๐บ๐ธ
zwebvigil
2026-10-02 21:25:09
(17 minutes ago)
34.76.247.10 [02/Oct/2026:14:25:08 -0700] "GET /dist/manifest.json HTTP/1.1" 404 22 "-" port=43592 ...
show more
34.76.247.10 [02/Oct/2026:14:25:08 -0700] "GET /dist/manifest.json HTTP/1.1" 404 22 "-" port=43592 "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36" "-" "-" "www.<host>" 3453
34.76.247.10 [02/Oct/2026:14:25:08 -0700] "GET /static/manifest.json HTTP/1.1" 404 22 "-" port=43592 "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36" "-" "-" "www.<host>" 3628
34.76.247.10 [02/Oct/2026:14:25:09 -0700] "GET /uk4yss8zqz0gx6l2i7ke HTTP/1.1" 404 22 "-" port=43616 "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)" "-" "-" "www.<host>" 11558
34.76.247.10 [02/Oct/2026:14:25:09 -0700] "GET /assets/manifest.json HTTP/1.1" 404 22 "-" port=43630 "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36" "-" "-" "www.<host>" 13579
34.76.247.10 [02/Oct/2026:14:25:
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 19:28:43
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.76.247.10 (10.247.76.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.76.247.10 (10.247.76.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 15:28:36.514152 2026] [security2:error] [pid 21777:tid 21777] [client 34.76.247.10:43480] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||pelicancovecondo.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "pelicancovecondo.com"] [uri "/z9x8c7v6b5-debug-trigger-pelicancovecondo.com"] [unique_id "asAF5M1j0H9BiAO1a34vSwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
itsolon
2026-10-02 19:11:23
(2 hours ago)
[02/Oct/2026:21:11:23 +0200] 179096828382.923202 34.76.247.10 49248 217.154.7.177 443
[02/Oct/2026:2 ...
show more
[02/Oct/2026:21:11:23 +0200] 179096828382.923202 34.76.247.10 49248 217.154.7.177 443
[02/Oct/2026:21:11:23 +0200] 179096828340.857215 34.76.247.10 49248 217.154.7.177 443
[02/Oct/2026:21:11:23 +0200] 179096828341.342330 34.76.247.10 49248 217.154.7.177 443
[02/Oct/2026:21:11:23 +0200] 179096828382.650898 34.76.247.10 49248 217.154.7.177 443
[02/Oct/2026:21:11:23 +0200] 17909682832.688473 34.76.247.10 49248 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
Anonymous
2026-10-02 17:30:04
(4 hours ago)
CrowdSec decision: crowdsecurity/http-bad-user-agent (origin: crowdsec)
Port Scan
๐บ๐ธ
TPI-Abuse
2026-10-02 16:29:00
(5 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.76.247.10 (10.247.76.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.76.247.10 (10.247.76.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 12:28:53.058209 2026] [security2:error] [pid 16858:tid 16873] [client 34.76.247.10:39122] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||peluqueriabuhos.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "peluqueriabuhos.com"] [uri "/z9x8c7v6b5-debug-trigger-peluqueriabuhos.com"] [unique_id "ar_bxXpLCT7bNjGVHLCY_gAAAIo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 15:57:26
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.76.247.10 (10.247.76.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.76.247.10 (10.247.76.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 11:57:22.797062 2026] [security2:error] [pid 9195:tid 9195] [client 34.76.247.10:33048] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "penisbreath.com.whoore.com"] [uri "/uploads../.env"] [unique_id "ar_UYv6AdTfOCOhCXgxTRQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-10-02 14:37:59
(7 hours ago)
20 attempts against mh-misbehave-ban on eris
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
updown.io
2026-10-02 12:16:42
(9 hours ago)
{"level":"info","ts":1790943401.5040152,"logger":"http.log.access.log1","msg":"handled request","req ...
show more
{"level":"info","ts":1790943401.5040152,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.76.247.10","remote_port":"32836","client_ip":"34.76.247.10","proto":"HTTP/2.0","method":"GET","host":"status.hotelratepro.com","uri":"/static/manifest.json","headers":{"Sec-Fetch-User":["?1"],"Sec-Fetch-Dest":["document"],"Sec-Ch-Ua-Mobile":["?1"],"Accept":["text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8"],"Sec-Fetch-Site":["none"],"User-Agent":["Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Mobile Safari/537.36"],"Sec-Fetch-Mode":["navigate"],"Upgrade-Insecure-Requests":["1"],"Accept-Encoding":["gzip, deflate, br, zstd"],"Priority":["u=0, i"],"Sec-Ch-Ua":["\"Not=A?Brand\";v=\"99\", \"Google Chrome\";v=\"151\", \"Chromium\";v=\"151\""],"X-Middleware-Subrequest":["src/middleware:nowaf:src/middleware:src/middleware:src/middleware:src/middleware:middleware:middleware:nowaf:middleware:m
...
show less
DDoS Attack
Web App Attack
Anonymous
2026-10-02 10:00:59
(11 hours ago)
Web App Attack
๐บ๐ธ
NXTwoThou
2026-10-02 08:11:29
(13 hours ago)
/graphql
Web App Attack
๐ง๐ฌ
HighWay
2026-10-02 08:10:12
(13 hours ago)
34.76.247.10 - - [02/Oct/2026:08:10:07 +0000] "GET /model/info HTTP/1.1" 404 473 "-" "Mozilla/5.0 (c ...
show more
34.76.247.10 - - [02/Oct/2026:08:10:07 +0000] "GET /model/info HTTP/1.1" 404 473 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36"
34.76.247.10 - - [02/Oct/2026:08:10:07 +0000] "GET /sign-in HTTP/1.1" 404 473 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36"
34.76.247.10 - - [02/Oct/2026:08:10:07 +0000] "GET /mz9hgrookgfd89atp5lk HTTP/1.1" 404 4424 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)"
34.76.247.10 - - [02/Oct/2026:08:10:07 +0000] "GET /cpq1jkwoyix5ayzcocyh HTTP/1.1" 404 4423 "-" "Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)"
34.76.247.10 - - [02/Oct/2026:08:10:07 +0000] "GET /signin HTTP/1.1" 404 4424 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36"
34.76.247.10 - - [02/Oct/2026:08:10:07 +0000] "GET /auth HTTP/1.
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-10-02 07:30:03
(14 hours ago)
CrowdSec decision: crowdsecurity/http-admin-interface-probing (origin: crowdsec)
Web App Attack
๐ซ๐ท
masterguru
2026-10-02 07:21:20
(14 hours ago)
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encod ...
show more
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encoding/ /proxy/ /lock-token/ /content-range/ /if/ /x-http-method-override/ /x-http-method/ /x-method-override/ /x-middleware-subrequest/ /expect/" at TX:header_name_920450_x-middleware-subrequest. (920450-197)
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-02 06:45:00
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.76.247.10 (10.247.76.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.76.247.10 (10.247.76.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 02:44:55.401716 2026] [security2:error] [pid 1347:tid 1422] [client 34.76.247.10:58146] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bortec-corp.com"] [uri "/@fs/app/.env"] [unique_id "ar9S54X5hH89zUg3RJegFgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-10-02 06:30:16
(15 hours ago)
Multiple WAF Violations
Web App Attack