๐ณ๐ฑ
SophieN25
2026-10-03 10:30:03
(4 minutes ago)
Automatically denied: 26 error log hits on stdnote.com
Fraud Orders
๐ฒ๐พ
Rizzy
2026-10-03 05:46:02
(4 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-03 02:20:12
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.84.145.37 (37.145.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.145.37 (37.145.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 22:20:06.486551 2026] [security2:error] [pid 25741:tid 25741] [client 34.84.145.37:38938] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.soviaenterprises.com"] [uri "/.env.dev"] [unique_id "asBmVqGEQTmHKv7gdmtoFQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ฌ
simpeg-adm.bandung.go.id
2026-10-03 00:53:56
(9 hours ago)
03/Oct/2026:00:53:55 +0000;34.84.145.37;"/lib/terminal-xhr.php"
03/Oct/2026:00:53:55 +0000;34.84.145 ...
show more
03/Oct/2026:00:53:55 +0000;34.84.145.37;"/lib/terminal-xhr.php"
03/Oct/2026:00:53:55 +0000;34.84.145.37;"/5v25xqcywvucjhxujdc1"
03/Oct/2026:00:53:55 +0000;34.84.145.37;"/.vite/manifest.json"
03/Oct/2026:00:53:55 +0000;34.84.145.37;"/z9x8c7v6b5-debug-trigger-vendors.brennamariephoto.com"
03/Oct/2026:00:53:55 +0000;34.84.145.37;"/model/info"
03/Oct/2026:00:53:55 +0000;34.84.145.37;"/rqq1yninahgtltr57gb1"
03/Oct/2026:00:53:55 +0000;34.84.145.37;"/dist/manifest.json"
...
show less
Web Spam
Brute-Force
Web App Attack
๐ง๐ช
cmbplf
2026-10-02 23:05:01
(11 hours ago)
2.081 requests from abuseipdb.com blacklisted IP (1yr1mo2w)
Brute-Force
Bad Web Bot
๐ฉ๐ช
TheDjRider
2026-10-02 21:47:26
(12 hours ago)
CrowdSec detected Hacking activity. Scenario: LePresidente/http-generic-403-bf. Automatic ban trigge ...
show more
CrowdSec detected Hacking activity. Scenario: LePresidente/http-generic-403-bf. Automatic ban triggered. Detection time (UTC): 2026-10-02T21:47:19.64233062Z. Context: http_status=403
show less
Hacking
๐ณ๐ฑ
Site.eu
2026-10-02 21:36:43
(12 hours ago)
Excessive multi-domain requests
Brute-Force
๐ณ๐ฑ
Alt255
2026-10-02 20:28:56
(14 hours ago)
[ti-22al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-22al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.84.145.37 - - [02/Oct/2026:22:28:37 +0200] "GET /.ssh/config HTTP/2.0" 301 49 "-" "Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 19:49:50
(14 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.84.145.37 (37.145.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.84.145.37 (37.145.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 15:49:47.394659 2026] [security2:error] [pid 29391:tid 29397] [client 34.84.145.37:34222] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.sparkhypnotherapy.com|F|2"] [data ".sparkhypnotherapy.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.sparkhypnotherapy.com"] [uri "/z9x8c7v6b5-debug-trigger-www.sparkhypnotherapy.com"] [unique_id "asAK23NNHUVMVKP5OCpdgwAAAUQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
rsa
2026-10-02 19:34:00
(15 hours ago)
POST /php-cgi/php-cgi.exe?%ADd+allow_url_include%3d1+%ADd+auto_
DDoS Attack
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 19:27:55
(15 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.84.145.37 (37.145.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.84.145.37 (37.145.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 15:27:48.587503 2026] [security2:error] [pid 19773:tid 19773] [client 34.84.145.37:36512] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.stat-alliance.com|F|2"] [data ".stat-alliance.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.stat-alliance.com"] [uri "/z9x8c7v6b5-debug-trigger-www.stat-alliance.com"] [unique_id "asAFtLYKQTgqQE-frP8uAAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 15:32:18
(19 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.84.145.37 (37.145.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.84.145.37 (37.145.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 11:32:10.587810 2026] [security2:error] [pid 25463:tid 25463] [client 34.84.145.37:49522] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||sparler.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "sparler.com"] [uri "/z9x8c7v6b5-debug-trigger-sparler.com"] [unique_id "ar_OeokrWQwlc5qIwPq4KQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-10-02 15:27:03
(19 hours ago)
Remote Command Execution: Direct Unix Command Execution. Pattern match "(?i)(?:^|b (932250-195)
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-02 15:08:39
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.84.145.37 (37.145.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.145.37 (37.145.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 11:08:32.551745 2026] [security2:error] [pid 25132:tid 25132] [client 34.84.145.37:58850] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.themotelwest.com"] [uri "/.env.development"] [unique_id "ar_I8IG7IMakzRh2RXjRKQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 14:41:57
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.84.145.37 (37.145.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.145.37 (37.145.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 10:41:51.809819 2026] [security2:error] [pid 27808:tid 27808] [client 34.84.145.37:36910] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.pixelspective.com"] [uri "/api/console/api_server"] [unique_id "ar_CrwMQbEPEjsgrUhHKtwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack