Anonymous
2026-10-11 05:43:00
(6 minutes ago)
(mod_security) mod_security triggered on hostname [redacted] 34.6.1.120 (120.1.6.34.bc.googleusercon ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.6.1.120 (120.1.6.34.bc.googleusercontent.com)
show less
SQL Injection
๐จ๐ญ
dalslab ltd
2026-10-11 05:14:03
(35 minutes ago)
2026/10/11 07:14:03 [error] 336#336: *568520 limiting requests, excess: 200.030 by zone "rl_per_ip", ...
show more
2026/10/11 07:14:03 [error] 336#336: *568520 limiting requests, excess: 200.030 by zone "rl_per_ip", client: 34.6.1.120, server: auth.dalslab.com, request: "GET /.s3cfg HTTP/2.0", host: "auth.dalslab.com"
2026/10/11 07:14:03 [error] 336#336: *568520 limiting requests, excess: 200.800 by zone "rl_per_ip", client: 34.6.1.120, server: auth.dalslab.com, request: "GET /.boto HTTP/2.0", host: "auth.dalslab.com"
2026/10/11 07:14:03 [error] 336#336: *568520 limiting requests, excess: 200.800 by zone "rl_per_ip", client: 34.6.1.120, server: auth.dalslab.com, request: "GET /.docker/config.json HTTP/2.0", host: "auth.dalslab.com"
2026/10/11 07:14:03 [error] 336#336: *568520 limiting requests, excess: 200.800 by zone "rl_per_ip", client: 34.6.1.120, server: auth.dalslab.com, request: "GET /serverless.yaml HTTP/2.0", host: "auth.dalslab.com"
2026/10/11 07:14:03 [error] 336#336: *568520 limiting requests, excess: 200.800 by zone "rl_per_ip", client: 34.6.1.120, server: auth.dalslab.com, request: "GE
...
show less
Brute-Force
SSH
๐จ๐ญ
๐จ๐ญ Hosting
2026-10-11 05:10:16
(39 minutes ago)
Automated WAF report: 400-500 blocked requests from this IP detected by our WAF.
Bad Web Bot
Web App Attack
๐ฉ๐ช
Skyrider
2026-10-11 03:06:15
(2 hours ago)
crowdsecurity/http-probing
Web App Attack
๐ซ๐ท
Quarks Solutions
2026-10-11 02:16:23
(3 hours ago)
crowdsecurity/appsec-vpatch
Web App Attack
๐ฌ๐ง
andypiper
2026-10-11 01:01:09
(4 hours ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-11 00:54:18
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.6.1.120 (120.1.6.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210730) triggered by 34.6.1.120 (120.1.6.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 20:54:11.904661 2026] [security2:error] [pid 15893:tid 15893] [client 34.6.1.120:45774] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||tortoisehosting.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "tortoisehosting.com"] [uri "/z9x8c7v6b5-debug-trigger-tortoisehosting.com"] [unique_id "asreM9k2J4cNJ_gu5px2xAAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
tecnoacquisti.com
2026-10-11 00:46:41
(5 hours ago)
PrestaShop Security Module: suspicious probe path detected (/.env)
Web App Attack
๐บ๐ธ
CDO
2026-10-11 00:40:17
(5 hours ago)
URL Injection attempt detected. Automated web attack.
Hacking
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-10-11 00:40:02
(5 hours ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
๐ฉ๐ช
Philister11
2026-10-11 00:15:08
(5 hours ago)
CrowdSec: crowdsecurity/http-bad-user-agent (NL/AS396982)
Bad Web Bot
Web App Attack
Anonymous
2026-10-11 00:09:37
(5 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.6.1.120 (120.1.6.34.bc.googleusercon ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.6.1.120 (120.1.6.34.bc.googleusercontent.com)
show less
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-10-10 23:47:32
(6 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.6.1.120 (120.1.6.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210730) triggered by 34.6.1.120 (120.1.6.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 19:47:28.926404 2026] [security2:error] [pid 23820:tid 23820] [client 34.6.1.120:46506] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||secuencia.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "secuencia.com"] [uri "/z9x8c7v6b5-debug-trigger-secuencia.com"] [unique_id "asrOkBtxbSQgo9LzMhMw3AAAACs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Skyrider
2026-10-10 23:36:55
(6 hours ago)
crowdsecurity/http-path-traversal-probing
Web App Attack
๐บ๐ธ
Lee Daniel
2026-10-10 23:20:40
(6 hours ago)
34.6.1.120 - - [10/Oct/2026:19:20:40 -0400] "GET /.htpasswd HTTP/1.1" 403 377 "-" "Mozilla/5.0 Apple ...
show more
34.6.1.120 - - [10/Oct/2026:19:20:40 -0400] "GET /.htpasswd HTTP/1.1" 403 377 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)"
...
show less
DDoS Attack
Web Spam
Email Spam
Port Scan
Brute-Force
Bad Web Bot
Web App Attack