๐ธ๐ช
Per-Erik Runebert
2026-08-09 08:39:16
(3 weeks ago)
Excessive unauthorized requests
Hacking
Anonymous
2026-08-08 20:16:13
(3 weeks ago)
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: TW, Attack patterns: Word ...
show more
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: TW, Attack patterns: WordPress scanning, Backup file probing, Cloud secrets probing
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
klaus_ph
2026-08-08 11:32:50
(3 weeks ago)
...
Bad Web Bot
๐ณ๐ด
Bots.go.to.hell
2026-08-08 07:43:22
(3 weeks ago)
This IP was detected by CrowdSec triggering custom/http-bad-crawler-ban
Web App Attack
Bad Web Bot
๐บ๐ธ
bigscoots.com
2026-08-08 07:36:44
(3 weeks ago)
(PERMBLOCK) 34.81.173.37 (TW/Taiwan/37.173.81.34.bc.googleusercontent.com) has had more than 4 temp ...
show more
(PERMBLOCK) 34.81.173.37 (TW/Taiwan/37.173.81.34.bc.googleusercontent.com) has had more than 4 temp blocks in the last 86400 secs; Ports: *; Direction: 1; Trigger: LF_PERMBLOCK_COUNT; Logs:
show less
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-08-08 06:28:51
(3 weeks ago)
(mod_security) mod_security (id:210730) triggered by 34.81.173.37 (37.173.81.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.81.173.37 (37.173.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 08 02:28:48.380678 2026] [security2:error] [pid 28024:tid 28024] [client 34.81.173.37:53182] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||_dc-mx.16e3f92f5f89.pixacast.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "_dc-mx.16e3f92f5f89.pixacast.com"] [uri "/rclone.conf"] [unique_id "anbMoGkfMUAo6l3LRsCU_QAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Baking333
2026-08-08 06:13:25
(3 weeks ago)
[redacted] 34.81.173.37 - - [08/Aug/2026:07:13:23 +0100] "GET /.gitconfig HTTP/2.0" 307 41 "-" "Mozi ...
show more
[redacted] 34.81.173.37 - - [08/Aug/2026:07:13:23 +0100] "GET /.gitconfig HTTP/2.0" 307 41 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; OAI-SearchBot/1.0; +https://[redacted]/searchbot" [redacted] 34.81.173.37 - - [08/Aug/2026:07:13:23 +0100] "GET /.git/HEAD HTTP/2.0" 307 41 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; OAI-SearchBot/1.0; +https://[redacted]/searchbot"
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-08 06:06:03
(3 weeks ago)
(mod_security) mod_security (id:210730) triggered by 34.81.173.37 (37.173.81.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.81.173.37 (37.173.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 08 02:05:59.853587 2026] [security2:error] [pid 2503:tid 2503] [client 34.81.173.37:42428] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||vittariadesign.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "vittariadesign.com"] [uri "/z9x8c7v6b5-debug-trigger-vittariadesign.com"] [unique_id "anbHR-MUZJBe0eywoZwzcwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
alferez
2026-08-08 05:41:24
(3 weeks ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack
๐ฎ๐น
mgarofano80
2026-08-08 03:49:23
(3 weeks ago)
Brute-Force
Web App Attack
๐บ๐ธ
oralunal
2026-08-08 03:40:19
(3 weeks ago)
IP banned by Fail2Ban in jail oral-suss access.log mvfnds
...
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-08-08 03:36:03
(3 weeks ago)
113 requests with url.path *.ssh/*
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-08 03:29:17
(3 weeks ago)
(mod_security) mod_security (id:210730) triggered by 34.81.173.37 (37.173.81.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.81.173.37 (37.173.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 23:29:13.032805 2026] [security2:error] [pid 556029:tid 556029] [client 34.81.173.37:43970] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.davispickering.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.davispickering.com"] [uri "/rclone.conf"] [unique_id "anaiiSoH5_KHpAxaMsU1RAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-08-08 02:09:23
(3 weeks ago)
csagent: score 19.4: secrets grab x2; 2 domain(s) in 10s
Web App Attack
Anonymous
2026-08-08 02:07:03
(3 weeks ago)
Automated web scanner. Requested suspicious paths: /.env.local | /admin/.env | /secrets.json | /z9x8 ...
show more
Automated web scanner. Requested suspicious paths: /.env.local | /admin/.env | /secrets.json | /z9x8c7v6b5-debug-trigger-api.tigzig.com | /.env.backup | /wp-json | /key.json | /config/.env | /serviceAccountKey.json | /secrets.yml | /auth/login | /login | /.env.bak | /credentials.json | /service-account.json | /console | /rclone.conf | /user/login | /graphql | /admin/login | /Dockerfile | /firebase-adminsdk.json | /.github/.env | /.htpasswd | /api/graphql | /v1/graphql | /.aws/credentials | /.docker/config.json | /firebase-service-account.json |, /backend/.env | /admin/.env | /secrets.json | /z9x8c7v6b5-debug-trigger-api.tigzig.com | /.env.back.... UTC: 2026-08-08 01:59:45.
show less
Web App Attack