π³π±
Savvii
2026-09-30 04:44:49
(30 minutes ago)
20 attempts against mh-misbehave-ban on pyrus
Brute-Force
Bad Web Bot
Web App Attack
π³π±
BlueWire Hosting
2026-09-30 03:38:15
(1 hour ago)
Bad bot ignoring robot.txt
Bad Web Bot
π³π΄
Bots.go.to.hell
2026-09-30 02:33:32
(2 hours ago)
This IP was detected by CrowdSec triggering custom/http-bad-crawler-ban
Web App Attack
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-09-30 02:13:04
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.78.38.58 (58.38.78.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.78.38.58 (58.38.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 22:12:56.606006 2026] [security2:error] [pid 10810:tid 10810] [client 34.78.38.58:50252] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||lynnejewson.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "lynnejewson.com"] [uri "/z9x8c7v6b5-debug-trigger-lynnejewson.com"] [unique_id "arxwKEvRGM3C6mavpqNbjAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-30 01:29:28
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.78.38.58 (58.38.78.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.78.38.58 (58.38.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 21:29:21.131092 2026] [security2:error] [pid 2104:tid 2124] [client 34.78.38.58:40392] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||lzmarketingsolutions.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "lzmarketingsolutions.com"] [uri "/z9x8c7v6b5-debug-trigger-lzmarketingsolutions.com"] [unique_id "arxl8XL6y_2N-NSeKdwZuQAAAJA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
Laplus
2026-09-30 01:03:35
(4 hours ago)
34.78.38.58 - - [30/Sep/2026:03:03:33 +0200] "GET /.git-credentials HTTP/1.1" 502 157 "-" "Mozilla/5 ...
show more
34.78.38.58 - - [30/Sep/2026:03:03:33 +0200] "GET /.git-credentials HTTP/1.1" 502 157 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.4; +https://openai.com/gptbot" "-"
34.78.38.58 - - [30/Sep/2026:03:03:34 +0200] "GET /.gitlab-ci.yml HTTP/1.1" 502 157 "-" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)" "-"
34.78.38.58 - - [30/Sep/2026:03:03:34 +0200] "GET /.github/workflows/deploy.yml HTTP/1.1" 502 157 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)" "-"
34.78.38.58 - - [30/Sep/2026:03:03:34 +0200] "GET /.env HTTP/1.1" 502 157 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)" "-"
34.78.38.58 - - [30/Sep/2026:03:03:34 +0200] "GET /.git/config HTTP/1.1" 502 157 "-" "Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)" "-"
34.78.38.58 - - [30/Sep/2026:03:03:34 +0200] "GET /.aws/config HTTP/1.1" 502 157 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7)
...
show less
Hacking
Web App Attack
π²πΎ
Rizzy
2026-09-30 00:36:18
(4 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
π©πͺ
Hazzard
2026-09-30 00:17:21
(4 hours ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted]): (CF_ENABLE)
Bad Web Bot
π©πͺ
Hary74656
2026-09-29 23:40:41
(5 hours ago)
Fail2Ban on schani.hostmi.at: jail=apache-instablock, failures=1.
[client 34.78.38.58] [realclient 3 ...
show more
Fail2Ban on schani.hostmi.at: jail=apache-instablock, failures=1.
[client 34.78.38.58] [realclient 34.78.38.58] [30/Sep/2026:01:40:41 +0200] [vhost schani.hostmi.at] 403 "GET /@fs/app/.env?raw?? HTTP/2.0"
show less
Web App Attack
π«π·
Stara
2026-09-29 23:32:52
(5 hours ago)
ModSecurity detected web attack - .env/config probing or SQLi/Code injection (Rule 949110)
Brute-Force
Hacking
Web App Attack
Anonymous
2026-09-29 22:50:05
(6 hours ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection
π«π·
IRISIO
2026-09-29 20:53:35
(8 hours ago)
scans/SQL injection/spam posts : 1604 queries
Web App Attack
SQL Injection
π³π΄
jad-abuse
2026-09-29 19:36:43
(9 hours ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: php_rce, ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: php_rce, env_probe, actuator, ignition_debug, source_backup, path_traversal, server_status, aws_creds. Observed by 1 sensor(s); 395 hits.
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-29 17:56:09
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.78.38.58 (58.38.78.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.78.38.58 (58.38.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 13:56:04.384039 2026] [security2:error] [pid 24426:tid 24426] [client 34.78.38.58:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "map.365soft.top"] [uri "/userfiles"] [unique_id "arv7tBqLP7m37bLcbjNotAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-29 17:43:49
(11 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack