Anonymous
2026-09-30 19:30:04
(1 week ago)
CrowdSec decision: crowdsecurity/http-bad-user-agent (origin: crowdsec)
Port Scan
๐บ๐ธ
JustMeHere
2026-09-30 19:18:23
(1 week ago)
[Wed Sep 30 15:18:18.958783 2026] [security2:error] [pid 805:tid 964] [client 34.84.77.45:36618] Mod ...
show more
[Wed Sep 30 15:18:18.958783 2026] [security2:error] [pid 805:tid 964] [client 34.84.77.45:36618] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.15.0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "yorknation.com"] [uri "/"] [unique_id "ar1gep2-GnwYoNsBZriaXgAAAJI"]
...
show less
Web App Attack
๐ซ๐ท
COMAITE
2026-09-30 19:02:02
(1 week ago)
Suspicious URL access.
Web App Attack
๐บ๐ธ
Power Ca
2026-09-30 17:52:32
(1 week ago)
34.84.77.45 - - [30/Sep/2026:17:52:30 +0000] "GET /z9x8c7v6b5-debug-trigger-www.leaderscartel.com HT ...
show more
34.84.77.45 - - [30/Sep/2026:17:52:30 +0000] "GET /z9x8c7v6b5-debug-trigger-www.leaderscartel.com HTTP/2.0" 404 123 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)"
34.84.77.45 - - [30/Sep/2026:17:52:30 +0000] "GET /dist/manifest.json HTTP/2.0" 404 185 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Mobile Safari/537.36"
34.84.77.45 - - [30/Sep/2026:17:52:30 +0000] "GET /.vite/manifest.json HTTP/2.0" 404 185 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Mobile Safari/537.36"
34.84.77.45 - - [30/Sep/2026:17:52:30 +0000] "GET /dist/.vite/manifest.json HTTP/2.0" 404 185 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Mobile Safari/537.36"
34.84.77.45 - - [30/Sep/2026:17:52:30 +0000] "POST /graphql HTTP/2.0" 404 185 "https://www.leaderscartel.com" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chro
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 15:32:33
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 34.84.77.45 (45.77.84.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.84.77.45 (45.77.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 11:32:30.568558 2026] [security2:error] [pid 23744:tid 23744] [client 34.84.77.45:37272] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||my-spec.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "my-spec.com"] [uri "/z9x8c7v6b5-debug-trigger-my-spec.com"] [unique_id "ar0rjhS2KYXLfYE4v0cVQQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-30 15:12:41
(1 week ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
๐บ๐ธ
oukat
2026-09-30 15:12:22
(1 week ago)
Web bot / web application probing against nginx
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 14:51:56
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 34.84.77.45 (45.77.84.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.84.77.45 (45.77.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 10:51:52.060731 2026] [security2:error] [pid 5731:tid 5731] [client 34.84.77.45:48212] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||leewis.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "leewis.com"] [uri "/z9x8c7v6b5-debug-trigger-leewis.com"] [unique_id "ar0iCEdqdouvRpyISK0OuAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
IndigoRidge
2026-09-30 13:55:14
(1 week ago)
34.84.77.45 - - [30/Sep/2026:09:55:11 -0400] "GET /cache/original/%2e%2e/.env HTTP/1.1" 404 58804 "- ...
show more
34.84.77.45 - - [30/Sep/2026:09:55:11 -0400] "GET /cache/original/%2e%2e/.env HTTP/1.1" 404 58804 "-" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/)"
34.84.77.45 - - [30/Sep/2026:09:55:11 -0400] "GET /api/fs/read?allowOutsideWorkspace=true&path=/app/.env HTTP/1.1" 404 58843 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)"
34.84.77.45 - - [30/Sep/2026:09:55:13 -0400] "GET /cache/original/%2e%2e/%2e%2e/.env HTTP/1.1" 404 58807 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot)"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 13:41:34
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.84.77.45 (45.77.84.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.77.45 (45.77.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 09:41:30.321832 2026] [security2:error] [pid 25870:tid 25870] [client 34.84.77.45:39548] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.lenosillevis.com"] [uri "/.htpasswd"] [unique_id "ar0RitSJTl3J-ssXpMfrTgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-30 13:39:29
(1 week ago)
Aggressive web scan
Web App Attack
Anonymous
2026-09-30 13:30:02
(1 week ago)
CrowdSec decision: crowdsecurity/http-crawl-non_statics (origin: crowdsec)
Port Scan
๐ณ๐ฑ
Savvii
2026-09-30 13:15:30
(1 week ago)
20 attempts against mh_ha-misbehave-ban on orcus
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
MakoWish
2026-09-30 12:29:50
(1 week ago)
Fuzzing for misconfigured web servers.
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 12:08:10
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 34.84.77.45 (45.77.84.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.84.77.45 (45.77.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 08:08:04.639658 2026] [security2:error] [pid 21510:tid 21510] [client 34.84.77.45:38068] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||leannebostwick.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "leannebostwick.com"] [uri "/z9x8c7v6b5-debug-trigger-leannebostwick.com"] [unique_id "arz7pKBn3C7KXa9uH0yJ9QAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack