๐ช๐ธ
pipeline.es
2026-09-24 08:59:06
(9 hours ago)
Web scanning / probing for vulnerable paths
Port Scan
Web App Attack
๐บ๐ธ
dot.mg
2026-09-24 03:42:02
(15 hours ago)
Bad behaviour
Web Spam
Anonymous
2026-09-24 01:52:12
(16 hours ago)
Bot / seems abusive / Apache connections: 22
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 22:54:16
(19 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.85.11.139 (139.11.85.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.85.11.139 (139.11.85.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 18:54:11.290613 2026] [security2:error] [pid 4221:tid 4276] [client 34.85.11.139:51216] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.kaulaniconsulting.com|F|2"] [data ".kaulaniconsulting.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.kaulaniconsulting.com"] [uri "/z9x8c7v6b5-debug-trigger-www.kaulaniconsulting.com"] [unique_id "arRYk9vml7RpJh3mN4m_UAAAANg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
bazter.pro
2026-09-23 22:13:02
(20 hours ago)
Fail2Ban: plesk-bot-aggressive - 15 failures
Port Scan
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 21:34:51
(21 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.85.11.139 (139.11.85.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.85.11.139 (139.11.85.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 17:34:45.811704 2026] [security2:error] [pid 16547:tid 16547] [client 34.85.11.139:55188] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||aquasafedemo.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "aquasafedemo.com"] [uri "/z9x8c7v6b5-debug-trigger-aquasafedemo.com"] [unique_id "arRF9TTLs34i7g8pBA6kyQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
robotstxt
2026-09-23 21:29:10
(21 hours ago)
34.85.11.139 - - [23/Sep/2026:21:28:02 +0000] "GET /dist/.vite/manifest.json HTTP/2.0" 403 36322 "-" ...
show more
34.85.11.139 - - [23/Sep/2026:21:28:02 +0000] "GET /dist/.vite/manifest.json HTTP/2.0" 403 36322 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "34.85.11.139" edge="162.159.106.123"
34.85.11.139 - - [23/Sep/2026:21:28:05 +0000] "GET /.env.save HTTP/2.0" 403 2 "-" "Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)" "34.85.11.139" edge="172.64.215.164"
34.85.11.139 - - [23/Sep/2026:21:28:06 +0000] "GET /.env.prod HTTP/2.0" 403 2 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)" "34.85.11.139" edge="172.64.215.164"
34.85.11.139 - - [23/Sep/2026:21:28:12 +0000] "GET /.git-credentials HTTP/2.0" 403 2 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot)" "34.85.11.139" edge="172.64.215.164"
34.85.11.139 - - [23/Sep/2026:21:28:13 +0000] "GET /.aws/credentials H
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 21:14:53
(21 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.85.11.139 (139.11.85.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.85.11.139 (139.11.85.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 17:14:48.375605 2026] [security2:error] [pid 11744:tid 11744] [client 34.85.11.139:49922] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||davidquiroa.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "davidquiroa.com"] [uri "/z9x8c7v6b5-debug-trigger-davidquiroa.com"] [unique_id "arRBSKm4waaySbsEhBCpdQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
GabrielJST
2026-09-23 21:13:44
(21 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.85.11.139 (JP/Japan/139.11.85.34.bc. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.85.11.139 (JP/Japan/139.11.85.34.bc.googleusercontent.com): (CF_ENABLE)
show less
SQL Injection
๐ช๐ธ
pipeline.es
2026-09-23 20:58:31
(21 hours ago)
Web scanning / probing for vulnerable paths | URL: /secrets.yml | Evidence: goinouttravels.com 34.85 ...
show more
Web scanning / probing for vulnerable paths | URL: /secrets.yml | Evidence: goinouttravels.com 34.85.11.139 - - [23/Sep/2026:22:56:54 +0200] \"GET /secrets.yml HTTP/2.0\" 404 22621 \"-\" \"Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.4; +https://openai.com/gptbot\" GEOIP_COUNTRY_CODE=JP | ASN: GOOGLE-CLOUD-PLATFORM | Country: JP
show less
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 20:03:01
(22 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.85.11.139 (139.11.85.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.85.11.139 (139.11.85.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 16:02:57.473548 2026] [security2:error] [pid 23569:tid 23569] [client 34.85.11.139:52560] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||joesteiner.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "joesteiner.com"] [uri "/z9x8c7v6b5-debug-trigger-joesteiner.com"] [unique_id "arQwcUk4BuYr5m8G5YhLXAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
oukat
2026-09-23 19:58:18
(22 hours ago)
Web bot / web application probing against nginx
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 18:29:32
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.85.11.139 (139.11.85.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.85.11.139 (139.11.85.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 14:29:27.983061 2026] [security2:error] [pid 26365:tid 26365] [client 34.85.11.139:34098] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||macryder.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "macryder.com"] [uri "/z9x8c7v6b5-debug-trigger-macryder.com"] [unique_id "arQah9o3JSZecb5PK6maRwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 17:45:22
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.85.11.139 (139.11.85.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.85.11.139 (139.11.85.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 13:45:17.917443 2026] [security2:error] [pid 14641:tid 14752] [client 34.85.11.139:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mindgardens.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mindgardens.com"] [uri "/z9x8c7v6b5-debug-trigger-mindgardens.com"] [unique_id "arQQLRzASW7NSz6R9qid9gAAAYw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-23 17:33:22
(1 day ago)
[ti-04al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-04al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.85.11.139 - - [23/Sep/2026:19:33:06 +0200] "GET /config/.env.php HTTP/2.0" 301 310 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)"
...
show less
Bad Web Bot
Web App Attack