๐ฆ๐บ
2000cn.com.au
2026-09-23 17:33:47
(52 minutes ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-23 17:32:04
(54 minutes ago)
(mod_security) mod_security (id:210730) triggered by 34.62.52.128 (128.52.62.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.62.52.128 (128.52.62.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 13:32:00.223089 2026] [security2:error] [pid 4222:tid 4284] [client 34.62.52.128:48012] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||cwpianolessons.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "cwpianolessons.com"] [uri "/z9x8c7v6b5-debug-trigger-cwpianolessons.com"] [unique_id "arQNEAbAi7Yjiq-MRwby6gAAAcU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-23 16:36:49
(1 hour ago)
Banned by Fail2Ban on server
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 16:31:48
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 34.62.52.128 (128.52.62.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.62.52.128 (128.52.62.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 12:31:41.190509 2026] [security2:error] [pid 29698:tid 29698] [client 34.62.52.128:38086] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||cynthiabaxter.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "cynthiabaxter.com"] [uri "/z9x8c7v6b5-debug-trigger-cynthiabaxter.com"] [unique_id "arP-7QZ86mmEeeF7Mjo-bgAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 16:10:07
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.62.52.128 (128.52.62.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.62.52.128 (128.52.62.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 12:10:03.955973 2026] [security2:error] [pid 3972:tid 3972] [client 34.62.52.128:49846] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||czarcrestwesties.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "czarcrestwesties.com"] [uri "/z9x8c7v6b5-debug-trigger-czarcrestwesties.com"] [unique_id "arP523kncsZFTTAcU2PkNAAAAC8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 15:41:15
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.62.52.128 (128.52.62.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.62.52.128 (128.52.62.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 11:41:10.152472 2026] [security2:error] [pid 5391:tid 5391] [client 34.62.52.128:51632] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||d365geek.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "d365geek.com"] [uri "/z9x8c7v6b5-debug-trigger-d365geek.com"] [unique_id "arPzFu2QjNFM4i3n6ib_wQAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-23 15:29:01
(2 hours ago)
๐ฅ Web application attack detected. Vulnerability scanning and exploitation attempts identified.
Web App Attack
๐ฉ๐ช
TheDjRider
2026-09-23 15:16:25
(3 hours ago)
CrowdSec detected Web application reconnaissance. Scenario: crowdsecurity/http-probing. Automatic ba ...
show more
CrowdSec detected Web application reconnaissance. Scenario: crowdsecurity/http-probing. Automatic ban triggered. Detection time (UTC): 2026-09-23T15:16:05.479872774Z. Context: http_status=404, http_status=403
show less
Web App Attack
๐ฌ๐ง
consul.to
2026-09-23 15:04:29
(3 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐ฉ๐ช
bazter.pro
2026-09-23 15:03:47
(3 hours ago)
Fail2Ban: plesk-bot-aggressive - 15 failures
Port Scan
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 15:00:49
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.62.52.128 (128.52.62.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.62.52.128 (128.52.62.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 11:00:45.674461 2026] [security2:error] [pid 19180:tid 19180] [client 34.62.52.128:40400] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||goatedlottosecrets.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "goatedlottosecrets.com"] [uri "/z9x8c7v6b5-debug-trigger-goatedlottosecrets.com"] [unique_id "arPpnRlN1EhuWx33VOHSuwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 14:42:17
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.62.52.128 (128.52.62.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.62.52.128 (128.52.62.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 10:42:13.492026 2026] [security2:error] [pid 14267:tid 14267] [client 34.62.52.128:33502] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||internet-brochures.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "internet-brochures.com"] [uri "/z9x8c7v6b5-debug-trigger-internet-brochures.com"] [unique_id "arPlRf0jUS7H26Zz7mkX4gAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐ด
clauss
2026-09-23 14:27:53
(3 hours ago)
34.62.52.128 - - [23/Sep/2026:17:27:47 +0300] "GET /rclone.conf HTTP/2.0" 403 146 "-" "Mozilla/5.0 ( ...
show more
34.62.52.128 - - [23/Sep/2026:17:27:47 +0300] "GET /rclone.conf HTTP/2.0" 403 146 "-" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)"
34.62.52.128 - - [23/Sep/2026:17:27:53 +0300] "GET /firebase-adminsdk.json HTTP/2.0" 301 0 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 14:12:10
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.62.52.128 (128.52.62.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.62.52.128 (128.52.62.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 10:12:05.526313 2026] [security2:error] [pid 30359:tid 30359] [client 34.62.52.128:54014] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||menagri.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "menagri.com"] [uri "/z9x8c7v6b5-debug-trigger-menagri.com"] [unique_id "arPeNUs3WUcQlC6BcFI0cAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 13:25:07
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.62.52.128 (128.52.62.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.62.52.128 (128.52.62.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 09:24:58.625716 2026] [security2:error] [pid 29308:tid 29308] [client 34.62.52.128:55508] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "saltcityprint.com"] [uri "/.htpasswd"] [unique_id "arPTKl0u3WJa-J8ctYeHHAAAAC0"]
show less
Brute-Force
Bad Web Bot
Web App Attack