๐ฉ๐ช
bazter.pro
2026-10-01 07:26:55
(1 hour ago)
Fail2Ban: plesk-bot-aggressive - 15 failures
Port Scan
Bad Web Bot
Web App Attack
๐ซ๐ท
phoenix1jl96
2026-10-01 06:29:08
(2 hours ago)
2026/10/01 08:29:07 [error] 3302796#3302796: *397802 open() "/home/user-data/www/default/cgi-bin/php ...
show more
2026/10/01 08:29:07 [error] 3302796#3302796: *397802 open() "/home/user-data/www/default/cgi-bin/php-cgi.exe" failed (2: No such file or directory), client: 34.6.190.237, server: autodiscover.aqteeve.com, request: "POST /cgi-bin/php-cgi.exe?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input HTTP/2.0", host: "autodiscover.aqteeve.com"
2026/10/01 08:29:07 [error] 3302796#3302796: *397802 open() "/home/user-data/www/default/cgi-bin/php" failed (2: No such file or directory), client: 34.6.190.237, server: autodiscover.aqteeve.com, request: "POST /cgi-bin/php?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input HTTP/2.0", host: "autodiscover.aqteeve.com"
...
show less
DNS Compromise
DNS Poisoning
DDoS Attack
Ping of Death
Web Spam
Email Spam
Blog Spam
Port Scan
Hacking
Brute-Force
Bad Web Bot
SSH
Web App Attack
๐ง๐ช
cmbplf
2026-10-01 04:39:05
(3 hours ago)
120 requests with url.path */@fs/*
Brute-Force
Bad Web Bot
๐ฉ๐ช
maxpower
2026-10-01 02:54:06
(5 hours ago)
(junkbot) REGOLA 8 - Junk Bot Blocked 34.6.190.237 (237.190.6.34.bc.googleusercontent.com): 1 in the ...
show more
(junkbot) REGOLA 8 - Junk Bot Blocked 34.6.190.237 (237.190.6.34.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.6.190.237 - - [01/Oct/2026:04:54:02 +0200] "GET /api/v2/config HTTP/2.0" 200 12023 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)" "-" host=accademiam.com
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-10-01 02:24:36
(6 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.6.190.237 (237.190.6.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.6.190.237 (237.190.6.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 22:24:31.099618 2026] [security2:error] [pid 20863:tid 20863] [client 34.6.190.237:60942] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.ardecymusic.com|F|2"] [data ".ardecymusic.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.ardecymusic.com"] [uri "/z9x8c7v6b5-debug-trigger-www.ardecymusic.com"] [unique_id "ar3EX2ZGTupUU0nZNAsb9AAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
factor1
2026-10-01 00:54:01
(7 hours ago)
CrowdSec at atlas Reports Abuse
Web App Attack
๐บ๐ธ
1gz
2026-10-01 00:06:21
(8 hours ago)
Triggered Cloudflare WAF (firewallCustom) from NL.
Action taken: CHALLENGE
Protocol: HTTP/2 (POST me ...
show more
Triggered Cloudflare WAF (firewallCustom) from NL.
Action taken: CHALLENGE
Protocol: HTTP/2 (POST method)
Endpoint: /feast/read-document
UA: Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฉ๐ช
Bedios GmbH
2026-09-30 22:55:29
(9 hours ago)
Keyfile theft attempt
Hacking
๐จ๐ญ
dalslab ltd
2026-09-30 20:08:05
(12 hours ago)
34.6.190.237 - - [30/Sep/2026:22:08:05 +0200] "POST / HTTP/1.1" 405 154 "-" "Mozilla/5.0 (compatible ...
show more
34.6.190.237 - - [30/Sep/2026:22:08:05 +0200] "POST / HTTP/1.1" 405 154 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)"
34.6.190.237 - - [30/Sep/2026:22:08:05 +0200] "POST /graphql HTTP/1.1" 405 556 "http://remote.dalslab.com" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
34.6.190.237 - - [30/Sep/2026:22:08:05 +0200] "POST /api/graphql HTTP/1.1" 405 556 "http://remote.dalslab.com" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
34.6.190.237 - - [30/Sep/2026:22:08:05 +0200] "POST /login HTTP/1.1" 405 154 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1)"
34.6.190.237 - - [30/Sep/2026:22:08:05 +0200] "POST /v1/graphql HTTP/1.1" 405 556 "http://remote.dalslab.com" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML
...
show less
Web Spam
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-30 18:39:29
(13 hours ago)
Aggressive web scan
Web App Attack
๐ฉ๐ช
london2038.com
2026-09-30 18:24:57
(14 hours ago)
Malformed or malicious web request
34.6.190.237 - - [30/Sep/2026:20:24:54 +0200] "POST /lib/terminal ...
show more
Malformed or malicious web request
34.6.190.237 - - [30/Sep/2026:20:24:54 +0200] "POST /lib/terminal-xhr.php HTTP/2.0" 404 40040 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)"
show less
Hacking
Web App Attack
๐ฉ๐ช
TheDjRider
2026-09-30 17:46:49
(14 hours ago)
CrowdSec detected Web application reconnaissance. Scenario: crowdsecurity/http-probing. Automatic ba ...
show more
CrowdSec detected Web application reconnaissance. Scenario: crowdsecurity/http-probing. Automatic ban triggered. Detection time (UTC): 2026-09-30T17:46:43.490519651Z. Context: http_status=404
show less
Web App Attack
๐บ๐ธ
proactive-noc
2026-09-30 17:17:11
(15 hours ago)
Web application abuse detected 7 times recently; honeypot-j.
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 16:00:20
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.6.190.237 (237.190.6.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.6.190.237 (237.190.6.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 12:00:15.868576 2026] [security2:error] [pid 15777:tid 15892] [client 34.6.190.237:41228] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.allstartaxidermy.com"] [uri "/wp-config.php.bak"] [unique_id "ar0yD-14HsboWLZrESliyQAAAlY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 15:34:27
(17 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.6.190.237 (237.190.6.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.6.190.237 (237.190.6.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 11:34:22.175253 2026] [security2:error] [pid 2388:tid 2484] [client 34.6.190.237:40896] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.geekshop.com|F|2"] [data ".geekshop.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.geekshop.com"] [uri "/z9x8c7v6b5-debug-trigger-www.geekshop.com"] [unique_id "ar0r_jfABwykuiz0zp9DtwAAAQ0"]
show less
Brute-Force
Bad Web Bot
Web App Attack