๐ณ๐ฑ
RobotOilInc
2026-10-09 05:45:57
(1 day ago)
[Coraza - Automated] Restricted URL Access Attempt. Data: Matched URL found: /config.js
Hacking
Bad Web Bot
๐ฉ๐ช
Gwyneth Llewelyn
2026-10-09 05:35:32
(1 day ago)
34.84.43.133 - - [09/Oct/2026:06:35:30 +0100] "POST /cgi-bin/php-cgi.exe?%ADd+allow_url_include%3d1+ ...
show more
34.84.43.133 - - [09/Oct/2026:06:35:30 +0100] "POST /cgi-bin/php-cgi.exe?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input HTTP/2.0" 404 994 "-" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)"
show less
Bad Web Bot
๐ฆ๐น
Pingger Shikkoken
2026-10-09 04:11:38
(1 day ago)
2026-10-09T04:11:38+00:00 iskariot kernel: AbuseIPDB-Blacklist-Dropped: IN=ens3 OUT=ServerBridge MAC ...
show more
2026-10-09T04:11:38+00:00 iskariot kernel: AbuseIPDB-Blacklist-Dropped: IN=ens3 OUT=ServerBridge MAC=b6:ab:74:e6:2e:14:2c:dd:e9:13:03:d9:08:00 SRC=34.84.43.133 DST=10.1.1.2 LEN=60 TOS=0x00 PREC=0x60 TTL=54 ID=386 DF PROTO=TCP SPT=54034 DPT=443 WINDOW=65320 RES=0x00 SYN URGP=0 2026-10-09T04:11:39+00:00 iskariot kernel: AbuseIPDB-Blacklist-Dropped: IN=ens3 OUT=ServerBridge MAC=b6:ab:74:e6:2e:14:2c:dd:e9:13:03:d9:08:00 SRC=34.84.43.133 DST=10.1.1.2 LEN=60 TOS=0x00 PREC=0x60 TTL=54 ID=387 DF PROTO=TCP SPT=54034 DPT=443 WINDOW=65320 RES=0x00 SYN URGP=0 2026-10-09T04:11:40+00:00 iskariot kernel: AbuseIPDB-Blacklist-Dropped: IN=ens3 OUT=ServerBridge MAC=b6:ab:74:e6:2e:14:2c:dd:e9:13:03:d9:08:00 SRC=34.84.43.133 DST=10.1.1.2 LEN=60 TOS=0x00 PREC=0x60 TTL=54 ID=388 DF PROTO=TCP SPT=54034 DPT=443 WINDOW=65320 RES=0x00 SYN URGP=0 ...
show less
Hacking
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-09 04:01:22
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.84.43.133 (133.43.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.43.133 (133.43.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 00:01:15.199877 2026] [security2:error] [pid 13651:tid 13651] [client 34.84.43.133:42414] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.studio716.info"] [uri "/static../.env"] [unique_id "ashnCx55vsAjcxnak9VExAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 03:41:08
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.84.43.133 (133.43.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.43.133 (133.43.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 23:41:04.513269 2026] [security2:error] [pid 19863:tid 19863] [client 34.84.43.133:57944] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.afjm.info"] [uri "/%2e%2e/.env"] [unique_id "ashiUEwYjfm37eEpUAjdlQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-10-09 02:08:29
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-bad-user-agent
Web App Attack
Bad Web Bot
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-10-09 01:17:06
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/grafana-cve-2021-43798
Web App Attack
Hacking
๐บ๐ธ
entangled_mongoose
2026-10-08 23:24:04
(1 day ago)
Probed /wp-json.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 23:23:41
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.84.43.133 (133.43.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.43.133 (133.43.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 19:23:34.366787 2026] [security2:error] [pid 13627:tid 13627] [client 34.84.43.133:33484] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bright-ideas.keystroke.info"] [uri "/.htpasswd"] [unique_id "asgl9nkECxIh-0o5Gns1AQAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
RobotOilInc
2026-10-08 23:11:04
(1 day ago)
[Coraza - Automated] Found User-Agent associated with restricted user agent. Data: Matched Data: fo ...
show more
[Coraza - Automated] Found User-Agent associated with restricted user agent. Data: Matched Data: found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36
show less
Hacking
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-08 22:58:06
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.84.43.133 (133.43.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.43.133 (133.43.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 18:58:01.257593 2026] [security2:error] [pid 17704:tid 17704] [client 34.84.43.133:48344] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bluedogzero.firstlegend.info"] [uri "/.htpasswd"] [unique_id "asgf-aTepVQid0vx8R9ZigAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Gwyneth Llewelyn
2026-10-08 22:57:52
(1 day ago)
2026/10/08 23:57:50 [error] 4060693#4060693: *1332997 access forbidden by rule, client: 34.84.43.133 ...
show more
2026/10/08 23:57:50 [error] 4060693#4060693: *1332997 access forbidden by rule, client: 34.84.43.133, server: betatechnologies.info, request: "GET /static../.env HTTP/2.0", host: "blogs.betatechnologies.info"
2026/10/08 23:57:50 [error] 4060693#4060693: *1332997 access forbidden by rule, client: 34.84.43.133, server: betatechnologies.info, request: "GET /media../.env HTTP/2.0", host: "blogs.betatechnologies.info"
2026/10/08 23:57:50 [error] 4060693#4060693: *1332997 access forbidden by rule, client: 34.84.43.133, server: betatechnologies.info, request: "GET /files../.env HTTP/2.0", host: "blogs.betatechnologies.info"
show less
Brute-Force
Web App Attack
๐ฉ๐ช
Gwyneth Llewelyn
2026-10-08 20:20:45
(1 day ago)
2026/10/08 21:20:43 [error] 4060693#4060693: *1292778 access forbidden by rule, client: 34.84.43.133 ...
show more
2026/10/08 21:20:43 [error] 4060693#4060693: *1292778 access forbidden by rule, client: 34.84.43.133, server: api.betatechnologies.info, request: "GET /static../.env HTTP/2.0", host: "api.betatechnologies.info"
2026/10/08 21:20:43 [error] 4060693#4060693: *1292778 access forbidden by rule, client: 34.84.43.133, server: api.betatechnologies.info, request: "GET /assets../.env HTTP/2.0", host: "api.betatechnologies.info"
2026/10/08 21:20:43 [error] 4060693#4060693: *1292778 access forbidden by rule, client: 34.84.43.133, server: api.betatechnologies.info, request: "GET /files../.env HTTP/2.0", host: "api.betatechnologies.info"
show less
Brute-Force
Web App Attack
Anonymous
2026-10-08 19:50:05
(1 day ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-10-08 19:14:27
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.84.43.133 (133.43.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.43.133 (133.43.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 15:14:21.234318 2026] [security2:error] [pid 19276:tid 19276] [client 34.84.43.133:54596] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sheldondesigns.info"] [uri "/.htpasswd"] [unique_id "asfrjUErYQ43hTNHQ-0NsgAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack