Anonymous
2026-10-11 02:49:00
(16 minutes ago)
Banned by Fail2Ban on server
Web App Attack
๐ฌ๐ท
setupgr
2026-10-11 02:19:21
(46 minutes ago)
(mod_security) mod_security (id:11000010) triggered by 34.85.111.243 (JP/Japan/Tokyo/Tokyo/-/[AS3969 ...
show more
(mod_security) mod_security (id:11000010) triggered by 34.85.111.243 (JP/Japan/Tokyo/Tokyo/-/[AS396982 Google LLC]): 1 in the last 86400 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Sun Oct 11 05:19:19.019242 2026] [security2:error] [pid 231235:tid 231277] [remote 34.85.111.243:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "Baiduspider" at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "114"] [id "11000010"] [msg "BLOCKED BOT: Baiduspider on santoriniicon.com"] [severity "ALERT"] [hostname "santoriniicon.com"] [uri "/.gitlab-ci.yml"] [unique_id "asryJ7VuYNVU94quP4kWKwAEzAE"]
show less
Port Scan
๐ซ๐ท
masterguru
2026-10-11 01:50:10
(1 hour ago)
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encod ...
show more
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encoding/ /proxy/ /lock-token/ /content-range/ /if/ /x-http-method-override/ /x-http-method/ /x-method-override/ /x-middleware-subrequest/ /expect/" at TX:header_name_920450_x-middleware-subrequest. (920450-197)
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-11 01:29:11
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.85.111.243 (243.111.85.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.85.111.243 (243.111.85.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 21:29:08.034957 2026] [security2:error] [pid 20099:tid 20099] [client 34.85.111.243:36752] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "samuelcurtis.com"] [uri "/backend/.env"] [unique_id "asrmZHqZPTjSaN_5lxkc7gAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
maxpower
2026-10-11 01:20:10
(1 hour ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.85.111.243 (JP/Japan/243.111.85.34.bc ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.85.111.243 (JP/Japan/243.111.85.34.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.85.111.243 - - [11/Oct/2026:03:20:06 +0200] "GET /.ssh/id_rsa HTTP/2.0" 200 12086 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)" "-" host=samitecnopetrol.com
show less
Port Scan
Anonymous
2026-10-11 01:15:39
(1 hour ago)
34.85.111.243 - - [10/Oct/2026:20:15:30 -0500] "GET /.env.prod HTTP/1.1" 301 245 "-" "Mozilla/5.0 (c ...
show more
34.85.111.243 - - [10/Oct/2026:20:15:30 -0500] "GET /.env.prod HTTP/1.1" 301 245 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)" 162.159.108.2
34.85.111.243 - - [10/Oct/2026:20:15:30 -0500] "GET /.env.old HTTP/1.1" 301 244 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)" 172.71.8.2
34.85.111.243 - - [10/Oct/2026:20:15:30 -0500] "GET /.env.save HTTP/1.1" 301 245 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)" 172.70.123.196
34.85.111.243 - - [10/Oct/2026:20:15:30 -0500] "GET /.env.bak HTTP/1.1" 301 244 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexity-user)" 172.68.85.209
34.85.111.243 - - [10/Oct/2026:20:15:31 -0500] "GET /.env.bak HTTP/1.1" 403 199 "http://sambrownlaw.com/.env.bak" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
andypiper
2026-10-11 01:01:44
(2 hours ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-11 00:58:06
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.85.111.243 (243.111.85.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.85.111.243 (243.111.85.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 20:58:00.691708 2026] [security2:error] [pid 27289:tid 27289] [client 34.85.111.243:49010] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||salonpurelodi.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "salonpurelodi.com"] [uri "/z9x8c7v6b5-debug-trigger-salonpurelodi.com"] [unique_id "asrfGIxw6m28HVqzsAhLYwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-11 00:41:49
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.85.111.243 (243.111.85.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.85.111.243 (243.111.85.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 20:41:45.834198 2026] [security2:error] [pid 11747:tid 11747] [client 34.85.111.243:47990] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||salazartransfers.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "salazartransfers.com"] [uri "/z9x8c7v6b5-debug-trigger-salazartransfers.com"] [unique_id "asrbSRsB4flyhVSs8kCVrQAAAEA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-11 00:23:53
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.85.111.243 (243.111.85.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.85.111.243 (243.111.85.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 20:23:48.722039 2026] [security2:error] [pid 29002:tid 29002] [client 34.85.111.243:42744] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||sailyourkayak.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "sailyourkayak.com"] [uri "/z9x8c7v6b5-debug-trigger-sailyourkayak.com"] [unique_id "asrXFEpNDOIMSVZkusZlWQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
rh24
2026-10-11 00:13:59
(2 hours ago)
(badbots) Bad bot user-agent [redacted] from 34.85.111.243 (JP/Japan/243.111.85.34.bc.googleusercont ...
show more
(badbots) Bad bot user-agent [redacted] from 34.85.111.243 (JP/Japan/243.111.85.34.bc.googleusercontent.com)
show less
Hacking
๐บ๐ธ
dot.mg
2026-10-11 00:13:02
(2 hours ago)
Bad behaviour
Web Spam
๐บ๐ธ
Lee Daniel
2026-10-11 00:01:54
(3 hours ago)
34.85.111.243 - - [10/Oct/2026:20:01:52 -0400] "GET /.env HTTP/1.1" 403 6293 "-" "Mozilla/5.0 (compa ...
show more
34.85.111.243 - - [10/Oct/2026:20:01:52 -0400] "GET /.env HTTP/1.1" 403 6293 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)"
...
show less
DDoS Attack
Web Spam
Email Spam
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
Mediashaker
2026-10-11 00:01:45
(3 hours ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 34.85.111.243 (JP/Ja ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 34.85.111.243 (JP/Japan/243.111.85.34.bc.googleusercontent.com)
show less
Bad Web Bot
๐ณ๐ฑ
Savvii
2026-10-10 22:49:31
(4 hours ago)
20 attempts against mh-misbehave-ban on ozone
Brute-Force
Bad Web Bot
Web App Attack