๐บ๐ธ
[email protected]
2026-09-24 11:28:52
(4 hours ago)
CrowdSec ban: crowdsecurity/unifi-flood-detection (duration: 71h59m51s)
Port Scan
๐ณ๐ฑ
Alt255
2026-09-24 07:26:49
(8 hours ago)
[ti-24al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-24al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.81.211.244 - - [24/Sep/2026:09:26:29 +0200] "GET /@fs/src/.env?raw?? HTTP/2.0" 404 2004 "-" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 05:55:44
(9 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.81.211.244 (244.211.81.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.81.211.244 (244.211.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 01:55:37.897934 2026] [security2:error] [pid 3560612:tid 3560612] [client 34.81.211.244:53250] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.loudenlow.com|F|2"] [data ".loudenlow.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.loudenlow.com"] [uri "/z9x8c7v6b5-debug-trigger-www.loudenlow.com"] [unique_id "arS7WWkcsISb9fLKy4tu5gAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐พ
Rizzy
2026-09-24 04:54:50
(10 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 03:14:18
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.81.211.244 (244.211.81.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.211.244 (244.211.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 23:14:14.154636 2026] [security2:error] [pid 9025:tid 9062] [client 34.81.211.244:55628] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.kandooo.com"] [uri "/.htpasswd"] [unique_id "arSVhgQhJIJTtPlPojbmawAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-09-24 03:01:27
(12 hours ago)
2.117 requests from abuseipdb.com blacklisted IP (5mos2w6d)
Brute-Force
Bad Web Bot
๐ฉ๐ช
TheDjRider
2026-09-24 02:51:26
(12 hours ago)
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban tri ...
show more
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban triggered. Detection time (UTC): 2026-09-24T02:51:24.863743555Z. Context: http_status=301
show less
Web App Attack
๐บ๐ธ
TAY
2026-09-24 02:15:45
(13 hours ago)
34.81.211.244 - - [24/Sep/2026:10:15:42 +0800] "GET /public/plugins/text/../../../../../../../../pro ...
show more
34.81.211.244 - - [24/Sep/2026:10:15:42 +0800] "GET /public/plugins/text/../../../../../../../../proc/self/environ HTTP/1.1" 400 2057 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] )"
34.81.211.244 - - [24/Sep/2026:10:15:43 +0800] "GET /public/plugins/grafana-clock-panel/../../../../../../../../proc/self/environ HTTP/1.1" 400 2057 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)"
34.81.211.244 - - [24/Sep/2026:10:15:43 +0800] "GET /api/w/admins/jobs_u/get_log_file/../../../../proc/self/environ HTTP/1.1" 301 398 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)"
34.81.211.244 - - [24/Sep/2026:10:15:43 +0800] "GET /api/w/default/jobs_u/get_log_file/../../../../proc/self/environ HTTP/1.1" 301 399 "-" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)"
34.81.211.244 - - [24/Sep/2026:10:15:43 +0800] "GET /api/w/starter/jobs_u/get_log_file/../../../../proc/self/environ H
...
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-24 01:11:36
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.81.211.244 (244.211.81.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.211.244 (244.211.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 21:11:33.154680 2026] [security2:error] [pid 2379:tid 2379] [client 34.81.211.244:40442] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.ifmamasang.com"] [uri "/.env.prod"] [unique_id "arR4xcllxANRHKaYROvJwgAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-24 00:30:09
(15 hours ago)
CrowdSec decision: crowdsecurity/http-bad-user-agent (origin: crowdsec)
Port Scan
๐บ๐ธ
TPI-Abuse
2026-09-24 00:17:50
(15 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.81.211.244 (244.211.81.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.81.211.244 (244.211.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 20:17:45.221503 2026] [security2:error] [pid 32280:tid 32295] [client 34.81.211.244:39250] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||antidote-it.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "antidote-it.com"] [uri "/z9x8c7v6b5-debug-trigger-antidote-it.com"] [unique_id "arRsKcuaiNSWaLXoU0RqmgAAAQo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-24 00:06:15
(15 hours ago)
Web application attack detected.
Web App Attack
๐ฉ๐ช
bazter.pro
2026-09-23 23:32:40
(16 hours ago)
Fail2Ban: plesk-bot-aggressive - 15 failures
Port Scan
Bad Web Bot
Web App Attack
๐ฉ๐ช
NewGastroline
2026-09-23 21:11:56
(18 hours ago)
Malicious request blocked by CrowdSec on gastro-prod1.boreus.de
Bad Web Bot
Web App Attack
๐จ๐ฆ
Anytech
2026-09-23 21:05:11
(18 hours ago)
Blocked by Conn-Monitor: env-probing
Web App Attack
Hacking