๐ณ๐ฑ
Site.eu
2026-09-24 04:31:55
(9 minutes ago)
Excessive multi-domain requests
Brute-Force
๐ช๐ธ
robotstxt
2026-09-24 03:55:03
(46 minutes ago)
34.78.44.38 - - [24/Sep/2026:03:54:00 +0000] "GET / HTTP/2.0" 403 10564 "https://geoposicionamiento. ...
show more
34.78.44.38 - - [24/Sep/2026:03:54:00 +0000] "GET / HTTP/2.0" 403 10564 "https://geoposicionamiento.com/" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" "-" edge="34.78.44.38"
34.78.44.38 - - [24/Sep/2026:03:54:00 +0000] "GET /.vite/manifest.json HTTP/2.0" 403 10980 "https://geoposicionamiento.com/.vite/manifest.json" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36 EdgA/152.0.0.0" "-" edge="34.78.44.38"
34.78.44.38 - - [24/Sep/2026:03:54:00 +0000] "GET /build/manifest.json HTTP/2.0" 403 10980 "https://geoposicionamiento.com/build/manifest.json" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36 EdgA/152.0.0.0" "-" edge="34.78.44.38"
34.78.44.38 - - [24/Sep/2026:03:54:00 +0000] "GET /z9x8c7v6b5-debug-trigger-geoposicionamiento.com HTTP/2.0" 403 11458 "https://geoposicionamiento.com/z9x8c7v6b5-debug-trigger-geoposicionamient
...
show less
Web App Attack
๐ฉ๐ช
bazter.pro
2026-09-24 03:53:55
(47 minutes ago)
Fail2Ban: plesk-bot-aggressive - 15 failures
Port Scan
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-24 03:52:26
(49 minutes ago)
20 attempts against mh-misbehave-ban on onion
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 03:49:26
(52 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.78.44.38 (38.44.78.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.78.44.38 (38.44.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 23:49:22.312180 2026] [security2:error] [pid 12353:tid 12353] [client 34.78.44.38:44032] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "georgelaceysales.com"] [uri "/.env"] [unique_id "arSdwi2xp_wVsq-0u4tCnQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
masterguru
2026-09-24 03:46:44
(55 minutes ago)
Inbound Anomaly Score Exceeded (Total Score: 5). Operator GE matched 5 at TX:anomaly_score. (949110- ...
show more
Inbound Anomaly Score Exceeded (Total Score: 5). Operator GE matched 5 at TX:anomaly_score. (949110-122)
show less
Hacking
Anonymous
2026-09-24 02:00:49
(2 hours ago)
34.78.44.38 - - [24/Sep/2026:04:00:47 +0200] "GET / HTTP/1.1" 403 183 "-" "Mozilla/5.0 (X11; Linux x ...
show more
34.78.44.38 - - [24/Sep/2026:04:00:47 +0200] "GET / HTTP/1.1" 403 183 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
34.78.44.38 - - [24/Sep/2026:04:00:47 +0200] "GET /account/login HTTP/1.1" 403 183 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
34.78.44.38 - - [24/Sep/2026:04:00:48 +0200] "GET /user/login HTTP/1.1" 403 183 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
34.78.44.38 - - [24/Sep/2026:04:00:48 +0200] "GET /signin HTTP/1.1" 403 183 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
34.78.44.38 - - [24/Sep/2026:04:00:48 +0200] "POST / HTTP/1.1" 403 124 "-" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)"
34.78.44.38 - - [24/Sep/2026:04:00:48 +0200] "GET /forgot-password HTTP/1.1" 403 183 "-" "Mozilla/5.0 (X11; Linux x
...
show less
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-09-24 00:28:01
(4 hours ago)
12.623 requests from abuseipdb.com blacklisted IP (1yr1mo1d)
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-23 21:07:35
(7 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.78.44.38 (38.44.78.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.78.44.38 (38.44.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 17:07:28.731994 2026] [security2:error] [pid 1020:tid 1020] [client 34.78.44.38:60578] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||geriterry.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "geriterry.com"] [uri "/z9x8c7v6b5-debug-trigger-geriterry.com"] [unique_id "arQ_kIxT3NM8MCV9GpFPOwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-23 19:20:07
(9 hours ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-09-23 18:27:42
(10 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.78.44.38 (38.44.78.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.78.44.38 (38.44.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 14:27:38.050706 2026] [security2:error] [pid 15760:tid 15760] [client 34.78.44.38:43484] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||gevieworld.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "gevieworld.com"] [uri "/z9x8c7v6b5-debug-trigger-gevieworld.com"] [unique_id "arQaGrTo8KoaV-7ARkrMKwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 18:12:34
(10 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.78.44.38 (38.44.78.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.78.44.38 (38.44.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 14:12:31.042127 2026] [security2:error] [pid 13871:tid 13878] [client 34.78.44.38:49858] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||gfx-technology.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "gfx-technology.com"] [uri "/z9x8c7v6b5-debug-trigger-gfx-technology.com"] [unique_id "arQWj1YUJS46cPD8f5p-1QAAAUE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
paissangroup
2026-09-23 17:25:01
(11 hours ago)
Multiple WAF Violations
Web App Attack
๐ฎ๐น
CoreTech srl
2026-09-23 17:14:15
(11 hours ago)
cloudlinux2 fail2ban: 2026-09-23 19:08:54,969 fail2ban.filter [1603]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-23 19:08:54,969 fail2ban.filter [1603]: INFO [plesk-modsecurity] Found 34.78.44.38 - 2026-09-23 19:08:54cloudlinux2 fail2ban: 2026-09-23 19:08:55,494 fail2ban.actions [1603]: NOTICE [plesk-modsecurity] Ban 34.78.44.38cloudlinux2 fail2ban: 2026-09-23 19:08:54,988 fail2ban.filter [1603]: INFO [plesk-modsecurity] Found 34.78.44.38 - 2026-09-23 19:08:54cloudlinux2 fail2ban: 2026-09-23 19:08:54,978 fail2ban.filter [1603]: INFO [plesk-modsecurity] Found 34.78.44.38 - 2026-09-23 19:08:54cloudlinux2 fail2ban: 2026-09-23 19:08:55,501 fail2ban.filter [1603]: INFO [recidive] Found 34.78.44.38 - 2026-09-23 19:08:55cloudlinux2 fail2ban: 2026-09-23 19:09:23,542 fail2ban.filter [1603]: INFO [plesk-modsecurity] Found 156.217.100.112 - 2026-09-23 19:09:23cloudlinux2 fail2ban: 2026-09-23 19:09:34,156 fail2ban.actions [1603]: NOTICE [plesk-modsecurity] Ban 156.217.100.112cloudlinux2 fail2ban: 2026-09-23 19:09:34,134 fail2ban.fil
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 17:07:38
(11 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.78.44.38 (38.44.78.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.78.44.38 (38.44.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 13:07:34.739119 2026] [security2:error] [pid 1243:tid 1243] [client 34.78.44.38:37220] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||giesselman.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "giesselman.com"] [uri "/z9x8c7v6b5-debug-trigger-giesselman.com"] [unique_id "arQHVtftxoTrFqvIPiRznQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack