๐ณ๐ฑ
MyGlobalFlowers
2026-06-13 16:49:11
(1 week ago)
Multiple WAF Violations
Web App Attack
๐จ๐ฆ
Mediashaker
2026-06-13 16:34:35
(1 week ago)
(apache-scanners) Failed apache-scanners trigger with match [redacted] from 34.79.184.171 (BE/Belgiu ...
show more
(apache-scanners) Failed apache-scanners trigger with match [redacted] from 34.79.184.171 (BE/Belgium/171.184.79.34.bc.googleusercontent.com)
show less
Port Scan
๐บ๐ธ
SketchyDude
2026-06-13 16:16:20
(1 week ago)
Banned by Fail2Ban jail: apache-fakegooglebot
Bad Web Bot
๐ธ๐ฌ
securejdprop
2026-06-13 15:34:09
(1 week ago)
This IP was detected by CrowdSec triggering crowdsecurity/suricata-major-severity(๐พ - ๐ Many TCP/SYN ...
show more
This IP was detected by CrowdSec triggering crowdsecurity/suricata-major-severity(๐พ - ๐ Many TCP/SYN - Possible Masscan Network Service Discovery ๐ฅท - T1046). Ip 34.79.184.171 performed 'crowdsecurity/suricata-major-severity' (1 events over 0s) at 2026-06-13 15:34:07.957088183 +0000 UTC
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-13 13:24:55
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 34.79.184.171 (171.184.79.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.79.184.171 (171.184.79.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 09:24:50.287636 2026] [security2:error] [pid 29074:tid 29074] [client 34.79.184.171:41752] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||humans2humans.org.asfmglobal.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "humans2humans.org.asfmglobal.com"] [uri "/.config/gcloud/credentials.db"] [unique_id "ai1aIpqnsD-Y6F1J9LxGEgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-13 12:21:51
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 34.79.184.171 (171.184.79.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.79.184.171 (171.184.79.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 08:21:45.045633 2026] [security2:error] [pid 30331:tid 30331] [client 34.79.184.171:59510] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ulrike-petri.de|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ulrike-petri.de"] [uri "/.config/gcloud/credentials.db"] [unique_id "ai1LWc6XRBmWffpn0uRJvwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-06-13 11:46:44
(1 week ago)
20 attempts against mh_ha-misbehave-ban on hail
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฟ
Antinson
2026-06-13 10:31:45
(1 week ago)
High error rate and elevated request volume targeting cPanel servers
Bad Web Bot
๐ง๐ช
cmbplf
2026-06-13 09:40:12
(1 week ago)
141 requests with url.path *compose.yml
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-13 09:24:07
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 34.79.184.171 (171.184.79.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.79.184.171 (171.184.79.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 05:24:03.207409 2026] [security2:error] [pid 10813:tid 10813] [client 34.79.184.171:47442] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.myshineart.com.sobhrach.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.myshineart.com.sobhrach.com"] [uri "/.config/gcloud/credentials.db"] [unique_id "ai0hs6u69xoi6qnWk5zUmgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-06-13 09:20:43
(1 week ago)
Excessive 404/403 errors
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-13 07:47:33
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.79.184.171 (171.184.79.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.79.184.171 (171.184.79.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 03:47:28.420639 2026] [security2:error] [pid 1866:tid 1866] [client 34.79.184.171:42914] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/config/config.yml" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.robtown.com"] [uri "/config/config.yml"] [unique_id "ai0LEIzNWYZbEwHDU1NoZwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-13 07:08:10
(1 week ago)
Multiple web server 400 error codes from same source ip
Web App Attack
๐บ๐ธ
mnsf
2026-06-13 07:06:35
(1 week ago)
Too many Status 40X (11)
Scanning/Probing (61)
Request Overload (383)
Brute-Force
Web App Attack
๐ฎ๐น
VHosting
2026-06-13 04:55:03
(1 week ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack