๐ฉ๐ช
klaus_ph
2026-09-23 11:24:54
(20 hours ago)
2026-09-22 23:39:18,114 fail2ban.actions [535885]: NOTICE [ipblocklist] Ban 34.82.89.113
...
Bad Web Bot
๐ซ๐ท
masterguru
2026-09-20 15:19:22
(3 days ago)
Restricted File Access Attempt. Matched phrase ".aws/" at REQUEST_FILENAME. (930130-195)
Hacking
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-20 15:05:49
(3 days ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-20 15:05:16
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.82.89.113 (113.89.82.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.82.89.113 (113.89.82.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 11:05:11.496905 2026] [security2:error] [pid 10095:tid 10116] [client 34.82.89.113:38922] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fnaandpartners.com"] [uri "/.env.local"] [unique_id "aq_2J3FmCuI-OtmwC466CAAAAFI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
dot.mg
2026-09-20 14:53:41
(3 days ago)
Scan of vulnerable files
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 14:25:21
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.82.89.113 (113.89.82.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.82.89.113 (113.89.82.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 10:25:18.152727 2026] [security2:error] [pid 5136:tid 5136] [client 34.82.89.113:48430] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "flyc2c.com"] [uri "/.git/HEAD"] [unique_id "aq_szn1RQY1P001oZv67HQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-09-20 14:20:15
(3 days ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ฉ๐ช
yitzhaq
2026-09-20 14:12:49
(3 days ago)
34.82.89.113 - - [20/Sep/2026:16:12:46 +0200] "GET /@fs/var/task/.env?raw?? HTTP/2.0" 404 294 "-" "M ...
show more
34.82.89.113 - - [20/Sep/2026:16:12:46 +0200] "GET /@fs/var/task/.env?raw?? HTTP/2.0" 404 294 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)"
34.82.89.113 - - [20/Sep/2026:16:12:46 +0200] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fproc/self/environ HTTP/2.0" 404 294 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36; compatible; OAI-SearchBot/1.4; +https://openai.com/searchbot"
34.82.89.113 - - [20/Sep/2026:16:12:46 +0200] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f.env HTTP/2.0" 404 294 "-" "Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)"
34.82.89.113 - - [20/Sep/2026:16:12:47 +0200] "GET /uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f.env HTTP/2.0" 404 317 "-" "Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)"
34.82.89.113 - - [20/Sep/2026:16:12:47 +0200] "GET /icons/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/proc/self/environ
show less
Web App Attack
Hacking
๐ฉ๐ช
konseptit
2026-09-20 13:45:29
(3 days ago)
(mod_security) mod_security triggered on hostname [redacted] 34.82.89.113 (US/United States/113.89.8 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.82.89.113 (US/United States/113.89.82.34.bc.googleusercontent.com)
show less
SQL Injection
๐ซ๐ท
masterguru
2026-09-20 13:37:37
(3 days ago)
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .backup/ ...
show more
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .compositefont/ .config/ .conf/ .crt/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dist/ .dll/ .dos/ .dpkg-dist/ .drv/ .gadget/ .hta/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .inf/ .ini/ .jse/ .key/ .licx/ .lnk/ .log/ .mdb/ .msc/ .ocx/ .old/ .pass/ .pdb/ .pfx/ .pif/ .pem/ .pol/ .prf/ .printer/ .pwd/ .rdb/ .rdp/ .reg/ .resources/ .resx/ .scr/ .sct/ .shs/ .sql/ .swp/ .sys/ .tlb/ .tmp/ .url/ .vb/ .vbe/ .vbs/ .vbproj/ .vsdisco/ .vxd/ .webinfo/ .ws/ .wsc/ .wsf/ .wsh/ .xsd/ .xsx/" at TX:extension. (920440-196)
show less
Hacking
๐ฉ๐ช
TheDjRider
2026-09-20 13:26:12
(3 days ago)
CrowdSec detected Web application reconnaissance. Scenario: crowdsecurity/http-probing. Automatic ba ...
show more
CrowdSec detected Web application reconnaissance. Scenario: crowdsecurity/http-probing. Automatic ban triggered. Detection time (UTC): 2026-09-20T13:26:00.383831567Z. Context: http_status=403, http_status=404
show less
Web App Attack
๐ฉ๐ช
Skyrider
2026-09-20 13:25:24
(3 days ago)
Nginx: HTTP 4xx probe/scan attempts. Automated fail2ban report.
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-20 12:48:40
(3 days ago)
Multiple WAF Violations
Web App Attack
๐ฎ๐น
VHosting
2026-09-20 12:35:04
(3 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 12:34:38
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 34.82.89.113 (113.89.82.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.82.89.113 (113.89.82.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 08:34:34.386612 2026] [security2:error] [pid 11624:tid 11624] [client 34.82.89.113:37404] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bridgital.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bridgital.com"] [uri "/z9x8c7v6b5-debug-trigger-bridgital.com"] [unique_id "aq_S2n9xsB9MopWi9mkNegAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack