π³π±
homeshowdomain.nl
2026-10-02 21:59:49
(2 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-10-01.
show less
Web App Attack
SSH
Hacking
πΊπΈ
TPI-Abuse
2026-10-01 17:33:00
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 34.80.138.246 (246.138.80.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.80.138.246 (246.138.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 13:32:53.266004 2026] [security2:error] [pid 18143:tid 18143] [client 34.80.138.246:48396] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||okwellbeing.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "okwellbeing.com"] [uri "/z9x8c7v6b5-debug-trigger-okwellbeing.com"] [unique_id "ar6ZReYtT8Y-EzJn61_2SwAAACs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-01 17:14:16
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.80.138.246 (246.138.80.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.138.246 (246.138.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 13:14:12.315130 2026] [security2:error] [pid 19896:tid 19896] [client 34.80.138.246:57054] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.flyingdodopublications.com"] [uri "/static/../../../a/../../../../.env"] [unique_id "ar6U5D0tlIMIQ47MMWGOgwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¨π
zynex
2026-10-01 16:49:49
(4 days ago)
URL Probing: /static/app/.env
Web App Attack
π©πͺ
FeG Deutschland
2026-10-01 16:04:43
(4 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 248
Exploited Host
Web App Attack
Anonymous
2026-10-01 15:51:05
(4 days ago)
Multiple pen test attempts.
Web App Attack
π§π·
dominioz
2026-10-01 15:50:47
(4 days ago)
34.80.138.246 - - [01/Oct/2026:12:50:47 -0300] "GET /static../.env HTTP/1.1" 502 2120 "-" "Mozilla/5 ...
show more
34.80.138.246 - - [01/Oct/2026:12:50:47 -0300] "GET /static../.env HTTP/1.1" 502 2120 "-" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" "-"
...
show less
Bad Web Bot
Web App Attack
πΊπΈ
[email protected]
2026-10-01 13:58:55
(4 days ago)
CrowdSec ban: crowdsecurity/http-probing on auth.anomaly.cx (duration 4h)
Web App Attack
π©πͺ
rh24
2026-10-01 12:57:25
(4 days ago)
(badbots) Bad bot user-agent [redacted] from 34.80.138.246 (TW/Taiwan/246.138.80.34.bc.googleusercon ...
show more
(badbots) Bad bot user-agent [redacted] from 34.80.138.246 (TW/Taiwan/246.138.80.34.bc.googleusercontent.com)
show less
Hacking
π³π±
Alt255
2026-10-01 12:51:06
(4 days ago)
[ti-24al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apac ...
show more
[ti-24al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apache-404. Example: 34.80.138.246 - - [01/Oct/2026:14:51:02 +0200] "GET /z9x8c7v6b5-debug-trigger-ai.angelikevalster.nl HTTP/2.0" 404 2004 "-" "Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)"
34.80.138.246 - - [01/Oct/2026:14:51:02 +0200] "GET /637yuqwf5m9ab2a52xv3 HTTP/2.0" 404 2004 "-" "Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)"
34.80.138.246 - - [01/Oct/2026:14:51:02 +0200] "GET /2fc9ml556uvtya54k2i4 HTTP/2.0" 404 2004 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)"
34.80.138.246 - - [01/Oct/2026:14:51:02 +0200] "GET /model/info HTTP/2.0" 404 2004 "-" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/)"
34.80.138.246 - - [01/Oct/2026:14:51:0
...
show less
Bad Web Bot
Web App Attack
π¨π¦
Anytech
2026-10-01 12:27:06
(4 days ago)
Blocked by Conn-Monitor: env-probing
Web App Attack
Hacking
Anonymous
2026-10-01 12:00:06
(4 days ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection
πΊπΈ
TPI-Abuse
2026-10-01 11:51:30
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 34.80.138.246 (246.138.80.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.80.138.246 (246.138.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 07:51:24.301335 2026] [security2:error] [pid 3633:tid 3633] [client 34.80.138.246:44346] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||mitchellamazing.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mitchellamazing.com"] [uri "/z9x8c7v6b5-debug-trigger-mitchellamazing.com"] [unique_id "ar5JPDuJM6nuI5mzfwX4YAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-01 11:20:18
(4 days ago)
Aggressive web scan
Web App Attack
π³π±
Alt255
2026-10-01 09:45:40
(4 days ago)
[ti-11al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-11al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.80.138.246 - - [01/Oct/2026:11:45:20 +0200] "GET /static../.env HTTP/2.0" 301 277 "-" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)"
...
show less
Bad Web Bot
Web App Attack