HTTP/1.1","method":"GET","host":"up.dfctaiwan.org","uri":"/firebase-adminsdk.json","headers":{"User-Agent":["Mozilla/5.0 (Linux; Android 8.0.0; d-02K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.105 Safari/537.36"],"Accept-Charset":["utf-8"],"Accept-Encoding":["gzip"],"Connection":["close"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"","server_name":"up.dfctaiwan.org","ech":false}},"bytes_read":0,"user_id":"","duration":0.000731727,"size":0,"status":429,"resp_headers":{"Server":["Caddy"],"Alt-Svc":["h3=\":443\"; ma=2592000"],"Retry-After":["1"]}}
{"level":"info","ts":1781337581.1976871,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.47.123.55","remote_port":"36020","client_ip":"34.47.123.55","proto":"HTTP/1.1","method":"GET","ho
...
show less
DDoS Attack
Web App Attack
๐ฎ๐น
VHosting
2026-06-13 07:35:04
(2 days ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-13 07:00:30
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.47.123.55 (55.123.47.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.47.123.55 (55.123.47.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 03:00:25.834779 2026] [security2:error] [pid 15024:tid 15063] [client 34.47.123.55:40990] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.markhoran.pictures|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.markhoran.pictures"] [uri "/backup.sql"] [unique_id "ai0ACZ1TrMGSad9qiV5ZFQAAAEU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-13 04:10:53
(2 days ago)
Multiple web server 400 error codes from same source ip
Web App Attack