🇩🇪
FD-IX
2026-09-11 01:33:13
(2 minutes ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇫🇷
Baking333
2026-09-11 01:05:57
(29 minutes ago)
[redacted] 34.80.115.186 - - [11/Sep/2026:02:05:56 +0100] "GET /.git/HEAD HTTP/1.1" 302 6778 0/59460 ...
show more
[redacted] 34.80.115.186 - - [11/Sep/2026:02:05:56 +0100] "GET /.git/HEAD HTTP/1.1" 302 6778 0/59460 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; OAI-SearchBot/1.0; +https://[redacted]/searchbot)" [redacted] 34.80.115.186 - - [11/Sep/2026:02:05:56 +0100] "GET /.git/config HTTP/1.1" 302 6778 0/57516 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://[redacted]/)"
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 00:52:06
(43 minutes ago)
(mod_security) mod_security (id:210730) triggered by 34.80.115.186 (186.115.80.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.80.115.186 (186.115.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 20:52:00.222482 2026] [security2:error] [pid 27488:tid 27488] [client 34.80.115.186:38090] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||dismain.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "dismain.com"] [uri "/rclone.conf"] [unique_id "aqNQsIdQKjS3Sfyq9cpL7gAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-11 00:50:59
(44 minutes ago)
Multiple WAF Violations
Web App Attack
🇺🇸
Mundo Bueno
2026-09-11 00:16:16
(1 hour ago)
[ISILIA Protection v2.1] Tentative d'accès: /config/env/aws_credentials.env | Pays: TW | UA: Mozilla ...
show more
[ISILIA Protection v2.1] Tentative d'accès: /config/env/aws_credentials.env | Pays: TW | UA: Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/)
show less
Hacking
Web App Attack
🇷🇴
iulianh
2026-09-11 00:13:20
(1 hour ago)
80,443
Brute-Force
SSH
🇺🇸
TPI-Abuse
2026-09-10 23:42:12
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 34.80.115.186 (186.115.80.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.80.115.186 (186.115.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 19:42:05.515679 2026] [security2:error] [pid 29012:tid 29012] [client 34.80.115.186:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||cloudex.link|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "cloudex.link"] [uri "/rclone.conf"] [unique_id "aqNATddPyDFd9UPMkgLMcgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-10 23:32:10
(2 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-10 22:52:24
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.80.115.186 (186.115.80.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.115.186 (186.115.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 18:52:20.512916 2026] [security2:error] [pid 1417312:tid 1417312] [client 34.80.115.186:44278] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "caferutadelaseda.com"] [uri "/.git/HEAD"] [unique_id "aqM0pH69ql2IpwrjrUvz5wAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-10 21:50:47
(3 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇩🇪
LRob
2026-09-10 21:33:08
(4 hours ago)
Declared crawler ignoring robots.txt and the refusals it is given | ua: Mozilla/5.0 AppleWebKit/537. ...
show more
Declared crawler ignoring robots.txt and the refusals it is given | ua: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] ) | path: /.aws/credentials (+3 more) | 2026-09-10 21:33 UTC
show less
Bad Web Bot
🇸🇪
vaia.cloud
2026-09-10 21:25:02
(4 hours ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
🇩🇪
big-cloud.nl
2026-09-10 21:05:22
(4 hours ago)
Try to access /.git/HEAD
Web App Attack
🇮🇹
VHosting
2026-09-10 20:40:04
(4 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇨🇭
lufi
2026-09-10 19:59:18
(5 hours ago)
2026-09-10 21:59:18 34.80.115.186: blacklistedPath: /.svn/entries
...
Web Spam
Brute-Force
Hacking
Web App Attack