Anonymous
2026-10-01 05:07:02
(32 minutes ago)
Automated web scanner. Requested suspicious paths: /lib/terminal-xhr.php | /dist/manifest.json | /di ...
show more
Automated web scanner. Requested suspicious paths: /lib/terminal-xhr.php | /dist/manifest.json | /dist/.vite/manifest.json | /build/manifest.json | /config.php.bak | /config/env/aws_credentials.env | /.vite/manifest.json. UTC: 2026-10-01 04:13:43.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 04:46:20
(52 minutes ago)
(mod_security) mod_security (id:210730) triggered by 34.80.108.59 (59.108.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.80.108.59 (59.108.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 00:46:10.610788 2026] [security2:error] [pid 27962:tid 27962] [client 34.80.108.59:60942] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||drumfever.okwellbeing.com|F|2"] [data ".okwellbeing.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "drumfever.okwellbeing.com"] [uri "/z9x8c7v6b5-debug-trigger-drumfever.okwellbeing.com"] [unique_id "ar3lksccMod0ZUzItKqi_wAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
itsolon
2026-10-01 04:41:58
(57 minutes ago)
[01/Oct/2026:06:41:58 +0200] 179082971871.972293 34.80.108.59 48336 217.154.7.177 443
[01/Oct/2026:0 ...
show more
[01/Oct/2026:06:41:58 +0200] 179082971871.972293 34.80.108.59 48336 217.154.7.177 443
[01/Oct/2026:06:41:58 +0200] 17908297188.407274 34.80.108.59 48336 217.154.7.177 443
[01/Oct/2026:06:41:58 +0200] 179082971854.024788 34.80.108.59 48336 217.154.7.177 443
[01/Oct/2026:06:41:58 +0200] 179082971887.576045 34.80.108.59 48336 217.154.7.177 443
[01/Oct/2026:06:41:58 +0200] 179082971839.956543 34.80.108.59 48336 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-01 04:28:56
(1 hour ago)
[ti-17al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apac ...
show more
[ti-17al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apache-404. Example: 34.80.108.59 - - [01/Oct/2026:06:28:39 +0200] "GET /gkyam3s4y738wiwn4405 HTTP/2.0" 404 98304 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36"
34.80.108.59 - - [01/Oct/2026:06:28:40 +0200] "GET /z9x8c7v6b5-debug-trigger-dpkto.mzoem.com HTTP/2.0" 404 101606 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
34.80.108.59 - - [01/Oct/2026:06:28:40 +0200] "GET /0u3mpbpcdpjq8nuxbk8w HTTP/2.0" 404 101606 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
34.80.108.59 - - [01/Oct/2026:06:28:40 +0200] "GET /model/info HTTP/2.0" 404 101623 "-" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)"
3
...
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-01 03:06:48
(2 hours ago)
[cb-13al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[cb-13al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.80.108.59 - - [01/Oct/2026:05:06:28 +0200] "GET /.env.php.bak HTTP/2.0" 404 1855 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot)"
...
show less
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-09-30 23:06:31
(6 hours ago)
2.948 requests from abuseipdb.com blacklisted IP (1yr10mos3w)
Brute-Force
Bad Web Bot
๐ณ๐ฑ
debestelapp
2026-09-30 20:50:07
(8 hours ago)
Web App Attack
Anonymous
2026-09-30 16:52:58
(12 hours ago)
XSS Attempt
Hacking
Anonymous
2026-09-30 16:30:04
(13 hours ago)
CrowdSec decision: crowdsecurity/http-sensitive-files (origin: crowdsec)
Web App Attack
๐ฎ๐น
VHosting
2026-09-30 14:55:03
(14 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ฉ๐ช
itsolon
2026-09-30 13:55:35
(15 hours ago)
[30/Sep/2026:15:55:34 +0200] 179077653486.644116 34.80.108.59 55378 217.154.7.177 443
[30/Sep/2026:1 ...
show more
[30/Sep/2026:15:55:34 +0200] 179077653486.644116 34.80.108.59 55378 217.154.7.177 443
[30/Sep/2026:15:55:34 +0200] 179077653459.546764 34.80.108.59 55378 217.154.7.177 443
[30/Sep/2026:15:55:34 +0200] 179077653460.075037 34.80.108.59 55378 217.154.7.177 443
[30/Sep/2026:15:55:35 +0200] 179077653548.720896 34.80.108.59 55378 217.154.7.177 443
[30/Sep/2026:15:55:35 +0200] 179077653569.045942 34.80.108.59 55378 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 13:46:51
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.80.108.59 (59.108.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.108.59 (59.108.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 09:46:47.912899 2026] [security2:error] [pid 25836:tid 25850] [client 34.80.108.59:43094] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.dukesandgannon.com"] [uri "/wp-config.php.bak"] [unique_id "ar0Sx2WaSoqWJhCSQZztnwAAAUw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-30 12:50:28
(16 hours ago)
Excessive multi-domain requests
Brute-Force
๐ง๐ฌ
HighWay
2026-09-30 12:39:40
(16 hours ago)
34.80.108.59 - - [30/Sep/2026:12:39:24 +0000] "GET /21bntkbfo0xqvyib1avs HTTP/1.1" 404 4759 "-" "Moz ...
show more
34.80.108.59 - - [30/Sep/2026:12:39:24 +0000] "GET /21bntkbfo0xqvyib1avs HTTP/1.1" 404 4759 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)"
34.80.108.59 - - [30/Sep/2026:12:39:25 +0000] "GET /model/info HTTP/1.1" 404 4758 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot"
34.80.108.59 - - [30/Sep/2026:12:39:25 +0000] "GET /l4jg0s2av6diq0mlmzv0 HTTP/1.1" 404 4758 "-" "Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)"
34.80.108.59 - - [30/Sep/2026:12:39:25 +0000] "POST /graphql HTTP/1.1" 404 770 "https://vhelectronics.com" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36"
34.80.108.59 - - [30/Sep/2026:12:39:25 +0000] "POST /icecoder/lib/terminal-xhr.php HTTP/1.1" 404 4758 "-" "Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)"
34.80.108.59 - - [30/Sep/2026:12:39:25 +0000] "GET /model/info HTTP/1.1" 404 7
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 12:30:36
(17 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.80.108.59 (59.108.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.80.108.59 (59.108.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 08:30:33.800686 2026] [security2:error] [pid 27691:tid 27691] [client 34.80.108.59:41658] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||dudleyanddudley.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "dudleyanddudley.com"] [uri "/z9x8c7v6b5-debug-trigger-dudleyanddudley.com"] [unique_id "ar0A6ZDO73N7-wLc2IBmswAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack