๐ซ๐ฎ
paissangroup
2026-09-22 00:45:20
(2 days ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
IVski.com
2026-09-22 00:03:11
(2 days ago)
IVski WAF | Vite /@fs/ CVE-2025-30208 file-read scan
Hacking
Brute-Force
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-21 22:35:01
(2 days ago)
crowdsecurity/http-cve-2021-41773
Brute-Force
Web App Attack
๐บ๐ธ
kosada.com
2026-09-21 18:44:36
(2 days ago)
Repeated requests for suspicious nonexistent URLs, for example: /api/openapi.json (HTTP/2.0 port 443 ...
show more
Repeated requests for suspicious nonexistent URLs, for example: /api/openapi.json (HTTP/2.0 port 443, user agent: "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)")
show less
Web App Attack
๐ฏ๐ต
nhawsjones
2026-09-21 18:18:46
(2 days ago)
[Tue Sep 22 03:16:45.388308 2026] [authz_core:error] [pid 481781:tid 481781] [client 34.81.191.157:3 ...
show more
[Tue Sep 22 03:16:45.388308 2026] [authz_core:error] [pid 481781:tid 481781] [client 34.81.191.157:35954] AH01630: client denied by server configuration: /var/www/external/.htpasswd
...
show less
Brute-Force
๐บ๐ธ
IndigoRidge
2026-09-21 18:08:18
(2 days ago)
[Mon Sep 21 14:08:15.703848 2026] [authz_core:error] [pid 387624:tid 139968554989312] [client 34.81. ...
show more
[Mon Sep 21 14:08:15.703848 2026] [authz_core:error] [pid 387624:tid 139968554989312] [client 34.81.191.157:0] AH01630: client denied by server configuration: /var/www/vhosts/drannagarrett.com/error_docs/forbidden.html
[Mon Sep 21 14:08:15.721547 2026] [authz_core:error] [pid 387626:tid 139967774828288] [client 34.81.191.157:0] AH01630: client denied by server configuration: /var/www/vhosts/drannagarrett.com/httpdocs/.git
[Mon Sep 21 14:08:15.721628 2026] [authz_core:error] [pid 387626:tid 139967774828288] [client 34.81.191.157:0] AH01630: client denied by server configuration: /var/www/vhosts/drannagarrett.com/error_docs/forbidden.html
[Mon Sep 21 14:08:17.772806 2026] [authz_core:error] [pid 387624:tid 139968085227264] [client 34.81.191.157:0] AH01630: client denied by server configuration: /var/www/vhosts/drannagarrett.com/httpdocs/graphql
[Mon Sep 21 14:08:17.772906 2026] [authz_core:error] [pid 387624:tid 139968085227264] [client 34.81.191.157:0] AH01630: client denied by server c
...
show less
Web App Attack
๐ณ๐ด
Bots.go.to.hell
2026-09-21 18:03:22
(2 days ago)
This IP was detected by CrowdSec triggering custom/http-bad-crawler-ban
Web App Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-21 17:25:13
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.81.191.157 (157.191.81.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.81.191.157 (157.191.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 13:25:08.550098 2026] [security2:error] [pid 10569:tid 10634] [client 34.81.191.157:39922] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||hooknpatch.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "hooknpatch.com"] [uri "/z9x8c7v6b5-debug-trigger-hooknpatch.com"] [unique_id "arFodDVmMLw7XBF23jf9TgAAAMY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 16:27:32
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.81.191.157 (157.191.81.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.191.157 (157.191.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 12:27:26.448067 2026] [security2:error] [pid 5063:tid 5063] [client 34.81.191.157:33006] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.holidaycardsboston.com"] [uri "/.env.old"] [unique_id "arFa7keSnps-ckcOHIBuGgAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 15:30:19
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.81.191.157 (157.191.81.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.191.157 (157.191.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 11:30:11.486960 2026] [security2:error] [pid 6783:tid 6783] [client 34.81.191.157:46000] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.notearsweb.com"] [uri "/js../.env"] [unique_id "arFNgy9ucsTwPuOg4AuCEQAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-21 15:30:02
(2 days ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐ฉ๐ช
mravb
2026-09-21 15:18:48
(2 days ago)
34.81.191.157 - - [21/Sep/2026:18:18:47 +0300] "GET /@fs/src/.env?raw?? HTTP/2.0" 404 1446 "-" "Mozi ...
show more
34.81.191.157 - - [21/Sep/2026:18:18:47 +0300] "GET /@fs/src/.env?raw?? HTTP/2.0" 404 1446 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)"
...
show less
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-21 15:11:49
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.81.191.157 (157.191.81.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.81.191.157 (157.191.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 11:11:43.164925 2026] [security2:error] [pid 29709:tid 29709] [client 34.81.191.157:43044] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.hl-re.com|F|2"] [data ".hl-re.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.hl-re.com"] [uri "/z9x8c7v6b5-debug-trigger-mail.hl-re.com"] [unique_id "arFJL2GV_LslXcZo9qi__AAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
dalslab ltd
2026-09-21 14:37:46
(2 days ago)
[21/Sep/2026:16:37:41 +0200] - 405 405 - POST https ai.dalslab.com "/" [Client 34.81.191.157] [Lengt ...
show more
[21/Sep/2026:16:37:41 +0200] - 405 405 - POST https ai.dalslab.com "/" [Client 34.81.191.157] [Length 31] [Gzip -] [Sent-to 10.1.1.246] "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36" "-"
[21/Sep/2026:16:37:41 +0200] - 405 405 - POST https ai.dalslab.com "/graphql" [Client 34.81.191.157] [Length 31] [Gzip -] [Sent-to 10.1.1.246] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "https://ai.dalslab.com"
[21/Sep/2026:16:37:42 +0200] - 405 405 - POST https ai.dalslab.com "/api/graphql" [Client 34.81.191.157] [Length 31] [Gzip -] [Sent-to 10.1.1.246] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "https://ai.dalslab.com"
[21/Sep/2026:16:37:42 +0200] - 405 405 - POST https ai.dalslab.com "/v1/graphql" [Client 34.81.191.157] [Length 31] [Gzip -] [Sent-to 10.1.1.246] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15
...
show less
Web Spam
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 14:11:37
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.81.191.157 (157.191.81.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.81.191.157 (157.191.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 10:11:31.461765 2026] [security2:error] [pid 26989:tid 27013] [client 34.81.191.157:36144] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||hnssales.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "hnssales.com"] [uri "/z9x8c7v6b5-debug-trigger-hnssales.com"] [unique_id "arE7E47BzI6O-1EkQZkedwAAAUg"]
show less
Brute-Force
Bad Web Bot
Web App Attack