๐ฒ๐พ
Rizzy
2026-09-22 15:34:39
(1 minute ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ช๐ธ
robotstxt
2026-09-22 15:20:36
(15 minutes ago)
34.79.216.182 - - [22/Sep/2026:15:19:58 +0000] "GET /.env.old HTTP/2.0" 403 49641 "-" "Mozilla/5.0 A ...
show more
34.79.216.182 - - [22/Sep/2026:15:19:58 +0000] "GET /.env.old HTTP/2.0" 403 49641 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.4; +https://openai.com/gptbot" "-"
34.79.216.182 - - [22/Sep/2026:15:19:59 +0000] "GET /config/.env HTTP/2.0" 403 49633 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)" "-"
34.79.216.182 - - [22/Sep/2026:15:19:59 +0000] "GET /api/.env HTTP/2.0" 403 49642 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)" "-"
34.79.216.182 - - [22/Sep/2026:15:19:59 +0000] "GET /backend/.env HTTP/2.0" 403 49577 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )" "-"
34.79.216.182 - - [22/Sep/2026:15:19:59 +0000] "GET /admin/.env HTTP/2.0" 403 49639 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )" "-"
...
show less
Web App Attack
Anonymous
2026-09-22 15:04:51
(31 minutes ago)
Banned by Fail2Ban on server
Web App Attack
๐ฉ๐ช
bazter.pro
2026-09-22 15:03:17
(32 minutes ago)
Fail2Ban: apache-ratelimit - 20 failures
Port Scan
Bad Web Bot
Web App Attack
Anonymous
2026-09-22 15:02:08
(33 minutes ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-09-22 14:07:21
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 34.79.216.182 (182.216.79.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.79.216.182 (182.216.79.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 10:07:16.758209 2026] [security2:error] [pid 17724:tid 17724] [client 34.79.216.182:41612] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||empratec.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "empratec.com"] [uri "/z9x8c7v6b5-debug-trigger-empratec.com"] [unique_id "arKLlOGHHUrast8QpVWwqAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-09-22 13:50:07
(1 hour ago)
[TueSep2215:50:03.9968652026][security2:error][pid834632:tid834647][client34.79.216.182:0]ModSecurit ...
show more
[TueSep2215:50:03.9968652026][security2:error][pid834632:tid834647][client34.79.216.182:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Stringmatchwithin\".asa/.asax/.ascx/.backup/.bak/.bat/.cdx/.cer/.cfg/.cmd/.com/.config/.conf/.cs/.csproj/.csr/.dat/.db/.dbf/.dll/.dos/.htr/.htw/.ida/.idc/.idq/.inc/.ini/.key/.licx/.lnk/.log/.mdb/.old/.pass/.pdb/.pol/.printer/.pwd/.rdb/.resources/.resx/.sql/.swp/.sys/.vb/.vbs/.vbproj/.vsdisco/.webinfo/.xsx/\"atTX:extension.[file\"/etc/apache2/conf.d/modsec_rules/00_asl_zz_strict.conf\"][line\"91\"][id\"390716\"][rev\"2\"][msg\"Atomicorp.comWAFRules:URLfileextensionisrestrictedbypolicy\"][data\".com\"][severity\"ERROR\"][hostname\"enricoalbertini.com\"][uri\"/z9x8c7v6b5-debug-trigger-enricoalbertini.com\"][unique_id\"arKHiyZMehDtdUUT0LDqJwAAAAQ\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
oralunal
2026-09-22 13:49:18
(1 hour ago)
IP banned by Fail2Ban in jail ente-suss ente.com-ssl_log mvfnds
...
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 13:34:22
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.79.216.182 (182.216.79.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.79.216.182 (182.216.79.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 09:34:19.221224 2026] [security2:error] [pid 6211:tid 6211] [client 34.79.216.182:35542] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ericadamsdesign.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ericadamsdesign.com"] [uri "/z9x8c7v6b5-debug-trigger-ericadamsdesign.com"] [unique_id "arKD21PZpUyC2D_djUJurAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐น๐ท
eryilmaz
2026-09-22 13:28:22
(2 hours ago)
Automated attack blocked by eryilmaz WAF/defense engine (level 1, source: auto, path: /signup)
Web App Attack
Hacking
๐ฟ๐ฆ
vanderhost
2026-09-22 13:06:19
(2 hours ago)
[Laravel HoneypotPlus] Automated report - Honeypot access detected on path: /config/firebase-admin.j ...
show more
[Laravel HoneypotPlus] Automated report - Honeypot access detected on path: /config/firebase-admin.json via rule: /config
show less
Web App Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-22 12:46:00
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.79.216.182 (182.216.79.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.79.216.182 (182.216.79.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 08:45:53.448846 2026] [security2:error] [pid 13719:tid 13817] [client 34.79.216.182:48832] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||exedesalesteam.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "exedesalesteam.com"] [uri "/z9x8c7v6b5-debug-trigger-exedesalesteam.com"] [unique_id "arJ4gScExj3DI8hY61HheQAAAkM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 12:23:52
(3 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.79.216.182 (182.216.79.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:949110) triggered by 34.79.216.182 (182.216.79.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 08:23:47.210351 2026] [security2:error] [pid 4154:tid 4154] [client 34.79.216.182:50130] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "faimrepsonline.com"] [uri "/z9x8c7v6b5-debug-trigger-faimrepsonline.com"] [unique_id "arJzU7_p7reh6qIlURIqHAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 11:53:13
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.79.216.182 (182.216.79.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.79.216.182 (182.216.79.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 07:53:06.699110 2026] [security2:error] [pid 8180:tid 8180] [client 34.79.216.182:41138] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||femalestripperslaquinta.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "femalestripperslaquinta.com"] [uri "/z9x8c7v6b5-debug-trigger-femalestripperslaquinta.com"] [unique_id "arJsIvvhsvrG9c5ceyjZcgAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 11:27:24
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.79.216.182 (182.216.79.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.79.216.182 (182.216.79.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 07:27:19.288109 2026] [security2:error] [pid 17045:tid 17045] [client 34.79.216.182:39188] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||fingershrine.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "fingershrine.com"] [uri "/z9x8c7v6b5-debug-trigger-fingershrine.com"] [unique_id "arJmF1mNf6wN9K1MxlRLqgAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack