๐ช๐ธ
pepitogrillo
2026-10-11 12:46:53
(1 hour ago)
34.74.111.148 - - [11/Oct/2026:12:46:52 +0000] "GET /25jdyetwutpt1tlvadj0 HTTP/1.1" 404 11840 "-" "M ...
show more
34.74.111.148 - - [11/Oct/2026:12:46:52 +0000] "GET /25jdyetwutpt1tlvadj0 HTTP/1.1" 404 11840 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
...
show less
DNS Compromise
DNS Poisoning
Fraud Orders
DDoS Attack
Ping of Death
Phishing
Fraud VoIP
Open Proxy
Web Spam
Email Spam
Port Scan
Hacking
SQL Injection
Bad Web Bot
Exploited Host
Web App Attack
IoT Targeted
Anonymous
2026-10-11 06:30:04
(7 hours ago)
CrowdSec decision: crowdsecurity/http-crawl-non_statics (origin: crowdsec)
Port Scan
๐ฉ๐ช
hbrks
2026-10-11 03:43:19
(10 hours ago)
200 attack(s) detected, such as these: {"event":"web_block","ip":"34.74.111.148","host":"api.marche- ...
show more
200 attack(s) detected, such as these: {"event":"web_block","ip":"34.74.111.148","host":"api.marche-be.com","request":"GET /portal HTTP/2.0","user_agent":"","reason":"Status-404","timestamp":"2026-10-11T03:43:19 00:00","logentry":"api.marche-be.com 34.74.111.148 - - [11/Oct/2026:03:43:19 0000] \"GET /portal HTTP/2.0\" 404 0 \"-\" \"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36\" \"172.25.79.30:5000\""} * Report Details *: https://p4u.xyz/9CF6HPY1R1T/1* IP Details *: https://p4u.xyz/9CF6HPY1R1T/2
show less
Web Spam
Hacking
Bad Web Bot
๐ฉ๐ช
TheDjRider
2026-10-11 03:26:40
(10 hours ago)
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban tri ...
show more
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban triggered. Detection time (UTC): 2026-10-11T03:26:38.470664806Z. Context: http_status=200
show less
Web App Attack
๐ซ๐ท
Quarks Solutions
2026-10-11 01:42:29
(12 hours ago)
crowdsecurity/appsec-vpatch
Web App Attack
๐จ๐ฆ
Vianpyro
2026-10-11 01:21:17
(13 hours ago)
Honeypot: 284 request(s) in 25 min. Paths: /, /%2Fadmin, /%2Fapi/config, /%2Fdashboard, /%2Fsettings ...
show more
Honeypot: 284 request(s) in 25 min. Paths: /, /%2Fadmin, /%2Fapi/config, /%2Fdashboard, /%2Fsettings. Method(s): GET, POST. UA: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; bingbot/2.0; +htt. ASN: 396982 (Google LLC). URL-encoding WAF evasion detected.
show less
Hacking
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-11 00:39:34
(13 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.74.111.148 (148.111.74.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.74.111.148 (148.111.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 20:39:28.408620 2026] [security2:error] [pid 31056:tid 31056] [client 34.74.111.148:40226] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||vvs-inc.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "vvs-inc.com"] [uri "/z9x8c7v6b5-debug-trigger-vvs-inc.com"] [unique_id "asrawJqTIlP5a_K8RcvnggAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Som1ght3n
2026-10-11 00:30:24
(13 hours ago)
Attempted path traversal to access sensitive .env files via an HTTP GET request.
Hacking
๐ซ๐ท
Allolatr
2026-10-11 00:24:06
(13 hours ago)
Oct 11 02:24:05 [redacted] j443: ::ffff:34.74.111.148 [redacted].com "GET /webpack-stats.json HTTP/2 ...
show more
Oct 11 02:24:05 [redacted] j443: ::ffff:34.74.111.148 [redacted].com "GET /webpack-stats.json HTTP/2.0" 301 166 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" Oct 11 02:24:05 [redacted] j443: ::ffff:34.74.111.148 [redacted].com "GET /ir5fmrr8l9bztdbgzh2o HTTP/2.0" 301 166 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36"
show less
Bad Web Bot
Web App Attack
Anonymous
2026-10-10 23:55:59
(14 hours ago)
Banned by Fail2Ban on server
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-10 23:32:40
(14 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.74.111.148 (148.111.74.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.74.111.148 (148.111.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 19:32:33.033451 2026] [security2:error] [pid 23409:tid 23409] [client 34.74.111.148:54966] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||voterfraud2016.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "voterfraud2016.com"] [uri "/z9x8c7v6b5-debug-trigger-voterfraud2016.com"] [unique_id "asrLEVSoMiRBzzWZghIk7AAAAGw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-10 23:30:11
(14 hours ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection
๐บ๐ธ
mnsf
2026-10-10 23:05:14
(15 hours ago)
Too many Status 40X (45)
Scanning/Probing (48)
Request Overload (128)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-10 23:02:06
(15 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.74.111.148 (148.111.74.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.74.111.148 (148.111.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 19:02:00.588216 2026] [security2:error] [pid 27437:tid 27437] [client 34.74.111.148:57138] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||vonkugelgen.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "vonkugelgen.com"] [uri "/z9x8c7v6b5-debug-trigger-vonkugelgen.com"] [unique_id "asrD6KkgUHv5gubDNxGEjgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-10-10 22:57:12
(15 hours ago)
Web attack/malicious scanning detected
Web App Attack