๐ฌ๐ง
consul.to
2026-09-09 12:00:24
(1 week ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-09 09:26:45
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 34.66.162.121 (121.162.66.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.66.162.121 (121.162.66.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 05:26:37.765397 2026] [security2:error] [pid 21085:tid 21085] [client 34.66.162.121:42620] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ftp.coconut-homes.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ftp.coconut-homes.com"] [uri "/database.sql"] [unique_id "aqEmTYjpJepllqPlF_yecgAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
MyGlobalFlowers
2026-09-09 05:11:15
(2 weeks ago)
Multiple WAF Violations
Web App Attack
๐ฌ๐ง
consul.to
2026-09-08 09:20:35
(2 weeks ago)
Web attack/malicious scanning detected
Web App Attack
๐ฉ๐ช
mondor.ro
2026-09-07 21:32:56
(2 weeks ago)
Cluster member 148.251.176.225 (DE/Germany/antares.webyouridea.ro) said, DENY 34.66.162.121, Reason: ...
show more
Cluster member 148.251.176.225 (DE/Germany/antares.webyouridea.ro) said, DENY 34.66.162.121, Reason:[(mod_security) mod_security (id:210730) triggered by 34.66.162.121 (US/United States/121.162.66.34.bc.googleusercontent.com): 3 in the last 3600 secs]; Ports: *; Direction: inout; Trigger: LF_CLUSTER; Logs:
show less
Port Scan
๐ณ๐ฑ
BlueWire Hosting
2026-09-07 08:47:28
(2 weeks ago)
Probing websites for vulnerabilities
Web App Attack
SQL Injection
๐ณ๐ฑ
Brict IT
2026-09-06 03:17:35
(2 weeks ago)
[Sun Sep 06 05:17:35.386514 2026] [authz_core:error] [pid 3233365:tid 3233418] [client 34.66.162.121 ...
show more
[Sun Sep 06 05:17:35.386514 2026] [authz_core:error] [pid 3233365:tid 3233418] [client 34.66.162.121:0] AH01630: client denied by server configuration: /var/www/vhosts/brict.it/httpdocs/.profile, referer: https://brict-it.nl/.profile
show less
DDoS Attack
FTP Brute-Force
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-06 03:00:47
(2 weeks ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-05 23:27:16
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.66.162.121 (121.162.66.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.66.162.121 (121.162.66.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:27:10.831338 2026] [security2:error] [pid 24781:tid 24781] [client 34.66.162.121:52666] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.page-wide.com"] [uri "/.htaccess"] [unique_id "apylTsBr8mJs1Mg9tSeI0gAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-05 21:34:27
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 34.66.162.121 (121.162.66.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.66.162.121 (121.162.66.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 17:34:19.376304 2026] [security2:error] [pid 28644:tid 28644] [client 34.66.162.121:41064] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bergopro.co.uk|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bergopro.co.uk"] [uri "/db.sql"] [unique_id "apyK2_nyWVE6gb5R9C-fhAAAADc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-05 21:13:13
(2 weeks ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐บ๐ธ
revslowmo
2026-09-05 19:01:31
(2 weeks ago)
Bot attempt ssh bruteforce
Brute-Force
SSH
Anonymous
2026-09-03 19:50:53
(2 weeks ago)
34.66.162.121 - visio.sliver85.eu - [03/Sep/2026:21:50:52 +0200] "GET /src/settings.json HTTP/1.1" 4 ...
show more
34.66.162.121 - visio.sliver85.eu - [03/Sep/2026:21:50:52 +0200] "GET /src/settings.json HTTP/1.1" 444 "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36"
34.66.162.121 - visio.sliver85.eu - [03/Sep/2026:21:50:52 +0200] "GET /src/sendgrid.py HTTP/1.1" 444 "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36"
34.66.162.121 - visio.sliver85.eu - [03/Sep/2026:21:50:52 +0200] "GET /src/settings.py HTTP/1.1" 444 "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36"
34.66.162.121 - visio.sliver85.eu - [03/Sep/2026:21:50:52 +0200] "GET /.ssh/authorized_keys HTTP/1.1" 444 "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36"
34.66.162.121 - visio.sliver85.eu - [03/Sep/2026:21:50:52 +0200] "GET /storage/logs/laravel.log HTTP/1.1" 444 "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/
...
show less
Brute-Force
Web App Attack