🇩🇪
findlab
2026-09-11 05:30:05
(6 hours ago)
Backdrop CMS module - malicious activity detected
Bad Web Bot
Web App Attack
🇩🇪
paissangroup
2026-09-11 05:27:39
(6 hours ago)
Multiple WAF Violations
Web App Attack
🇩🇪
FD-IX
2026-09-11 04:58:14
(6 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 04:48:00
(6 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.57.18.232 (232.18.57.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.57.18.232 (232.18.57.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 00:47:53.505744 2026] [security2:error] [pid 849:tid 849] [client 34.57.18.232:52958] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||hakkawok.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "hakkawok.com"] [uri "/z9x8c7v6b5-debug-trigger-hakkawok.com"] [unique_id "aqOH-Ral7SWtjL0p6KR8aQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Savvii
2026-09-11 04:21:43
(7 hours ago)
20 attempts against mh-misbehave-ban on mars
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-11 04:03:42
(7 hours ago)
Automatically blocked after 12 security events. Observed sensitive configuration-file probes. Source ...
show more
Automatically blocked after 12 security events. Observed sensitive configuration-file probes. Source: Cloudflare security controls.
show less
Hacking
Bad Web Bot
Web App Attack
🇳🇱
Savvii
2026-09-11 03:31:00
(8 hours ago)
20 attempts against mh-misbehave-ban on kiwi
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-11 03:23:53
(8 hours ago)
Excessive multi-domain requests
Brute-Force
🇩🇪
Gwyneth Llewelyn
2026-09-11 03:05:08
(8 hours ago)
2026/09/11 04:05:06 [error] 1267648#1267648: *47525 access forbidden by rule, client: 34.57.18.232, ...
show more
2026/09/11 04:05:06 [error] 1267648#1267648: *47525 access forbidden by rule, client: 34.57.18.232, server: feminina.eu, request: "GET /uploads../.env HTTP/2.0", host: "feminina.eu"
2026/09/11 04:05:06 [error] 1267648#1267648: *47527 access forbidden by rule, client: 34.57.18.232, server: feminina.eu, request: "GET /assets../.env HTTP/2.0", host: "feminina.eu"
2026/09/11 04:05:06 [error] 1267648#1267648: *47528 access forbidden by rule, client: 34.57.18.232, server: feminina.eu, request: "GET /images../.env HTTP/2.0", host: "feminina.eu"
show less
Brute-Force
Web App Attack
🇧🇷
Halux
2026-09-11 03:04:36
(8 hours ago)
34.57.18.232 Probing protected path or service
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 02:47:58
(8 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.57.18.232 (232.18.57.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.57.18.232 (232.18.57.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 22:47:51.936641 2026] [security2:error] [pid 418167:tid 418186] [client 34.57.18.232:53360] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||evolutionaryethics.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "evolutionaryethics.com"] [uri "/rclone.conf"] [unique_id "aqNr1yAdNvd6ISreONnG9QAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
oralunal
2026-09-11 02:31:40
(9 hours ago)
IP banned by Fail2Ban in jail ente-suss ente.com-ssl_log mvfnds
...
Bad Web Bot
Web App Attack
🇬🇧
D3monite
2026-09-11 02:24:26
(9 hours ago)
Attempted Brute Force (APIService)
Brute-Force
🇪🇸
el-brujo
2026-09-11 02:19:57
(9 hours ago)
34.57.18.232 - - [11/Sep/2026:04:19:56 +0200] "GET /build/manifest.json HTTP/2.0" 404 15828 "-" "Moz ...
show more
34.57.18.232 - - [11/Sep/2026:04:19:56 +0200] "GET /build/manifest.json HTTP/2.0" 404 15828 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36 Edg/152.0.0.0"
34.57.18.232 - - [11/Sep/2026:04:19:56 +0200] "GET /rclone.conf HTTP/2.0" 404 15828 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )"
34.57.18.232 - - [11/Sep/2026:04:19:56 +0200] "GET /z9x8c7v6b5-debug-trigger-elhacker.net HTTP/2.0" 404 15828 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)"
34.57.18.232 - - [11/Sep/2026:04:19:56 +0200] "GET /dist/.vite/manifest.json HTTP/2.0" 404 15828 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36 Edg/152.0.0.0"
...
show less
Web App Attack
Hacking
🇩🇪
netclix.gr
2026-09-11 01:34:42
(10 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.57.18.232 (US/United States/232.18.5 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.57.18.232 (US/United States/232.18.57.34.bc.googleusercontent.com): (CF_ENABLE)
show less
SQL Injection