🇮🇹
CoreTech srl
2026-09-13 02:33:57
(2 hours ago)
cloudlinux2 fail2ban: 2026-09-13 04:31:12,472 fail2ban.filter [1606]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-13 04:31:12,472 fail2ban.filter [1606]: INFO [plesk-modsecurity] Found 34.74.91.11 - 2026-09-13 04:31:12cloudlinux2 fail2ban: 2026-09-13 04:31:12,481 fail2ban.filter [1606]: INFO [plesk-modsecurity] Found 34.74.91.11 - 2026-09-13 04:31:12cloudlinux2 fail2ban: 2026-09-13 04:31:11,757 fail2ban.filter [1606]: INFO [plesk-modsecurity] Found 34.74.91.11 - 2026-09-13 04:31:11cloudlinux2 fail2ban: 2026-09-13 04:31:12,606 fail2ban.actions [1606]: NOTICE [plesk-modsecurity] Ban 34.74.91.11cloudlinux2 fail2ban: 2026-09-13 04:31:12,528 fail2ban.filter [1606]: INFO [plesk-modsecurity] Found 34.74.91.11 - 2026-09-13 04:31:12cloudlinux2 fail2ban: 2026-09-13 04:31:12,621 fail2ban.filter [1606]: INFO [recidive] Found 34.74.91.11 - 2026-09-13 04:31:12cloudlinux2 fail2ban: 2026-09-13 04:31:12,509 fail2ban.filter [1606]: INFO [plesk-modsecurity] Found 34.74.91.11 - 2026-09-13 04:31:12cloudlinux2 fail2ban: 2026-09-13 04:31:12,
show less
Brute-Force
🇺🇸
xmission.com
2026-09-13 02:30:24
(2 hours ago)
34.74.91.11 - - [12/Sep/2026:20:30:23 -0600] "-" 400 150 "-" "-"
34.74.91.11 - - [12/Sep/2026:20:30: ...
show more
34.74.91.11 - - [12/Sep/2026:20:30:23 -0600] "-" 400 150 "-" "-"
34.74.91.11 - - [12/Sep/2026:20:30:23 -0600] "-" 400 150 "-" "-"
34.74.91.11 - - [12/Sep/2026:20:30:23 -0600] "-" 400 150 "-" "-"
34.74.91.11 - - [12/Sep/2026:20:30:23 -0600] "-" 400 150 "-" "-"
34.74.91.11 - - [12/Sep/2026:20:30:23 -0600] "-" 400 150 "-" "-"
...
show less
Web App Attack
🇫🇷
Tilellit.PRO
2026-09-13 02:12:34
(2 hours ago)
Malicious web traffic detected by CrowdSec
Hacking
🇺🇸
dot.mg
2026-09-13 02:08:02
(2 hours ago)
Bad behaviour
Web Spam
🇩🇪
Philister11
2026-09-13 02:04:59
(3 hours ago)
CrowdSec: crowdsecurity/http-crawl-non_statics (US/AS396982)
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 01:49:23
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.74.91.11 (11.91.74.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.74.91.11 (11.91.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 21:49:16.336673 2026] [security2:error] [pid 4604:tid 4604] [client 34.74.91.11:54222] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mandavaassoc.com"] [uri "/@fs/var/task/.env"] [unique_id "aqYBHO2sA3kb-Il-I7KXEwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
EGP Abuse Dept
2026-09-13 01:39:12
(3 hours ago)
Scanning for web/db/file exploits on manchetknopenkopen.nl
SQL Injection
Bad Web Bot
Web App Attack
🇸🇬
crimefireNOC
2026-09-13 01:19:58
(3 hours ago)
[waf.rce.eval] waf.rce.eval on https://manakmewa.com/api/v1/validate/code via POST (action: ban+403)
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 01:11:43
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.74.91.11 (11.91.74.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.74.91.11 (11.91.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 21:11:36.227304 2026] [security2:error] [pid 15748:tid 15763] [client 34.74.91.11:41446] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "managementconsultantcertification.com"] [uri "/.git/config"] [unique_id "aqX4SKsh2cos85QeCvKPqwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
ConsulHosting
2026-09-13 00:34:17
(4 hours ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
Anonymous
2026-09-13 00:21:52
(4 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇳🇱
Site.eu
2026-09-13 00:10:02
(4 hours ago)
Excessive multi-domain requests
Brute-Force
🇺🇸
TPI-Abuse
2026-09-13 00:05:41
(5 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.74.91.11 (11.91.74.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:949110) triggered by 34.74.91.11 (11.91.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 20:05:37.016636 2026] [security2:error] [pid 6408:tid 6408] [client 34.74.91.11:46664] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "malolobookings.com"] [uri "/rclone.conf"] [unique_id "aqXo0cxpIn6YRDX7hQ8gWQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-12 23:58:11
(5 hours ago)
Banned by Fail2Ban on server
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 23:47:40
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.74.91.11 (11.91.74.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.74.91.11 (11.91.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 19:47:33.443392 2026] [security2:error] [pid 7295:tid 7295] [client 34.74.91.11:41780] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "malinka.us"] [uri "/appearance/../../.env"] [unique_id "aqXklQkSe0D7CyPDk6_mYwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack