๐ฉ๐ช
klaus_ph
2026-09-26 18:35:44
(3 hours ago)
2026-09-25 19:16:03,529 fail2ban.actions [594716]: NOTICE [ipblocklist] Ban 34.80.23.228
...
Bad Web Bot
๐ฉ๐ช
klaus_ph
2026-09-23 11:11:32
(3 days ago)
2026-09-22 23:31:59,342 fail2ban.actions [535885]: NOTICE [ipblocklist] Ban 34.80.23.228
...
Bad Web Bot
๐ฎ๐ณ
evicky2002
2026-09-22 06:00:01
(4 days ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
Anonymous
2026-09-21 22:44:49
(4 days ago)
34.80.23.228 - - [22/Sep/2026:00:44:44 +0200] "GET /config.json HTTP/1.1" 404 28675
34.80.23.228 - - ...
show more
34.80.23.228 - - [22/Sep/2026:00:44:44 +0200] "GET /config.json HTTP/1.1" 404 28675
34.80.23.228 - - [22/Sep/2026:00:44:44 +0200] "GET /constants.js HTTP/1.1" 404 30267
34.80.23.228 - - [22/Sep/2026:00:44:44 +0200] "GET /graphql HTTP/1.1" 404 30232
34.80.23.228 - - [22/Sep/2026:00:44:45 +0200] "GET /api/config HTTP/1.1" 404 28561
34.80.23.228 - - [22/Sep/2026:00:44:44 +0200] "GET /api/settings HTTP/1.1" 404 30416
34.80.23.228 - - [22/Sep/2026:00:44:45 +0200] "GET /settings.json HTTP/1.1" 404 28747
34.80.23.228 - - [22/Sep/2026:00:44:45 +0200] "GET /api/graphql HTTP/1.1" 404 28786
34.80.23.228 - - [22/Sep/2026:00:44:46 +0200] "GET /config.js HTTP/1.1" 404 30406
34.80.23.228 - - [22/Sep/2026:00:44:45 +0200] "GET /credentials.js HTTP/1.1" 404 30164
34.80.23.228 - - [22/Sep/2026:00:44:46 +0200] "GET /config.json.js HTTP/1.1" 404 30134
...
show less
Web Spam
Web App Attack
๐ธ๐ฌ
Cloudkul Cloudkul
2026-09-21 22:24:26
(4 days ago)
Attempted Brute Force on our application
Brute-Force
Web App Attack
๐จ๐ฆ
polycoda
2026-09-21 22:16:53
(4 days ago)
๐ฅ VERY AGGRESSIVE SCANNER probed over 700 inexistent files and PHP scripts in less than an hour.
Hacking
Web App Attack
๐ซ๐ฎ
paissangroup
2026-09-21 21:56:05
(5 days ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 21:34:05
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.80.23.228 (228.23.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.23.228 (228.23.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 17:34:01.338860 2026] [security2:error] [pid 9648:tid 9648] [client 34.80.23.228:36330] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.joqlawncare.com"] [uri "/.git/HEAD"] [unique_id "arGiyUbc35muqvx_nLbJXwAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
svr
2026-09-21 20:18:48
(5 days ago)
Abusive Automated Web Scanner
Web App Attack
๐ฉ๐ช
raph
2026-09-21 19:33:08
(5 days ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
๐ซ๐ท
IRISIO
2026-09-21 16:58:30
(5 days ago)
scans/SQL injection/spam posts : 511 queries
Web App Attack
SQL Injection
๐ณ๐ฑ
Mangelot Hosting
2026-09-21 16:32:29
(5 days ago)
(modsecurity) srv103 ModSecurity 34.80.23.228 (TW/Taiwan/228.23.80.34.bc.googleusercontent.com): 30 ...
show more
(modsecurity) srv103 ModSecurity 34.80.23.228 (TW/Taiwan/228.23.80.34.bc.googleusercontent.com): 30 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 16:30:11
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.80.23.228 (228.23.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.23.228 (228.23.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 12:30:04.631663 2026] [security2:error] [pid 9386:tid 9386] [client 34.80.23.228:47566] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.marlinlee.com"] [uri "/admin/.env"] [unique_id "arFbjIyKYUYm2Eq_yAZ2GQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 15:30:35
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 34.80.23.228 (228.23.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.80.23.228 (228.23.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 11:30:31.378468 2026] [security2:error] [pid 22180:tid 22180] [client 34.80.23.228:53894] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||puoci.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "puoci.com"] [uri "/z9x8c7v6b5-debug-trigger-puoci.com"] [unique_id "arFNlxkQGx1b1Wyg8SXTqgAAADw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 14:46:48
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.80.23.228 (228.23.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.23.228 (228.23.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 10:46:44.347472 2026] [security2:error] [pid 6973:tid 7212] [client 34.80.23.228:49296] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.oplconnect.com"] [uri "/.git/config"] [unique_id "arFDVOnGAoDSm12nz2RY9AAAAYs"]
show less
Brute-Force
Bad Web Bot
Web App Attack