๐ณ๐ฑ
Savvii
2026-10-11 01:41:34
(32 minutes ago)
20 attempts against mh-misbehave-ban on lunar
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-10-11 01:30:26
(43 minutes ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ณ๐ฑ
Site.eu
2026-10-11 01:14:36
(59 minutes ago)
Excessive multi-domain requests
Brute-Force
๐ฉ๐ช
Skyrider
2026-10-11 01:02:46
(1 hour ago)
crowdsecurity/http-path-traversal-probing
Web App Attack
๐บ๐ธ
JustMeHere
2026-10-11 00:35:42
(1 hour ago)
[Sat Oct 10 20:35:38.161398 2026] [security2:error] [pid 77000:tid 77034] [client 34.80.28.14:57070] ...
show more
[Sat Oct 10 20:35:38.161398 2026] [security2:error] [pid 77000:tid 77034] [client 34.80.28.14:57070] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.15.0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "yorknation.com"] [uri "/"] [unique_id "asrZ2meJgorsyfrg3auCJwAAAMY"]
...
show less
Web App Attack
๐บ๐ธ
WizardsToolkit
2026-10-10 23:55:15
(2 hours ago)
tried to access server backup files
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-10 23:54:05
(2 hours ago)
[ti-05al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-05al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.80.28.14 - - [11/Oct/2026:01:53:54 +0200] "GET /@fs/home/ubuntu/.aws/credentials?raw?? HTTP/2.0" 403 395 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )"
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-10-10 23:46:41
(2 hours ago)
34.80.28.14 - - [11/Oct/2026:07:46:40 +0800] "GET /userfiles/x?path=../../.env HTTP/1.1" 404 196 "-" ...
show more
34.80.28.14 - - [11/Oct/2026:07:46:40 +0800] "GET /userfiles/x?path=../../.env HTTP/1.1" 404 196 "-" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-10 23:36:37
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.80.28.14 (14.28.80.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.80.28.14 (14.28.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 19:36:30.257841 2026] [security2:error] [pid 16933:tid 16933] [client 34.80.28.14:51834] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||wisdomwfm.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "wisdomwfm.com"] [uri "/z9x8c7v6b5-debug-trigger-wisdomwfm.com"] [unique_id "asrL_qJlAnBtDImHgIixYgAAAGk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
palzer.IT
2026-10-10 23:32:10
(2 hours ago)
Fail2ban automatic report for plesk-apache-badbot: 34.80.28.14 - - [11/Oct/2026:01:31:37 +0200] GET ...
show more
Fail2ban automatic report for plesk-apache-badbot: 34.80.28.14 - - [11/Oct/2026:01:31:37 +0200] GET /xwb02gmlw29nippde9wn [DOMAIN_REMOVED] 303 5719 - Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; +claudebot@[DOMAIN_REMOVED])
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-10 23:15:15
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.80.28.14 (14.28.80.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.80.28.14 (14.28.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 19:15:11.015432 2026] [security2:error] [pid 1642:tid 1642] [client 34.80.28.14:60452] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||wintercypher.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "wintercypher.com"] [uri "/z9x8c7v6b5-debug-trigger-wintercypher.com"] [unique_id "asrG_61lzjuyKv3-JXxcuAAAAEU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
antlac1
2026-10-10 22:57:32
(3 hours ago)
crowdsecurity/http-path-traversal-probing
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-10 22:54:11
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.80.28.14 (14.28.80.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.80.28.14 (14.28.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 18:54:07.781112 2026] [security2:error] [pid 28122:tid 28122] [client 34.80.28.14:36990] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||winestoria.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "winestoria.com"] [uri "/z9x8c7v6b5-debug-trigger-winestoria.com"] [unique_id "asrCD6J9KApaoATbuRDu_QAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-10 22:09:02
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.80.28.14 (14.28.80.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.80.28.14 (14.28.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 18:08:55.960865 2026] [security2:error] [pid 17125:tid 17125] [client 34.80.28.14:42288] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||wilklass.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "wilklass.com"] [uri "/z9x8c7v6b5-debug-trigger-wilklass.com"] [unique_id "asq3d4c7rK2q3vGchQTu4gAAAEs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
konseptit
2026-10-10 21:42:32
(4 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.80.28.14 (TW/Taiwan/14.28.80.34.bc.g ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.80.28.14 (TW/Taiwan/14.28.80.34.bc.googleusercontent.com)
show less
SQL Injection