Anonymous
2026-10-05 17:20:03
(16 hours ago)
| Common web attack.
Web App Attack
Hacking
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-10-05 13:20:38
(20 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.68.61.227 (227.61.68.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.68.61.227 (227.61.68.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 09:20:32.359231 2026] [security2:error] [pid 25204:tid 25204] [client 34.68.61.227:46294] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||_dc-mx.fa6adf43a6d6.betiqos.com|F|2"] [data ".fa6adf43a6d6.betiqos.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "_dc-mx.fa6adf43a6d6.betiqos.com"] [uri "/z9x8c7v6b5-debug-trigger-_dc-mx.fa6adf43a6d6.betiqos.com"] [unique_id "asOkIO7aju2rz2vmv2KhFQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 12:59:06
(21 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.68.61.227 (227.61.68.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.68.61.227 (227.61.68.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 08:59:01.946451 2026] [security2:error] [pid 17968:tid 17968] [client 34.68.61.227:56512] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||waggonerfinancial.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "waggonerfinancial.com"] [uri "/z9x8c7v6b5-debug-trigger-waggonerfinancial.com"] [unique_id "asOfFfIXP9JqAks5J4W-iAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
tmiland
2026-10-05 12:37:18
(21 hours ago)
(nginx_444) Nginx 444 34.68.61.227 (US/United States/227.61.68.34.bc.googleusercontent.com): 5 in th ...
show more
(nginx_444) Nginx 444 34.68.61.227 (US/United States/227.61.68.34.bc.googleusercontent.com): 5 in the last 3600 secs; IP: 34.68.61.227; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 2026/10/05 14:37:11 [error] 4177439#4177439: *399210 open() "/home/tmiland/public_html/dist/manifest.json" failed (2: No such file or directory), client: 34.68.61.227, server: *.*, request: "GET /dist/manifest.json HTTP/1.1", host: "*.*" 34.68.61.227 - - [05/Oct/2026:14:37:13 +0200] "GET /.ssh/id_ed25519 HTTP/1.1" 444 0 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )" 34.68.61.227 - - [05/Oct/2026:14:37:13 +0200] "GET /.npmrc HTTP/1.1" 444 0 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.4; +https://openai.com/gptbot" 34.68.61.227 - - [05/Oct/2026:14:37:13 +0200] "GET /.npmrc HTTP/1.1" 444 0 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.4; +https://openai.com/gptbot" 34.68.61.227 - - [05/Oct/20
show less
Brute-Force
๐ฎ๐น
mgarofano80
2026-10-05 12:28:21
(21 hours ago)
Brute-Force
Web App Attack
๐บ๐ธ
nasset
2026-10-05 11:39:34
(22 hours ago)
34.68.61.227 - - [05/Oct/2026:04:39:33 -0700] "GET /.env.development?raw HTTP/1.1" 403 584 "-" "Mozi ...
show more
34.68.61.227 - - [05/Oct/2026:04:39:33 -0700] "GET /.env.development?raw HTTP/1.1" 403 584 "-" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)" TLSv1.3 TLS_AES_256_GCM_SHA384
34.68.61.227 - - [05/Oct/2026:04:39:33 -0700] "GET /.env.production?raw HTTP/1.1" 403 584 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)" TLSv1.3 TLS_AES_256_GCM_SHA384
34.68.61.227 - - [05/Oct/2026:04:39:33 -0700] "GET /.env.local?.svg?.wasm?init HTTP/1.1" 403 584 "-" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" TLSv1.3 TLS_AES_256_GCM_SHA384
34.68.61.227 - - [05/Oct/2026:04:39:33 -0700] "GET /.env?.svg?.wasm?init HTTP/1.1" 403 584 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)" TLSv1.3 TLS_AES_256_GCM_SHA384
34.68.61.227 - - [05/Oct/2026:04:39:33 -0700] "GET /.env.development?import&raw HTTP/1.1" 403 584 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 11:33:12
(22 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.68.61.227 (227.61.68.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.68.61.227 (227.61.68.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 07:33:07.743235 2026] [security2:error] [pid 19881:tid 20029] [client 34.68.61.227:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||raytbrown.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "raytbrown.com"] [uri "/z9x8c7v6b5-debug-trigger-raytbrown.com"] [unique_id "asOK8_9N-ckBJ1HJW2VuqQAAARc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Baking333
2026-10-05 10:59:51
(23 hours ago)
[redacted] 34.68.61.227 - - [05/Oct/2026:11:59:49 +0100] "GET /@fs/src/.env?raw?? HTTP/2.0" 301 83 " ...
show more
[redacted] 34.68.61.227 - - [05/Oct/2026:11:59:49 +0100] "GET /@fs/src/.env?raw?? HTTP/2.0" 301 83 "-" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://[redacted]/)" [redacted] 34.68.61.227 - - [05/Oct/2026:11:59:49 +0100] "GET /@fs/../.env?raw?? HTTP/2.0" 301 56 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://[redacted]/)"
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
paissangroup
2026-10-05 10:51:49
(23 hours ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
on-com
2026-10-05 10:41:38
(23 hours ago)
URL scan
Brute-Force
Web App Attack
๐ฉ๐ช
maxpower
2026-10-05 10:40:30
(23 hours ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.68.61.227 (US/United States/227.61.68 ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.68.61.227 (US/United States/227.61.68.34.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.68.61.227 - - [05/Oct/2026:12:40:27 +0200] "GET /.ssh/id_ed25519 HTTP/2.0" 200 4813 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)" "34.68.61.227" host=olscitaly.com
show less
Port Scan
๐ฌ๐ง
oja
2026-10-05 10:39:19
(23 hours ago)
Aggressive web scanner
Web App Attack
๐ต๐ฑ
Niko's Stuff
2026-10-05 10:27:00
(23 hours ago)
Triggered crowdsecurity/http-probing. More information at: https://app.crowdsec.net/cti/34.68.61.227
Web App Attack
Hacking
Anonymous
2026-10-05 09:45:10
(1 day ago)
IP banned by Fail2Ban in jail nginx-abusive-ips
Web App Attack
Brute-Force
Bad Web Bot
๐บ๐ธ
WizardsToolkit
2026-10-05 09:34:33
(1 day ago)
tried to access forbidden files; attempted to access /@fs/app/.env?raw??
Web App Attack