๐ซ๐ท
Octopuce
2026-09-23 23:47:36
(2 minutes ago)
Aggressive web search of vulnerable pages: /docker/.env /.next/.env /build/.env /dist/.env /core/.en ...
show more
Aggressive web search of vulnerable pages: /docker/.env /.next/.env /build/.env /dist/.env /core/.env ...
show less
Web App Attack
๐ฉ๐ช
bazter.pro
2026-09-23 23:41:56
(8 minutes ago)
Fail2Ban: plesk-bot-aggressive - 15 failures
Port Scan
Bad Web Bot
Web App Attack
๐บ๐ธ
kosada.com
2026-09-23 23:06:25
(44 minutes ago)
Repeated requests for suspicious nonexistent URLs, for example: /dist/manifest.json (HTTP/2.0 port 4 ...
show more
Repeated requests for suspicious nonexistent URLs, for example: /dist/manifest.json (HTTP/2.0 port 443, user agent: "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36")
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 22:08:32
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 34.84.168.248 (248.168.84.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.84.168.248 (248.168.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 18:08:26.588587 2026] [security2:error] [pid 4886:tid 4886] [client 34.84.168.248:54752] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||97201.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "97201.com"] [uri "/z9x8c7v6b5-debug-trigger-97201.com"] [unique_id "arRN2rHOPx71j3isCSqiZQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Lee Daniel
2026-09-23 21:42:59
(2 hours ago)
34.84.168.248 - - [23/Sep/2026:17:42:58 -0400] "GET /.env HTTP/1.1" 403 344 "https://caribbeannewmed ...
show more
34.84.168.248 - - [23/Sep/2026:17:42:58 -0400] "GET /.env HTTP/1.1" 403 344 "https://caribbeannewmedia.com/_nuxt/../.env" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.4; +https://openai.com/gptbot"
...
show less
DDoS Attack
Web Spam
Email Spam
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 21:10:15
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.84.168.248 (248.168.84.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.84.168.248 (248.168.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 17:10:11.470803 2026] [security2:error] [pid 10962:tid 10962] [client 34.84.168.248:45850] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||fritsknuf.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "fritsknuf.com"] [uri "/z9x8c7v6b5-debug-trigger-fritsknuf.com"] [unique_id "arRAM3pvUYxcEDVKvI8jPwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
svr
2026-09-23 20:57:15
(2 hours ago)
Abusive Automated Web Scanner
Web App Attack
๐ฉ๐ช
Phenix Info
2026-09-23 20:52:39
(2 hours ago)
SmallGuard.fr - HoneyPot
Web App Attack
๐ฉ๐ช
itsolon
2026-09-23 20:52:04
(2 hours ago)
[23/Sep/2026:22:52:02 +0200] 179019672258.833749 34.84.168.248 33694 217.154.7.177 443
[23/Sep/2026: ...
show more
[23/Sep/2026:22:52:02 +0200] 179019672258.833749 34.84.168.248 33694 217.154.7.177 443
[23/Sep/2026:22:52:03 +0200] 179019672368.063980 34.84.168.248 33694 217.154.7.177 443
[23/Sep/2026:22:52:03 +0200] 179019672361.853402 34.84.168.248 33696 217.154.7.177 443
[23/Sep/2026:22:52:03 +0200] 17901967232.725519 34.84.168.248 33696 217.154.7.177 443
[23/Sep/2026:22:52:03 +0200] 179019672386.244200 34.84.168.248 33696 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
๐ฒ๐พ
Rizzy
2026-09-23 20:51:04
(2 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 20:28:56
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.84.168.248 (248.168.84.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.84.168.248 (248.168.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 16:28:48.041406 2026] [security2:error] [pid 23825:tid 23825] [client 34.84.168.248:38112] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||loupgaroubooks.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "loupgaroubooks.com"] [uri "/z9x8c7v6b5-debug-trigger-loupgaroubooks.com"] [unique_id "arQ2gMTJFTY7BKU8alAQvAAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 20:05:23
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.84.168.248 (248.168.84.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.84.168.248 (248.168.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 16:05:17.849787 2026] [security2:error] [pid 25977:tid 25977] [client 34.84.168.248:55232] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||loveoflearning.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "loveoflearning.com"] [uri "/z9x8c7v6b5-debug-trigger-loveoflearning.com"] [unique_id "arQw_QV-ZGKwuljUoHJCqwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
BlueWire Hosting
2026-09-23 19:46:23
(4 hours ago)
Bad bot ignoring robot.txt
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-23 19:17:52
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.84.168.248 (248.168.84.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.84.168.248 (248.168.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 15:17:48.151039 2026] [security2:error] [pid 16596:tid 16596] [client 34.84.168.248:43310] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||lsippell.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "lsippell.com"] [uri "/z9x8c7v6b5-debug-trigger-lsippell.com"] [unique_id "arQl3FSX9f_WdwOiTkgnSgAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 19:01:10
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.84.168.248 (248.168.84.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.84.168.248 (248.168.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 15:01:07.255964 2026] [security2:error] [pid 19824:tid 19824] [client 34.84.168.248:41508] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||lubbockknights.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "lubbockknights.com"] [uri "/z9x8c7v6b5-debug-trigger-lubbockknights.com"] [unique_id "arQh88fNAP_rshFdA0_4CgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack