๐ณ๐ฑ
Alt255
2026-09-16 04:51:40
(8 minutes ago)
[cb-04al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail ngin ...
show more
[cb-04al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail nginx-404. Example: 34.55.48.191 - - [16/Sep/2026:06:51:31 +0200] "GET /signin HTTP/1.0" 404 3595 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36"
34.55.48.191 - - [16/Sep/2026:06:51:31 +0200] "GET /auth HTTP/1.0" 404 3595 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36"
34.55.48.191 - - [16/Sep/2026:06:51:31 +0200] "GET /login HTTP/1.0" 404 3595 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36"
34.55.48.191 - - [16/Sep/2026:06:51:31 +0200] "GET /sign-in HTTP/1.0" 404 3595 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36"
34.55.48.191 - - [
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 04:42:42
(17 minutes ago)
(mod_security) mod_security (id:210730) triggered by 34.55.48.191 (191.48.55.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.55.48.191 (191.48.55.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 00:42:36.186606 2026] [security2:error] [pid 22758:tid 22758] [client 34.55.48.191:57100] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||hierrosbernal.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "hierrosbernal.com"] [uri "/z9x8c7v6b5-debug-trigger-hierrosbernal.com"] [unique_id "aqoePEPWyzwu6KN2YiUscAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
taivas.nl
2026-09-16 04:34:29
(25 minutes ago)
Many_bad_calls
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 04:14:26
(45 minutes ago)
(mod_security) mod_security (id:210730) triggered by 34.55.48.191 (191.48.55.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.55.48.191 (191.48.55.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 00:14:20.089823 2026] [security2:error] [pid 17519:tid 17519] [client 34.55.48.191:59306] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||hickorygrovecottages.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "hickorygrovecottages.com"] [uri "/z9x8c7v6b5-debug-trigger-hickorygrovecottages.com"] [unique_id "aqoXnA_P2mKk86op68P6IQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
hghosting
2026-09-16 02:56:28
(2 hours ago)
CrowdSec auto-report: crowdsecurity/http-path-traversal-probing โ 4 events
Brute-Force
SSH
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-16 02:33:55
(2 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/grafana-cve-2021-43798
Web App Attack
Hacking
๐บ๐ธ
Blue Pumpkin
2026-09-16 02:00:07
(2 hours ago)
34.55.48.191 - - [16/Sep/2026:02:00:06 +0000] "GET /firebase-config.json HTTP/1.1" 302 603 "-" "Mozi ...
show more
34.55.48.191 - - [16/Sep/2026:02:00:06 +0000] "GET /firebase-config.json HTTP/1.1" 302 603 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
...
show less
Brute-Force
๐ท๐ด
clauss
2026-09-16 01:54:30
(3 hours ago)
34.55.48.191 - - [16/Sep/2026:04:54:23 +0300] "GET /config.json HTTP/2.0" 404 22055 "-" "Mozilla/5.0 ...
show more
34.55.48.191 - - [16/Sep/2026:04:54:23 +0300] "GET /config.json HTTP/2.0" 404 22055 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)"
34.55.48.191 - - [16/Sep/2026:04:54:29 +0300] "GET /_ignition/health-check HTTP/2.0" 404 22055 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)"
...
show less
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-16 01:19:03
(3 hours ago)
[ti-07al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apac ...
show more
[ti-07al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apache-404. Example: 34.55.48.191 - - [16/Sep/2026:03:18:55 +0200] "GET /.gitlab-ci.yml HTTP/1.1" 404 2050 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot)"
34.55.48.191 - - [16/Sep/2026:03:18:55 +0200] "GET /.gitconfig HTTP/1.1" 404 2050 "-" "Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)"
34.55.48.191 - - [16/Sep/2026:03:18:55 +0200] "GET /.svn/entries HTTP/1.1" 404 2050 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)"
34.55.48.191 - - [16/Sep/2026:03:18:55 +0200] "GET /.git-credentials HTTP/1.1" 404 7386 "-" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)"
34.55.48.191 - - [16/S
...
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-16 01:09:10
(3 hours ago)
Excessive multi-domain requests
Brute-Force
๐ซ๐ท
โจ
2026-09-16 00:58:16
(4 hours ago)
Domain : hestonlee.com
Rule : hack
2026-09-16 00:56:28 ***hidden-privacy*** GET /.env.bak - 443 - 34 ...
show more
Domain : hestonlee.com
Rule : hack
2026-09-16 00:56:28 ***hidden-privacy*** GET /.env.bak - 443 - 34.55.48.191 HTTP/2 Mozilla/5.0 (compatible; PanguBot/1.0; https://www.huaweicloud.com/) - hestonlee.com 404 0 2 1549 389 96 - -
show less
Hacking
SQL Injection
Brute-Force
๐ฉ๐ช
Philister11
2026-09-16 00:52:51
(4 hours ago)
CrowdSec: crowdsecurity/grafana-cve-2021-43798 (US/AS396982)
Web App Attack
Hacking
๐ฎ๐ณ
evicky2002
2026-09-16 00:02:04
(4 hours ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
Anonymous
2026-09-15 23:14:16
(5 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐ซ๐ท
david.houstin
2026-09-15 23:08:52
(5 hours ago)
34.55.48.191 - - [16/Sep/2026:01:08:49 +0200] "GET /.git/HEAD HTTP/2.0" 404 264 "-" "Mozilla/5.0 (co ...
show more
34.55.48.191 - - [16/Sep/2026:01:08:49 +0200] "GET /.git/HEAD HTTP/2.0" 404 264 "-" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)"
34.55.48.191 - - [16/Sep/2026:01:08:49 +0200] "GET /.git/config HTTP/2.0" 404 264 "-" "Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)"
34.55.48.191 - - [16/Sep/2026:01:08:49 +0200] "GET /config/env/aws_credentials.env HTTP/2.0" 404 264 "-" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/)"
34.55.48.191 - - [16/Sep/2026:01:08:49 +0200] "GET /.aws/credentials HTTP/2.0" 404 264 "-" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)"
34.55.48.191 - - [16/Sep/2026:01:08:49 +0200] "GET /.aws/config HTTP/2.0" 404 264 "-" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)"
34.55.48.191 - - [16/Sep/2026:01:08:49 +0200] "GET /.env HTTP/2.0" 404 264 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)"
...
show less
Web App Attack
Bad Web Bot