Anonymous
2026-10-11 07:00:04
(3 hours ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection
Anonymous
2026-10-10 22:30:23
(12 hours ago)
malicious scanning tool activity
Web App Attack
π³π±
Alt255
2026-10-10 21:27:20
(13 hours ago)
[ti-30al] Excessive 404 errors (web scanning): 32 suspicious requests detected by fail2ban jail apac ...
show more
[ti-30al] Excessive 404 errors (web scanning): 32 suspicious requests detected by fail2ban jail apache-404. Example: 34.6.82.142 - - [10/Oct/2026:23:27:12 +0200] "GET /mgdi2cnn5qat62yw6x85 HTTP/2.0" 404 2004 "-" "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
34.6.82.142 - - [10/Oct/2026:23:27:12 +0200] "GET /z9x8c7v6b5-debug-trigger-account.sivacanaltours.com HTTP/2.0" 404 2004 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)"
34.6.82.142 - - [10/Oct/2026:23:27:12 +0200] "GET /css../.env HTTP/2.0" 404 2004 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] )"
34.6.82.142 - - [10/Oct/2026:23:27:12 +0200] "GE
...
show less
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-10 20:55:52
(13 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.6.82.142 (142.82.6.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.6.82.142 (142.82.6.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 16:55:45.826600 2026] [security2:error] [pid 29937:tid 29937] [client 34.6.82.142:41836] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||victorvictorloft.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "victorvictorloft.com"] [uri "/z9x8c7v6b5-debug-trigger-victorvictorloft.com"] [unique_id "asqmUcWz86V84DWJQXAcIgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-10 20:16:19
(14 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.6.82.142 (142.82.6.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.6.82.142 (142.82.6.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 16:16:17.610685 2026] [security2:error] [pid 30066:tid 30066] [client 34.6.82.142:47386] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||syscoxlegends.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "syscoxlegends.com"] [uri "/z9x8c7v6b5-debug-trigger-syscoxlegends.com"] [unique_id "asqdES8vbZhT_FatoXgn8wAAAD0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¨π¦
polycoda
2026-10-10 19:57:43
(14 hours ago)
AutoBlock: π― Vulnerability Scanner (Non Decay-Based) - π‘ Port Scan (Non Decay-Based) - β Excessive 4 ...
show more
AutoBlock: π― Vulnerability Scanner (Non Decay-Based) - π‘ Port Scan (Non Decay-Based) - β Excessive 40X Errors (Decay-Based)
show less
Port Scan
Hacking
Bad Web Bot
Web App Attack
π³π±
Savvii
2026-10-10 19:55:48
(14 hours ago)
20 attempts against mh-misbehave-ban on moon
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-10 19:52:46
(14 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.6.82.142 (142.82.6.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.6.82.142 (142.82.6.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 15:52:41.936385 2026] [security2:error] [pid 31217:tid 31217] [client 34.6.82.142:55602] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||skintormint.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "skintormint.com"] [uri "/z9x8c7v6b5-debug-trigger-skintormint.com"] [unique_id "asqXiecoX_RujcU2QLXpiQAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¦πΊ
2000cn.com.au
2026-10-10 19:43:31
(14 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
πΊπΈ
TPI-Abuse
2026-10-10 19:36:27
(14 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.6.82.142 (142.82.6.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.6.82.142 (142.82.6.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 15:36:20.256605 2026] [security2:error] [pid 17309:tid 17309] [client 34.6.82.142:43892] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||sketchnotebook.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "sketchnotebook.com"] [uri "/z9x8c7v6b5-debug-trigger-sketchnotebook.com"] [unique_id "asqTtG9BA5TbjZbiOF9efgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΈπͺ
vaia.cloud
2026-10-10 19:25:03
(15 hours ago)
crowdsecurity/grafana-cve-2021-43798
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-10 19:19:27
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.6.82.142 (142.82.6.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.6.82.142 (142.82.6.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 15:19:19.863523 2026] [security2:error] [pid 25977:tid 25977] [client 34.6.82.142:33498] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sjjcox.com"] [uri "/@fs/app/.env"] [unique_id "asqPt0IT7VI6e6hu2wTtdgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Alt255
2026-10-10 19:05:53
(15 hours ago)
[ti-04al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-04al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.6.82.142 - - [10/Oct/2026:21:05:38 +0200] "GET /userfiles?path=../../../.env HTTP/2.0" 403 17060 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] )"
...
show less
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-10 19:02:08
(15 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.6.82.142 (142.82.6.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.6.82.142 (142.82.6.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 15:02:01.275032 2026] [security2:error] [pid 27538:tid 27538] [client 34.6.82.142:33608] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||sittser.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "sittser.com"] [uri "/z9x8c7v6b5-debug-trigger-sittser.com"] [unique_id "asqLqdc14k4puLDGJ_4HSwAAAC4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
consul.to
2026-10-10 18:49:13
(15 hours ago)
Web attack/malicious scanning detected
Web App Attack