Anonymous
2026-09-24 10:15:08
(17 minutes ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 09:18:11
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 34.7.137.222 (222.137.7.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.7.137.222 (222.137.7.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 05:18:05.380189 2026] [security2:error] [pid 29697:tid 29697] [client 34.7.137.222:44894] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.thelowensteinfamily.com|F|2"] [data ".thelowensteinfamily.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.thelowensteinfamily.com"] [uri "/z9x8c7v6b5-debug-trigger-www.thelowensteinfamily.com"] [unique_id "arTqzXpEjM2jlxmy1-yQTQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Baking333
2026-09-24 08:31:47
(2 hours ago)
[redacted] 34.7.137.222 - - [24/Sep/2026:09:31:45 +0100] "GET /.[redacted] HTTP/2.0" 301 191 "-" "Mo ...
show more
[redacted] 34.7.137.222 - - [24/Sep/2026:09:31:45 +0100] "GET /.[redacted] HTTP/2.0" 301 191 "-" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://[redacted]/search/[redacted])" [redacted] 34.7.137.222 - - [24/Sep/2026:09:31:45 +0100] "GET /.[redacted] HTTP/2.0" 301 192 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://[redacted]/)"
show less
Bad Web Bot
Web App Attack
๐ซ๐ฎ
paissangroup
2026-09-24 08:28:32
(2 hours ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
maxpower
2026-09-24 08:23:12
(2 hours ago)
(PERMBLOCK) 34.7.137.222 (222.137.7.34.bc.googleusercontent.com) has had more than 4 temp blocks in ...
show more
(PERMBLOCK) 34.7.137.222 (222.137.7.34.bc.googleusercontent.com) has had more than 4 temp blocks in the last 86400 secs; Ports: *; Direction: inout; Trigger: LF_PERMBLOCK_COUNT; Logs:
show less
Port Scan
๐ต๐ซ
www.gregorymariani.com
2026-09-24 06:43:11
(3 hours ago)
Web App Attack
๐ฎ๐ณ
evicky2002
2026-09-24 06:00:03
(4 hours ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ง๐ช
taivas.nl
2026-09-24 04:33:14
(5 hours ago)
Many_bad_calls
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 03:40:00
(6 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.7.137.222 (222.137.7.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.7.137.222 (222.137.7.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 23:39:54.610916 2026] [security2:error] [pid 2081:tid 2081] [client 34.7.137.222:34672] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.cs-mall.com|F|2"] [data ".cs-mall.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.cs-mall.com"] [uri "/z9x8c7v6b5-debug-trigger-www.cs-mall.com"] [unique_id "arSbiqkDbhs_px0aCSpJlAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ฌ
mypatricks
2026-09-24 03:23:10
(7 hours ago)
34.7.137.222 | Port: 12562 | DNS: 222.137.7.34.bc.googleusercontent.com 2026-09-24T11:23:08+08:00 Eu ...
show more
34.7.137.222 | Port: 12562 | DNS: 222.137.7.34.bc.googleusercontent.com 2026-09-24T11:23:08+08:00 Europe/Amsterdam | Fake Baiduspider Detected | UA: Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html) HTTP/1.1 443 GET | URL: /hm7g6h0d85umuaodw8x7 | Ref: https://www.xxxxxx/hm7g6h0d85umuaodw8x7 | Country: NL/Netherlands the/+01:00 IP City: Groningen a3feab32ce8c8f37-AMS/Amsterdam, Netherlands 2 hits/1 secs Robots 0
show less
Brute-Force
Web App Attack
Blog Spam
Web Spam
Exploited Host
Anonymous
2026-09-24 03:08:04
(7 hours ago)
malicious scanning tool activity
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 02:52:58
(7 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.7.137.222 (222.137.7.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.7.137.222 (222.137.7.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 22:52:52.752337 2026] [security2:error] [pid 26038:tid 26038] [client 34.7.137.222:41734] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.banis-associates.com|F|2"] [data ".banis-associates.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.banis-associates.com"] [uri "/z9x8c7v6b5-debug-trigger-www.banis-associates.com"] [unique_id "arSQhBdgiYeOfXupehlzcAAAADA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2026-09-24 01:56:03
(8 hours ago)
(modsecurity) srv101 ModSecurity 34.7.137.222 (NL/The Netherlands/222.137.7.34.bc.googleusercontent. ...
show more
(modsecurity) srv101 ModSecurity 34.7.137.222 (NL/The Netherlands/222.137.7.34.bc.googleusercontent.com): 30 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐ฉ๐ช
Marc
2026-09-24 01:04:14
(9 hours ago)
34.7.137.222 - - [24/Sep/2026:03:04:13 +0200] "GET /backoffice HTTP/2.0" 404 314 "-" "Mozilla/5.0 (M ...
show more
34.7.137.222 - - [24/Sep/2026:03:04:13 +0200] "GET /backoffice HTTP/2.0" 404 314 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 Edg/153.0.0.0" 34.7.137.222 - - [24/Sep/2026:03:04:13 +0200] "GET /portal HTTP/2.0" 404 269 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 Edg/153.0.0.0" 34.7.137.222 - - [24/Sep/2026:03:04:13 +0200] "GET /account HTTP/2.0" 404 269 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 Edg/153.0.0.0"
show less
Brute-Force
๐ณ๐ฑ
Site.eu
2026-09-24 00:53:20
(9 hours ago)
Excessive multi-domain requests
Brute-Force