๐ฟ๐ฆ
conure.sh
2026-09-21 03:35:33
(3 hours ago)
csagent: score 20.8: 404 noise floor x3, secrets grab x2; 1 domain(s) in 0s
Web App Attack
๐น๐ญ
thaizone.com
2026-09-21 03:26:45
(3 hours ago)
Hacking attempts against websites (D1) #1
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-21 02:47:46
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.80.217.0 (0.217.80.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.80.217.0 (0.217.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 22:47:42.079411 2026] [security2:error] [pid 24796:tid 24796] [client 34.80.217.0:59568] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||jazzclubla.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "jazzclubla.com"] [uri "/z9x8c7v6b5-debug-trigger-jazzclubla.com"] [unique_id "arCazoJl2Izz9a-1ja-gKQAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-21 00:56:30
(6 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐ณ๐ฑ
Alt255
2026-09-21 00:10:20
(7 hours ago)
[ti-05al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-05al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.80.217.0 - - [21/Sep/2026:02:10:06 +0200] "GET /.aws/credentials HTTP/2.0" 401 532 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1)"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 23:59:47
(7 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.80.217.0 (0.217.80.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.80.217.0 (0.217.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 19:59:39.913857 2026] [security2:error] [pid 2052:tid 2052] [client 34.80.217.0:58634] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.barryherbach.com|F|2"] [data ".barryherbach.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.barryherbach.com"] [uri "/z9x8c7v6b5-debug-trigger-mail.barryherbach.com"] [unique_id "arBzazbbo8HaKgyAyGPBmwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ฌ
Cloudkul Cloudkul
2026-09-20 23:36:25
(7 hours ago)
Attempted Brute Force on our application
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 23:27:59
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.80.217.0 (0.217.80.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.217.0 (0.217.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 19:27:54.401149 2026] [security2:error] [pid 17524:tid 17524] [client 34.80.217.0:43344] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bizzybeejunkremoval.com"] [uri "/.env"] [unique_id "arBr-rcZQtwBswrr8CqN5gAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-20 22:44:27
(8 hours ago)
XSS Attempt
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-20 22:20:09
(9 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.80.217.0 (0.217.80.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.80.217.0 (0.217.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 18:20:04.357546 2026] [security2:error] [pid 27589:tid 27589] [client 34.80.217.0:60470] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bigheartskitchen.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bigheartskitchen.com"] [uri "/z9x8c7v6b5-debug-trigger-bigheartskitchen.com"] [unique_id "arBcFIii73G93gqSFUn8wgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-20 21:53:49
(9 hours ago)
IP matched detection query 50 and more bad rqs apache.
Hacking
Bad Web Bot
Brute-Force
Web App Attack
๐ฉ๐ช
updown.io
2026-09-20 21:35:01
(9 hours ago)
{"level":"info","ts":1789940094.1271183,"logger":"http.log.access.log1","msg":"handled request","req ...
show more
{"level":"info","ts":1789940094.1271183,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.80.217.0","remote_port":"36762","client_ip":"34.80.217.0","proto":"HTTP/2.0","method":"GET","host":"status.apifreaks.com","uri":"/__/firebase/init.json","headers":{"X-Nextjs-Data":["1"],"Accept-Encoding":["gzip"],"User-Agent":["Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)"],"Accept":["*/*"],"X-Middleware-Subrequest":["src/middleware:nowaf:src/middleware:src/middleware:src/middleware:src/middleware:middleware:middleware:nowaf:middleware:middleware:middleware:pages/_middleware"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"h2","server_name":"status.apifreaks.com","ech":false}},"bytes_read":0,"user_id":"","duration":0.000817311,"size":0,"status":429,"resp_headers":{"Server":["Caddy"],"Alt-Svc":["h3=\":443\"; ma=2592000"],"Retry-After":["1"]}}
{"level":"info","ts":1789940094.138079,"logger":"http.log.access.l
...
show less
DDoS Attack
Web App Attack
Anonymous
2026-09-20 21:33:46
(9 hours ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 21:18:00
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.80.217.0 (0.217.80.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.217.0 (0.217.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 17:17:54.253717 2026] [security2:error] [pid 12951:tid 12951] [client 34.80.217.0:36190] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bigredgraphicdesign.com"] [uri "/backend/.env"] [unique_id "arBNguX3qBarcLyGi85PCgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐น๐ญ
thaizone.com
2026-09-20 21:02:18
(10 hours ago)
Brute Force Attack on a Web Resources (probe) #1
DDoS Attack
Web Spam
Brute-Force
Web App Attack