Anonymous
2026-10-11 02:05:06
(4 hours ago)
WAF repeated trigger detected by Fail2Ban
Web App Attack
๐ซ๐ฎ
KTSTechnology
2026-10-11 01:24:44
(5 hours ago)
Web vulnerability scanning detected by our ISP firewall
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-10-11 01:20:20
(5 hours ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
clapper
2026-10-11 00:47:59
(5 hours ago)
(mod_security) mod_security (id:980001) triggered by 34.79.183.69 (BE/Belgium/69.183.79.34.bc.google ...
show more
(mod_security) mod_security (id:980001) triggered by 34.79.183.69 (BE/Belgium/69.183.79.34.bc.googleusercontent.com): 5 in the last 3600 secs; ID: Clar
show less
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-11 00:47:57
(5 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.79.183.69 (69.183.79.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.79.183.69 (69.183.79.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 20:47:52.311979 2026] [security2:error] [pid 11545:tid 11545] [client 34.79.183.69:56002] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||windisfun.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "windisfun.com"] [uri "/z9x8c7v6b5-debug-trigger-windisfun.com"] [unique_id "asrcuDIhtMkZz7_UC7r98gAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-11 00:40:19
(5 hours ago)
Detected by CrowdSec: crowdsecurity/http-sensitive-files
Web App Attack
๐ซ๐ท
demomodule
2026-10-10 23:24:33
(7 hours ago)
PrestaShop Security Module: suspicious probe path detected (/.env)
Web App Attack
๐ณ๐ฑ
middelkoopcc
2026-10-10 23:10:21
(7 hours ago)
2026-10-11 01:08:13 GET /serviceAccountKey.json [404] && 2026-10-11 01:08:13 GET /key.json [404] && ...
show more
2026-10-11 01:08:13 GET /serviceAccountKey.json [404] && 2026-10-11 01:08:13 GET /key.json [404] && 2026-10-11 01:08:13 GET /service_account.json [404] && 182 more within 20 minutes
show less
Web App Attack
๐ซ๐ท
Stara
2026-10-10 22:59:13
(7 hours ago)
ModSecurity detected web attack - .env/config probing or SQLi/Code injection (Rule 949110)
Brute-Force
Hacking
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-10 22:52:43
(7 hours ago)
[ti-04al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apac ...
show more
[ti-04al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apache-404. Example: 34.79.183.69 - - [11/Oct/2026:00:52:35 +0200] "GET /auth/login HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36"
34.79.183.69 - - [11/Oct/2026:00:52:35 +0200] "GET /z9x8c7v6b5-debug-trigger-bakkerbeheer.com HTTP/2.0" 404 1855 "-" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)"
34.79.183.69 - - [11/Oct/2026:00:52:35 +0200] "GET /users/login HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36"
34.79.183.69 - - [11/Oct/2026:00:52:35 +0200] "GET /secure HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (K
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-10 22:48:58
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.79.183.69 (69.183.79.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.79.183.69 (69.183.79.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 18:48:55.381174 2026] [security2:error] [pid 30227:tid 30227] [client 34.79.183.69:43672] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "baker15.com"] [uri "/.env.production"] [unique_id "asrA11ICZRQdxULTn8BtfQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ฌ
mypatricks
2026-10-10 22:47:38
(7 hours ago)
34.79.183.69 | Port: 10169 | DNS: 69.183.79.34.bc.googleusercontent.com 2026-10-11T06:47:37+08:00 As ...
show more
34.79.183.69 | Port: 10169 | DNS: 69.183.79.34.bc.googleusercontent.com 2026-10-11T06:47:37+08:00 Asia/Singapore | BC.GOOGLEUSERCONTENT Data Center/Web Hosting/Transit Spam list | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 Edg/153.0.0.0 HTTP/1.1 443 GET | URL: / | Ref: - | Country: BE/Belgium/+01:00 macOS a4892af64be16f05-CDG/Paris, France 1 hits/0 secs Browser 0
show less
Brute-Force
Web App Attack
Blog Spam
Web Spam
Exploited Host
๐บ๐ธ
TPI-Abuse
2026-10-10 22:13:04
(8 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.79.183.69 (69.183.79.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.79.183.69 (69.183.79.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 18:13:00.281622 2026] [security2:error] [pid 1387:tid 1387] [client 34.79.183.69:43686] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||backspaced.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "backspaced.com"] [uri "/z9x8c7v6b5-debug-trigger-backspaced.com"] [unique_id "asq4bGwq2WPNW7w2bN_jWQAAAGk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Victor Lรณpez
2026-10-10 22:04:34
(8 hours ago)
babystudio4d.com 34.79.183.69 - - [10/Oct/2026:17:04:32 -0500] "GET /__vite_rsc_findSourceMapURL?fil ...
show more
babystudio4d.com 34.79.183.69 - - [10/Oct/2026:17:04:32 -0500] "GET /__vite_rsc_findSourceMapURL?filename=file:///app/.env&environmentName=rsc HTTP/2.0" 404 15605 "-" "Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)" -
babystudio4d.com 34.79.183.69 - - [10/Oct/2026:17:04:32 -0500] "GET /_image?href=/../../../.env HTTP/2.0" 404 15605 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)" -
babystudio4d.com 34.79.183.69 - - [10/Oct/2026:17:04:34 -0500] "GET /api/console/api_server?sense_version=%40%40SENSE_VERSION&apis=../../../../../../.env HTTP/2.0" 404 15605 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] )" -
...
show less
Hacking
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-10 21:51:00
(8 hours ago)
[ti-10al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-10al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.79.183.69 - - [10/Oct/2026:23:50:59 +0200] "GET /.env.backup HTTP/2.0" 301 297 "-" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/)"
...
show less
Bad Web Bot
Web App Attack