๐บ๐ธ
TPI-Abuse
2026-09-17 06:17:34
(3 minutes ago)
(mod_security) mod_security (id:210730) triggered by 34.82.111.74 (74.111.82.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.82.111.74 (74.111.82.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 02:17:30.226834 2026] [security2:error] [pid 20695:tid 20695] [client 34.82.111.74:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||portfoliolighting.net|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "portfoliolighting.net"] [uri "/rclone.conf"] [unique_id "aquF-vxI7TkfhzQjH5ArCwAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
Burayot
2026-09-17 06:11:49
(9 minutes ago)
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 34.82.111.74 (US/United States/74.11 ...
show more
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 34.82.111.74 (US/United States/74.111.82.34.bc.googleusercontent.com): 1 in the last 3600 secs
show less
Web App Attack
๐ฎ๐ณ
evicky2002
2026-09-17 06:00:05
(21 minutes ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ซ๐ฎ
xyz.rip
2026-09-17 05:53:27
(27 minutes ago)
WAF Violation
...
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 05:23:09
(58 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.82.111.74 (74.111.82.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.82.111.74 (74.111.82.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 01:23:06.460679 2026] [security2:error] [pid 18489:tid 18489] [client 34.82.111.74:53820] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nwtree.com"] [uri "/dist/.env"] [unique_id "aqt5Op6RQ5o8ybkJdZJqBQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-17 05:14:05
(1 hour ago)
Banned by Fail2Ban on server
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-17 05:11:39
(1 hour ago)
[cb-14al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail ngin ...
show more
[cb-14al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail nginx-404. Example: 34.82.111.74 - - [17/Sep/2026:07:11:12 +0200] "GET /static/manifest.json HTTP/1.0" 404 5647 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36"
34.82.111.74 - - [17/Sep/2026:07:11:12 +0200] "GET /z9x8c7v6b5-debug-trigger-nice2move.nl HTTP/1.0" 404 89450 "https://nice2move.nl/z9x8c7v6b5-debug-trigger-nice2move.nl" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)"
34.82.111.74 - - [17/Sep/2026:07:11:12 +0200] "GET /wp-json HTTP/1.0" 404 89420 "https://nice2move.nl/wp-json" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)"
34.82.111.74 - - [17/Sep/2026:07:11:12 +0200] "GET /ssl/localhost.key HTTP/1.0" 404 89431 "https://nice2move.nl/ssl/localhost.key" "Mozilla/5.0 (compatible; PanguBo
...
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-17 04:58:14
(1 hour ago)
20 attempts against mh-misbehave-ban on eris
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
pscriptos
2026-09-17 03:59:04
(2 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ณ๐ฑ
Savvii
2026-09-17 03:33:00
(2 hours ago)
20 attempts against mh-misbehave-ban on ethyl
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-09-17 02:51:30
(3 hours ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ksol-hostmaster
2026-09-17 02:47:43
(3 hours ago)
2026/09/17 04:47:43 [error] 13320#100926: *7060320 limiting requests, excess: 0.980 by zone "crawler ...
show more
2026/09/17 04:47:43 [error] 13320#100926: *7060320 limiting requests, excess: 0.980 by zone "crawler", client: 34.82.111.74, server: ksol.io, request: "GET /.env?import&url&inline HTTP/2.0", host: "ksol.io"
...
show less
Bad Web Bot
Anonymous
2026-09-17 02:39:02
(3 hours ago)
Bot / scanning and/or hacking attempts: GET /shop/.env HTTP/2.0, GET /internal/.env HTTP/2.0, GET /f ...
show more
Bot / scanning and/or hacking attempts: GET /shop/.env HTTP/2.0, GET /internal/.env HTTP/2.0, GET /forgot-password HTTP/2.0, GET /app HTTP/2.0, GET / HTTP/2.0, GET /panel HTTP/2.0, GET /lib/.env HTTP/2.0, GET /store/.env HTTP/2.0, GET /portal/.env HTTP/2.0, [73/72] schedule: stream 145, GET /tmp/.env, GET /assets/.env HTTP/2.0, GET /panel/.env HTTP/2.0, GET /static/.env HTTP/2.0, GET /.env_1 HTTP/2.0, GET /private/.env HTTP/2.0
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 02:11:00
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.82.111.74 (74.111.82.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.82.111.74 (74.111.82.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 22:10:54.121879 2026] [security2:error] [pid 16713:tid 16713] [client 34.82.111.74:59182] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jerusalem-korczak-home.com"] [uri "/shop/.env"] [unique_id "aqtMLjDKb3Zrd9M7gc3wNAAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
EGP Abuse Dept
2026-09-17 02:09:11
(4 hours ago)
Scanning for web/db/file exploits on www.jb-hydraulics.nl
SQL Injection
Bad Web Bot
Web App Attack