๐ธ๐ฌ
simpeg-adm.bandung.go.id
2026-10-05 19:04:34
(5 hours ago)
05/Oct/2026:19:04:34 +0000;34.7.95.108;"/lwy7ibpj1g7abrg6bozd"
05/Oct/2026:19:04:34 +0000;34.7.95.10 ...
show more
05/Oct/2026:19:04:34 +0000;34.7.95.108;"/lwy7ibpj1g7abrg6bozd"
05/Oct/2026:19:04:34 +0000;34.7.95.108;"/dist/.vite/manifest.json"
05/Oct/2026:19:04:34 +0000;34.7.95.108;"/.vite/manifest.json"
05/Oct/2026:19:04:34 +0000;34.7.95.108;"/dist/manifest.json"
05/Oct/2026:19:04:34 +0000;34.7.95.108;"/z9x8c7v6b5-debug-trigger-app.peggysaas.com"
05/Oct/2026:19:04:34 +0000;34.7.95.108;"/lib/terminal-xhr.php"
05/Oct/2026:19:04:34 +0000;34.7.95.108;"/x487w1bh36gmqkny9ia2"
...
show less
Web Spam
Brute-Force
Web App Attack
๐บ๐ธ
chronos
2026-10-05 17:27:47
(6 hours ago)
[AUTORAVALT][[05/10/2026 - 14:27:47 -03:00 UTC]
Attack from [Google LLC]
[34.7.95.108][108.95.7.34.b ...
show more
[AUTORAVALT][[05/10/2026 - 14:27:47 -03:00 UTC]
Attack from [Google LLC]
[34.7.95.108][108.95.7.34.bc.googleusercontent.com]
Action: BLocKed
Hacking... Unauthorized attempts to access the server.
Web App Attack -> Attempts to probe for or exploit installed web applications such as a CMS like WordPress/Drupal, e-commerce solutions, forum software, phpMyAdmin a]
...
show less
Hacking
Web App Attack
๐บ๐ธ
thieuleu
2026-10-05 13:34:24
(10 hours ago)
Unauthorized connection attempt blocked by firewall policy. Web application hardening active.
Brute-Force
Exploited Host
๐บ๐ธ
TPI-Abuse
2026-10-05 11:00:47
(13 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.7.95.108 (108.95.7.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.7.95.108 (108.95.7.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 07:00:41.574294 2026] [security2:error] [pid 980:tid 980] [client 34.7.95.108:43758] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||rooksfamily.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "rooksfamily.com"] [uri "/z9x8c7v6b5-debug-trigger-rooksfamily.com"] [unique_id "asODWVWPPTNJcuWz2-ukywAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-10-05 09:47:12
(14 hours ago)
Crawler ignoring refusals | ua: Mozilla/5.0 (compatible; Bytespider; [email protected] ) ...
show more
Crawler ignoring refusals | ua: Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36, Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36, Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/) (+8 more) | path: /40uf3wgignzutf7vmhyb, /asset-manifest.json, /dist/manifest.json (+15 more)
show less
Bad Web Bot
๐ท๐ด
clauss
2026-10-05 09:43:43
(14 hours ago)
34.7.95.108 - - [05/Oct/2026:12:43:42 +0300] "GET /api/orders/..%2fadmin/config.json HTTP/2.0" 301 0 ...
show more
34.7.95.108 - - [05/Oct/2026:12:43:42 +0300] "GET /api/orders/..%2fadmin/config.json HTTP/2.0" 301 0 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )"
34.7.95.108 - - [05/Oct/2026:12:43:42 +0300] "GET /api/orders/..%2fadmin/config.json HTTP/2.0" 404 14179 "https://remusazoitei.com/api/orders/..%2fadmin/config.json" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 09:05:20
(15 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.7.95.108 (108.95.7.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.7.95.108 (108.95.7.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 05:05:13.961237 2026] [security2:error] [pid 29010:tid 29010] [client 34.7.95.108:35996] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||rcrgalicia.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "rcrgalicia.com"] [uri "/z9x8c7v6b5-debug-trigger-rcrgalicia.com"] [unique_id "asNoSdhM6V-KtMlASyeuhQAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
masterguru
2026-10-05 07:56:51
(16 hours ago)
Inbound Anomaly Score Exceeded (Total Score: 5). Operator GE matched 5 at TX:anomaly_score. (949110- ...
show more
Inbound Anomaly Score Exceeded (Total Score: 5). Operator GE matched 5 at TX:anomaly_score. (949110-122)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-05 07:55:43
(16 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.7.95.108 (108.95.7.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.7.95.108 (108.95.7.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 03:55:35.625477 2026] [security2:error] [pid 16284:tid 16284] [client 34.7.95.108:49008] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||puckerbuttbikini.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "puckerbuttbikini.com"] [uri "/z9x8c7v6b5-debug-trigger-puckerbuttbikini.com"] [unique_id "asNX9_G_oJB8wG2RcQauGwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐พ
Rizzy
2026-10-05 07:38:01
(16 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ง๐ช
cmbplf
2026-10-05 07:34:05
(16 hours ago)
303 requests with url.path */@fs/*
125 requests with url.path */proc/*
Brute-Force
Bad Web Bot
๐ฌ๐ง
poundawebsiteltd
2026-10-05 07:04:31
(17 hours ago)
Malicious activity in general-malicious. Evidence: (apache_probe) Failed Access (403/404) 34.7.95.10 ...
show more
Malicious activity in general-malicious. Evidence: (apache_probe) Failed Access (403/404) 34.7.95.108 (NL/The Netherlands/[REDACTED_DOMAIN]): 20 in the last 3600 secs | UA: (apache_probe) Failed Access (403/404) 34.7.95.108 (NL/The Netherlands/108.95.7.34.bc.googleusercontent.com): 20 in the last 3600 secs
show less
Brute-Force
Web App Attack
๐ช๐ธ
masterguru
2026-10-05 06:50:48
(17 hours ago)
BAD BOT - Detected and Blocked.. Matched phrase "claudebot" at REQUEST_HEADERS:user-agent. (1100000- ...
show more
BAD BOT - Detected and Blocked.. Matched phrase "claudebot" at REQUEST_HEADERS:user-agent. (1100000-122)
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-05 06:41:06
(17 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.7.95.108 (108.95.7.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.7.95.108 (108.95.7.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 02:41:01.219380 2026] [security2:error] [pid 27788:tid 27788] [client 34.7.95.108:60668] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||podbillspec.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "podbillspec.com"] [uri "/z9x8c7v6b5-debug-trigger-podbillspec.com"] [unique_id "asNGfWMW2PYPTZ7B0q972AAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 05:44:59
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.7.95.108 (108.95.7.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.7.95.108 (108.95.7.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 01:44:54.124911 2026] [security2:error] [pid 15080:tid 15080] [client 34.7.95.108:57558] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "perlcreative.com"] [uri "/.htpasswd"] [unique_id "asM5VrDiNnLmXzeM1OQKSQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack