๐ฎ๐ฉ
David Koswari
2026-08-21 05:22:00
(1 day ago)
REQ_BLOCKED_SECURITY
DDoS Attack
FTP Brute-Force
Ping of Death
Port Scan
Hacking
SQL Injection
Spoofing
Brute-Force
Bad Web Bot
Exploited Host
Web App Attack
SSH
IoT Targeted
๐ฉ๐ช
grassau.com
2026-08-20 10:43:08
(2 days ago)
(mod_security) mod_security triggered on hostname [redacted] 34.73.21.76 (US/United States/South Car ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.73.21.76 (US/United States/South Carolina/North Charleston/76.21.73.34.bc.googleusercontent.com)
show less
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-08-20 10:18:16
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.73.21.76 (76.21.73.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.73.21.76 (76.21.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 06:18:13.583373 2026] [security2:error] [pid 30924:tid 30924] [client 34.73.21.76:37268] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||circlehealthcaregroup.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "circlehealthcaregroup.com"] [uri "/rclone.conf"] [unique_id "aobUZfSGtqF62Ka3ye3nCQAAACs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
voormedia
2026-08-20 10:01:58
(2 days ago)
Accessed trap at '/.aws/credentials'
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-20 09:52:30
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.73.21.76 (76.21.73.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.73.21.76 (76.21.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 05:52:23.314220 2026] [security2:error] [pid 30198:tid 30198] [client 34.73.21.76:49532] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.accu-tuner.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.accu-tuner.com"] [uri "/rclone.conf"] [unique_id "aobOV-Rb6MfwH92rHCENqQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-20 07:55:58
(2 days ago)
Sensitive Configuration File Disclosure.
Hacking
๐ฆ๐บ
[email protected]
2026-08-20 07:25:02
(2 days ago)
[Drupal AbuseIPDB module] Request path is blacklisted. /webpack-stats.json
Web App Attack
๐ณ๐ฑ
Savvii
2026-08-20 07:23:10
(2 days ago)
20 attempts against mh-misbehave-ban on tilia
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
london2038.com
2026-08-20 07:12:59
(2 days ago)
Malformed or malicious web request
34.73.21.76 - - [20/Aug/2026:09:12:56 +0200] "POST /graphql HTTP/ ...
show more
Malformed or malicious web request
34.73.21.76 - - [20/Aug/2026:09:12:56 +0200] "POST /graphql HTTP/2.0" 404 40034 "https://<REDACTED>" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/148.0.0.0 Safari/537.36"
show less
Hacking
Web App Attack
Anonymous
2026-08-20 07:08:00
(2 days ago)
Aggressive Robot or Attack DDOS
DDoS Attack
Anonymous
2026-08-20 06:39:28
(2 days ago)
Banned by Fail2Ban on server
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-20 06:05:53
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.73.21.76 (76.21.73.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.73.21.76 (76.21.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 02:05:49.577306 2026] [security2:error] [pid 29101:tid 29101] [client 34.73.21.76:43942] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.creartest.com|F|2"] [data ".creartest.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.creartest.com"] [uri "/z9x8c7v6b5-debug-trigger-www.creartest.com"] [unique_id "aoaZPYbkh02JG16H_2x__gAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
LoneRider
2026-08-20 05:46:09
(2 days ago)
[20/Aug/2026:07:46:09.324252 +0200] aoaUoQncCjM85UmDSjBmfAAAAAE 34.73.21.76 50342 127.0.0.1 7081
[20 ...
show more
[20/Aug/2026:07:46:09.324252 +0200] aoaUoQncCjM85UmDSjBmfAAAAAE 34.73.21.76 50342 127.0.0.1 7081
[20/Aug/2026:07:46:09.354584 +0200] aoaUoU8I4_X3hMBavGAhwQAAAAA 34.73.21.76 50346 127.0.0.1 7081
[20/Aug/2026:07:46:09.419931 +0200] aoaUoeUDwnbcXMbeVlXtewAAAAQ 34.73.21.76 50368 127.0.0.1 7081
...
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-20 05:41:48
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.73.21.76 (76.21.73.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.73.21.76 (76.21.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 01:41:41.998461 2026] [security2:error] [pid 18153:tid 18153] [client 34.73.21.76:46464] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||desarrollosdecolima.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "desarrollosdecolima.com"] [uri "/rclone.conf"] [unique_id "aoaTlWIm7KiXiKiYS6jOBgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-20 05:25:06
(2 days ago)
GET /.git/config HTTP/1.1
...
Web App Attack