๐ฟ๐ฆ
conure.sh
2026-09-23 12:13:54
(2 days ago)
csagent: score 17.2: 404 noise floor x29, secrets grab x1; 1 domain(s) in 3s
Web App Attack
๐ฎ๐ณ
evicky2002
2026-09-23 06:00:01
(3 days ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-09-22 22:39:57
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 34.80.38.243 (243.38.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.80.38.243 (243.38.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 18:39:51.096403 2026] [security2:error] [pid 27234:tid 27234] [client 34.80.38.243:40034] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.be4ventures.com|F|2"] [data ".be4ventures.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.be4ventures.com"] [uri "/z9x8c7v6b5-debug-trigger-www.be4ventures.com"] [unique_id "arMDt2SZwqHevCrbBBX5kAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Stara
2026-09-22 21:09:53
(3 days ago)
ModSecurity detected web attack - .env/config probing or SQLi/Code injection (Rule 949110)
Brute-Force
Hacking
Web App Attack
Anonymous
2026-09-22 19:53:28
(3 days ago)
Blocked by ModSec and CSF
Port Scan
๐บ๐ธ
TPI-Abuse
2026-09-22 19:44:54
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.80.38.243 (243.38.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.38.243 (243.38.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 15:44:48.731609 2026] [security2:error] [pid 12832:tid 12832] [client 34.80.38.243:44060] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "brandsmedia.com"] [uri "/wp-config.php.bak"] [unique_id "arLasGX7YhYxNmTo0cZsiQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-22 19:43:51
(3 days ago)
34.80.38.243 - - [22/Sep/2026:21:43:49 +0200] "GET / HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Macintosh; ...
show more
34.80.38.243 - - [22/Sep/2026:21:43:49 +0200] "GET / HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
34.80.38.243 - - [22/Sep/2026:21:43:49 +0200] "GET /login HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
34.80.38.243 - - [22/Sep/2026:21:43:50 +0200] "GET /signup HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
34.80.38.243 - - [22/Sep/2026:21:43:50 +0200] "POST / HTTP/1.1" 403 124 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)"
34.80.38.243 - - [22/Sep/2026:21:43:50 +0200] "GET /f1fqv4c6bsan96zbugrw HTTP/1.1" 403 124 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )"
34.80.38.243 - - [22/Sep/2026:21:43:50 +0200] "GET /user/logi
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-09-22 19:29:50
(3 days ago)
This address declares itself a crawler and keeps requesting pages after being refused (HTTP 403/429) ...
show more
This address declares itself a crawler and keeps requesting pages after being refused (HTTP 403/429) and told to stop by robots.txt. A crawler that ignores refusals costs our servers capacity for nothing and is treated as abusive; blocked. Please make it honour robots.txt and the refusals it is given. | ua: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] ) | path: /p9qec5o4cathjde5zadx (+6 more) | 2026-09-22 19:29 UTC
show less
Bad Web Bot
๐บ๐ธ
rsa
2026-09-22 19:17:00
(3 days ago)
GET /env.bak HTTP/2.0
DDoS Attack
Exploited Host
Web App Attack
๐ฆ๐บ
QT
2026-09-22 19:05:19
(3 days ago)
Website hack attempted at 2026-09-23 05:05:17 +1000
Web App Attack
๐ฌ๐ง
poundawebsiteltd
2026-09-22 18:48:57
(3 days ago)
Malicious activity in general-malicious. Evidence: (apache_probe) Failed Access (403/404) 34.80.38.2 ...
show more
Malicious activity in general-malicious. Evidence: (apache_probe) Failed Access (403/404) 34.80.38.243 (TW/Taiwan/[REDACTED_DOMAIN]): 20 in the last 3600 secs | UA: (apache_probe) Failed Access (403/404) 34.80.38.243 (TW/Taiwan/243.38.80.34.bc.googleusercontent.com): 20 in the last 3600 secs
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 17:53:40
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 34.80.38.243 (243.38.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.80.38.243 (243.38.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 13:53:35.574715 2026] [security2:error] [pid 22955:tid 22955] [client 34.80.38.243:58000] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||cayman-boat-registration.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "cayman-boat-registration.com"] [uri "/z9x8c7v6b5-debug-trigger-cayman-boat-registration.com"] [unique_id "arLAn2rpgStumbCoQMQ_iQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
CoreTech srl
2026-09-22 17:38:56
(3 days ago)
cloudlinux2 fail2ban: 2026-09-22 19:34:16,267 fail2ban.actions [1598]: NOTICE [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-09-22 19:34:16,267 fail2ban.actions [1598]: NOTICE [plesk-wordpress] Unban 172.98.33.229cloudlinux2 fail2ban: 2026-09-22 19:35:01,902 fail2ban.filter [1598]: INFO [plesk-wordpress] Found 172.98.33.224 - 2026-09-22 19:35:01cloudlinux2 fail2ban: 2026-09-22 19:37:10,337 fail2ban.filter [1598]: INFO [plesk-wordpress] Found 172.245.102.55 - 2026-09-22 19:37:09cloudlinux2 fail2ban: 2026-09-22 19:38:16,074 fail2ban.filter [1598]: INFO [plesk-modsecurity] Found 34.80.38.243 - 2026-09-22 19:38:15cloudlinux2 fail2ban: 2026-09-22 19:38:18,101 fail2ban.filter [1598]: INFO [plesk-modsecurity] Found 34.80.38.243 - 2026-09-22 19:38:18cloudlinux2 fail2ban: 2026-09-22 19:38:18,456 fail2ban.filter [1598]: INFO [recidive] Found 34.80.38.243 - 2026-09-22 19:38:18cloudlinux2 fail2ban: 2026-09-22 19:38:17,733 fail2ban.filter [1598]: INFO [plesk-modsecurity] Found 34.80.38.243 - 2026-09-22 19:38:17cloudlinux2 fail2ban: 2026-09-22 19
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 16:22:16
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 34.80.38.243 (243.38.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.80.38.243 (243.38.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 12:22:12.183764 2026] [security2:error] [pid 23551:tid 23551] [client 34.80.38.243:49710] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||clustershow.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "clustershow.com"] [uri "/z9x8c7v6b5-debug-trigger-clustershow.com"] [unique_id "arKrNGKy_ZM0eUrMlggQmgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 15:52:36
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 34.80.38.243 (243.38.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.80.38.243 (243.38.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 11:52:31.339710 2026] [security2:error] [pid 16088:tid 16088] [client 34.80.38.243:57320] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||comobarbershop.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "comobarbershop.com"] [uri "/z9x8c7v6b5-debug-trigger-comobarbershop.com"] [unique_id "arKkP86_UR63unCbIaKcegAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack