๐ง๐ท
radardatelecom
2026-10-06 22:27:03
(1 day ago)
Blocked by Radar da Telecom firewall โ abuseipdb
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-10-06 22:02:56
(1 day ago)
20 attempts against mh-misbehave-ban on frost
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 21:58:45
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.47.57.247 (247.57.47.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.47.57.247 (247.57.47.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 17:58:38.557224 2026] [security2:error] [pid 12958:tid 12958] [client 34.47.57.247:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||sistememail.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "sistememail.com"] [uri "/z9x8c7v6b5-debug-trigger-sistememail.com"] [unique_id "asVvDj4FwPbPdqo7_mJn1gAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
yvoictra
2026-10-06 21:49:00
(1 day ago)
Bloqueado automรกticamente por CrowdSec. Escenario: crowdsecurity/http-probing
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 21:41:15
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.47.57.247 (247.57.47.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.47.57.247 (247.57.47.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 17:41:09.506557 2026] [security2:error] [pid 29195:tid 29218] [client 34.47.57.247:38930] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||siraceservices.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "siraceservices.com"] [uri "/z9x8c7v6b5-debug-trigger-siraceservices.com"] [unique_id "asVq9b5jYQTCTvMV05U5jgAAAFU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 21:19:04
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.47.57.247 (247.57.47.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.47.57.247 (247.57.47.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 17:18:59.750087 2026] [security2:error] [pid 1362:tid 1362] [client 34.47.57.247:42978] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||singleslidestrategy.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "singleslidestrategy.com"] [uri "/z9x8c7v6b5-debug-trigger-singleslidestrategy.com"] [unique_id "asVlw4GcSp3XeF1tymhejAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐พ
Rizzy
2026-10-06 20:37:23
(1 day ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 20:28:40
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.47.57.247 (247.57.47.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.47.57.247 (247.57.47.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 16:28:34.451918 2026] [security2:error] [pid 673:tid 673] [client 34.47.57.247:38432] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||simplybrandedllc.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "simplybrandedllc.com"] [uri "/z9x8c7v6b5-debug-trigger-simplybrandedllc.com"] [unique_id "asVZ8v8F3dv4Bd_Dw5KLngAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
danchoivanov
2026-10-06 20:12:47
(1 day ago)
Automated scanner probing /.env on simpleitsrq.com. Auto-blocked by honeypot trap.
Web App Attack
Hacking
๐ฉ๐ช
thesimonmanuel
2026-10-06 20:04:08
(1 day ago)
34.47.57.247 - - [07/Oct/2026:01:34:08 +0530] "GET /.ssh/id_rsa HTTP/2.0" 404 8191 "-" "Mozilla/5.0 ...
show more
34.47.57.247 - - [07/Oct/2026:01:34:08 +0530] "GET /.ssh/id_rsa HTTP/2.0" 404 8191 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)"
show less
Web App Attack
๐ฉ๐ช
Jarda_H
2026-10-06 19:54:51
(1 day ago)
http-probing
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 19:39:50
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.47.57.247 (247.57.47.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.47.57.247 (247.57.47.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 15:39:44.276728 2026] [security2:error] [pid 7537:tid 7537] [client 34.47.57.247:41914] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||simcorr.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "simcorr.com"] [uri "/z9x8c7v6b5-debug-trigger-simcorr.com"] [unique_id "asVOgPGEktRxAYaZVLUN4QAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
masterguru
2026-10-06 19:29:20
(1 day ago)
Inbound Anomaly Score Exceeded (Total Score: 5). Operator GE matched 5 at TX:anomaly_score. (949110- ...
show more
Inbound Anomaly Score Exceeded (Total Score: 5). Operator GE matched 5 at TX:anomaly_score. (949110-122)
show less
Hacking
๐ซ๐ฎ
sibahota
2026-10-06 19:27:21
(1 day ago)
34.47.57.247 - - [06/Oct/2026:19:27:21 +0000] silverworldoman.com "GET /gcp-credentials.json HTTP/1. ...
show more
34.47.57.247 - - [06/Oct/2026:19:27:21 +0000] silverworldoman.com "GET /gcp-credentials.json HTTP/1.1" 404 7215 0.014 "-" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)" 172.17.0.1:3019 404 0.014 "http://silverworldoman.com/gcp-credentials.json"
...
show less
Web App Attack
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-10-06 18:06:02
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.47.57.247 (247.57.47.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.47.57.247 (247.57.47.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 14:05:54.670025 2026] [security2:error] [pid 30845:tid 30845] [client 34.47.57.247:44058] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||sigridsnaturalfoods.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "sigridsnaturalfoods.com"] [uri "/z9x8c7v6b5-debug-trigger-sigridsnaturalfoods.com"] [unique_id "asU4grfJ5df5oVa12EJluwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack