๐ฉ๐ช
NetShield-DE
2026-10-11 04:07:51
(3 hours ago)
Auto-report via Fail2Ban aggregation. IP observed in jails: abuseipdb.
Events: 1. First: 2026-10-11T ...
show more
Auto-report via Fail2Ban aggregation. IP observed in jails: abuseipdb.
Events: 1. First: 2026-10-11T06:07:02+0200. Last: 2026-10-11T06:07:02+0200.
Samples:
- 2026-10-11 05:34:44,935 fail2ban.actions [858]: NOTICE [abuseipdb] Ban 34.81.121.228
show less
Web App Attack
๐ซ๐ท
security.rdmc.fr
2026-10-11 03:17:01
(4 hours ago)
Web App Attack
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-11 02:34:42
(5 hours ago)
[cb-13al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apac ...
show more
[cb-13al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apache-404. Example: 34.81.121.228 - - [11/Oct/2026:04:34:32 +0200] "GET /dist/.vite/manifest.json HTTP/2.0" 404 1878 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
34.81.121.228 - - [11/Oct/2026:04:34:32 +0200] "GET /.vite/manifest.json HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
34.81.121.228 - - [11/Oct/2026:04:34:32 +0200] "GET /z9x8c7v6b5-debug-trigger-adminer.dutchtallship.com HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)"
34.81.121.228 - - [11/Oct/2026:04:34:32 +0200] "GET /static../.env HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (Macintosh; In
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-11 01:40:46
(6 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.81.121.228 (228.121.81.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.81.121.228 (228.121.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 21:40:39.559800 2026] [security2:error] [pid 27854:tid 27854] [client 34.81.121.228:43226] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||pyxelstudios.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "pyxelstudios.com"] [uri "/z9x8c7v6b5-debug-trigger-pyxelstudios.com"] [unique_id "asrpFyDjRTNutrmDt7dmWAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
robotstxt
2026-10-11 01:38:23
(6 hours ago)
34.81.121.228 - - [11/Oct/2026:01:37:28 +0000] "GET /.vite/manifest.json HTTP/2.0" 403 34891 "https: ...
show more
34.81.121.228 - - [11/Oct/2026:01:37:28 +0000] "GET /.vite/manifest.json HTTP/2.0" 403 34891 "https://outcomes10.com/.vite/manifest.json" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36" "-" edge="34.81.121.228"
34.81.121.228 - - [11/Oct/2026:01:37:28 +0000] "GET /dist/.vite/manifest.json HTTP/2.0" 403 34976 "https://outcomes10.com/dist/.vite/manifest.json" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36" "-" edge="34.81.121.228"
34.81.121.228 - - [11/Oct/2026:01:37:28 +0000] "GET /dist/manifest.json HTTP/2.0" 403 34998 "https://outcomes10.com/dist/manifest.json" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36" "-" edge="34.81.121.228"
34.81.121.228 - - [11/Oct/2026:01:37:28 +0000] "GET /z9x8c7v6b5-debug-trigger-outcomes10.com HTTP/2.0" 403 36717 "https://outcomes10.com/z9x8c7v6b5-debug-trigger
...
show less
Web App Attack
๐บ๐ธ
kosada.com
2026-10-11 01:26:54
(6 hours ago)
Repeated exploit attempts, for example: /api/graphql {x22queryx22:x22{ __schema { types { name field ...
show more
Repeated exploit attempts, for example: /api/graphql {x22queryx22:x22{ __schema { types { name fields { name args { name defaultValue } } } } }x22} (HTTP/2.0 port 443, user agent: "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36")
show less
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2026-10-11 01:23:49
(6 hours ago)
(web_sensitive_file) srv103 Sensitive file probe (.env/.git/backup) 34.81.121.228 (TW/Taiwan/228.121 ...
show more
(web_sensitive_file) srv103 Sensitive file probe (.env/.git/backup) 34.81.121.228 (TW/Taiwan/228.121.81.34.bc.googleusercontent.com): 2 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-11 01:16:10
(6 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.81.121.228 (228.121.81.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.81.121.228 (228.121.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 21:16:02.689071 2026] [security2:error] [pid 2099:tid 2099] [client 34.81.121.228:44622] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||flyingdodostudio.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "flyingdodostudio.com"] [uri "/z9x8c7v6b5-debug-trigger-flyingdodostudio.com"] [unique_id "asrjUhh7nsHK1qcBbHWCdQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-11 00:56:07
(6 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.81.121.228 (228.121.81.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.81.121.228 (228.121.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 20:56:03.333040 2026] [security2:error] [pid 4428:tid 4428] [client 34.81.121.228:45114] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ellavandeven.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ellavandeven.com"] [uri "/z9x8c7v6b5-debug-trigger-ellavandeven.com"] [unique_id "asreoxExDDHNtLn8r6LyqAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
bensmithurst
2026-10-11 00:55:52
(6 hours ago)
34.81.121.228 - - [11/Oct/2026:00:55:51 +0000] "GET /@fs/..%2f..%2f..%2f..%2f..%2fproc/self/environ ...
show more
34.81.121.228 - - [11/Oct/2026:00:55:51 +0000] "GET /@fs/..%2f..%2f..%2f..%2f..%2fproc/self/environ HTTP/1.1" 400 150 "-" "-"
34.81.121.228 - - [11/Oct/2026:00:55:52 +0000] "GET /@fs/..%2f..%2f..%2f..%2f..%2froot/.env HTTP/1.1" 400 150 "-" "-"
34.81.121.228 - - [11/Oct/2026:00:55:52 +0000] "GET /@fs/..%2f..%2f..%2f..%2f..%2froot/.env HTTP/1.1" 400 150 "-" "-"
... [host=LAN***]
show less
Web App Attack
๐ซ๐ท
masterguru
2026-10-11 00:21:32
(7 hours ago)
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .backup/ ...
show more
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .compositefont/ .config/ .conf/ .crt/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dist/ .dll/ .dos/ .dpkg-dist/ .drv/ .gadget/ .hta/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .inf/ .ini/ .jse/ .key/ .licx/ .lnk/ .log/ .mdb/ .msc/ .ocx/ .old/ .pass/ .pdb/ .pfx/ .pif/ .pem/ .pol/ .prf/ .printer/ .pwd/ .rdb/ .rdp/ .reg/ .resources/ .resx/ .scr/ .sct/ .shs/ .sql/ .swp/ .sys/ .tlb/ .tmp/ .url/ .vb/ .vbe/ .vbs/ .vbproj/ .vsdisco/ .vxd/ .webinfo/ .ws/ .wsc/ .wsf/ .wsh/ .xsd/ .xsx/" at TX:extension. (920440-195)
show less
Hacking
Anonymous
2026-10-11 00:10:11
(7 hours ago)
34.81.121.228 - - [10/Oct/2026:19:10:04 -0500] "GET /.env.production HTTP/1.1" 403 199 "-" "Mozilla/ ...
show more
34.81.121.228 - - [10/Oct/2026:19:10:04 -0500] "GET /.env.production HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 34.81.121.228
34.81.121.228 - - [10/Oct/2026:19:10:04 -0500] "GET /.env.local HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)" 34.81.121.228
34.81.121.228 - - [10/Oct/2026:19:10:05 -0500] "GET /.env.backup HTTP/1.1" 403 199 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)" 34.81.121.228
34.81.121.228 - - [10/Oct/2026:19:10:05 -0500] "GET /.env.bak HTTP/1.1" 403 199 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )" 34.81.121.228
34.81.121.228 - - [10/Oct/2026:19:10:05 -0500] "GET /.env.old HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)" 34.81.121.228
34.81.121.228
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Vegascosmetics
2026-10-11 00:08:39
(7 hours ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after matched multi-pattern attack signatur ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after matched multi-pattern attack signature. Evidence: AttackPattern: /\.vite/ (Match: /.vite/)
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-11 00:03:51
(7 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.81.121.228 (228.121.81.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.81.121.228 (228.121.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 20:03:45.323851 2026] [security2:error] [pid 15615:tid 15615] [client 34.81.121.228:53956] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||elenacampo.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "elenacampo.com"] [uri "/z9x8c7v6b5-debug-trigger-elenacampo.com"] [unique_id "asrSYbWw_no_ahyrdy8SegAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐น
Evag Touf
2026-10-10 23:22:17
(8 hours ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 34.81.121.228 (TW/Ta ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 34.81.121.228 (TW/Taiwan/228.121.81.34.bc.googleusercontent.com)
show less
Bad Web Bot