๐ฌ๐ง
Aetherweb Ark
2026-10-05 07:35:17
(20 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.74.23.60 (US/United States/60.23.74.34.bc.go ...
show more
(mod_security) mod_security (id:949110) triggered by 34.74.23.60 (US/United States/60.23.74.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 07:32:05
(20 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.74.23.60 (60.23.74.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.74.23.60 (60.23.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 03:31:58.459320 2026] [security2:error] [pid 2538:tid 2538] [client 34.74.23.60:36536] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||vintageamptubes.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "vintageamptubes.com"] [uri "/z9x8c7v6b5-debug-trigger-vintageamptubes.com"] [unique_id "asNSbvIVWicpSBXw1tV_TgAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
etu brutus
2026-10-05 07:31:45
(20 hours ago)
34.74.23.60 has been banned for [WebApp Attack]
...
Hacking
Bad Web Bot
Web App Attack
๐ซ๐ท
Stara
2026-10-05 06:06:14
(21 hours ago)
ModSecurity detected web attack - .env/config probing or SQLi/Code injection (Rule 949110)
Brute-Force
Hacking
Web App Attack
Anonymous
2026-10-05 05:47:20
(22 hours ago)
fail2ban jail apache-scanner: 34.74.23.60 - - [04/Oct/2026:22:47:13 -0700] "GET /z9x8c7v6b5-debug-tr ...
show more
fail2ban jail apache-scanner: 34.74.23.60 - - [04/Oct/2026:22:47:13 -0700] "GET /z9x8c7v6b5-debug-trigger-vikchaudhary.com HTTP/1.1" 404 65489 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)" 34.74.23.60 - - [04/Oct/2026:22:47:13 -0700] "GET /thllec1fgd62te9j6j3i HTTP/1.1" 404 69453 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)" 34.74.23.60 - - [04/Oct/2026:22:47:13 -0700] "POST /lib/terminal-xhr.php HTTP/1.1" 404 69451 "-" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)" 34.74.23.60 - - [04/Oct/2026:22:47:13 -0700] "GET /dist/.vite/manifest.json HTTP/1.1" 404 69451 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" 34.74.23.60 - - [04/Oct/2026:22:47:13 -0700] "GET /build/manifest.json HTTP/1.1" 404 69451 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153
show less
Web App Attack
Port Scan
๐บ๐ธ
TPI-Abuse
2026-10-05 05:16:08
(22 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.74.23.60 (60.23.74.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.74.23.60 (60.23.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 01:16:04.025340 2026] [security2:error] [pid 17173:tid 17173] [client 34.74.23.60:56896] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||videoverse.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "videoverse.com"] [uri "/z9x8c7v6b5-debug-trigger-videoverse.com"] [unique_id "asMylMfFnIZ-XjRqp1VEJAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 04:24:41
(23 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.74.23.60 (60.23.74.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.74.23.60 (60.23.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 00:24:37.272463 2026] [security2:error] [pid 28784:tid 28784] [client 34.74.23.60:58518] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||vibratingharvard.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "vibratingharvard.com"] [uri "/z9x8c7v6b5-debug-trigger-vibratingharvard.com"] [unique_id "asMmhf6KRx9dIM6dADq2zQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-10-05 04:24:26
(23 hours ago)
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .backup/ ...
show more
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .compositefont/ .config/ .conf/ .crt/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dist/ .dll/ .dos/ .dpkg-dist/ .drv/ .gadget/ .hta/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .inf/ .ini/ .jse/ .key/ .licx/ .lnk/ .log/ .mdb/ .msc/ .ocx/ .old/ .pass/ .pdb/ .pfx/ .pif/ .pem/ .pol/ .prf/ .printer/ .pwd/ .rdb/ .rdp/ .reg/ .resources/ .resx/ .scr/ .sct/ .shs/ .sql/ .swp/ .sys/ .tlb/ .tmp/ .url/ .vb/ .vbe/ .vbs/ .vbproj/ .vsdisco/ .vxd/ .webinfo/ .ws/ .wsc/ .wsf/ .wsh/ .xsd/ .xsx/" at TX:extension. (920440-195)
show less
Hacking
๐ซ๐ท
COMAITE
2026-10-05 02:40:20
(1 day ago)
Common web attack from 34.74.23.60.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 02:33:52
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.74.23.60 (60.23.74.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.74.23.60 (60.23.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 22:33:44.794354 2026] [security2:error] [pid 15761:tid 15761] [client 34.74.23.60:37120] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||vexxarr.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "vexxarr.com"] [uri "/z9x8c7v6b5-debug-trigger-vexxarr.com"] [unique_id "asMMiCIfAmv-DF1gkN695QAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 02:03:00
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.74.23.60 (60.23.74.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.74.23.60 (60.23.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 22:02:54.119262 2026] [security2:error] [pid 30447:tid 30447] [client 34.74.23.60:44362] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||vertirama.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "vertirama.com"] [uri "/z9x8c7v6b5-debug-trigger-vertirama.com"] [unique_id "asMFTtVy5xJKneeEKvDr7gAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-10-05 01:49:43
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
๐ซ๐ท
masterguru
2026-10-05 01:44:41
(1 day ago)
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .back/ .b ...
show more
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .back/ .backup/ .bak/ .bck/ .bk/ .bkp/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .cnf/ .com/ .compositefont/ .config/ .conf/ .copy/ .crt/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dist/ .dll/ .dos/ .dpkg-dist/ .drv/ .gadget/ .hta/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .inf/ .ini/ .jks/ .jse/ .key/ .licx/ .lnk/ .log/ .mdb/ .msc/ .ocx/ .old/ .pass/ .pdb/ .pfx/ .pif/ .pem/ .pol/ .prf/ .printer/ .pwd/ .rdb/ .rdp/ .reg/ .resources/ .resx/ .sav/ .save/ .scr/ .sct/ .sh/ .shs/ .sql/ .sqlite/ .sqlite3/ .swap/ .swo/ .swp/ .sys/ .temp/ .tfstate/ .tlb/ .tmp/ .vb/ .vbe/ .vbs/ .vbproj/ .vsdisco/ .vxd/ .webinfo/ .ws/ .wsc/ .wsf/ .wsh/ .xsd/ .xsx/" at TX:extension. (920440-193)
show less
Hacking
๐ง๐ช
cmbplf
2026-10-05 01:23:46
(1 day ago)
1.260 requests with url.path */@fs/*
363 requests with url.path */proc/*
261 requests with url.pa ...
show more
1.260 requests with url.path */@fs/*
363 requests with url.path */proc/*
261 requests with url.path *config.json
247 requests with url.path *.aws/*
176 requests with url.path *.ssh/*
show less
Brute-Force
Bad Web Bot
๐ณ๐ฑ
Savvii
2026-10-05 01:17:15
(1 day ago)
20 attempts against mh_ha-misbehave-ban on bud
Brute-Force
Bad Web Bot
Web App Attack