πΊπΈ
TPI-Abuse
2026-09-24 12:04:49
(14 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.85.231.157 (157.231.85.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.85.231.157 (157.231.85.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 08:04:41.279977 2026] [security2:error] [pid 5069:tid 5069] [client 34.85.231.157:45620] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mrbaystreet.crossfiregold.com|F|2"] [data ".crossfiregold.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mrbaystreet.crossfiregold.com"] [uri "/z9x8c7v6b5-debug-trigger-mrbaystreet.crossfiregold.com"] [unique_id "arUR2RR0t4nqju3htEPySwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
[email protected]
2026-09-24 11:29:23
(15 hours ago)
CrowdSec ban: crowdsecurity/unifi-flood-detection (duration: 71h59m59s)
Port Scan
πΊπΈ
TAY
2026-09-24 11:14:59
(15 hours ago)
34.85.231.157 - - [24/Sep/2026:19:14:46 +0800] "GET /wp-config.php.bak HTTP/1.1" 404 363 "-" "Mozill ...
show more
34.85.231.157 - - [24/Sep/2026:19:14:46 +0800] "GET /wp-config.php.bak HTTP/1.1" 404 363 "-" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)"
34.85.231.157 - - [24/Sep/2026:19:14:46 +0800] "GET /wp-config.php.old HTTP/1.1" 404 363 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )"
34.85.231.157 - - [24/Sep/2026:19:14:46 +0800] "GET /wp-config.php~ HTTP/1.1" 404 363 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)"
34.85.231.157 - - [24/Sep/2026:19:14:46 +0800] "GET /wp-config.php.swp HTTP/1.1" 404 363 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)"
34.85.231.157 - - [24/Sep/2026:19:14:49 +0800] "GET /_image?href=/../../../.env HTTP/1.1" 404 363 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.4; +https://openai.com/gptbot"
34.85.231.157 - - [24/Sep/2026:19:14:54 +0800] "GET /static/../../../a/../../../../proc/self/environ HTTP/1.1" 400 414 "-" "Mozilla/5.0 AppleWebKi
...
show less
Brute-Force
π©πͺ
EGP Abuse Dept
2026-09-24 06:29:18
(20 hours ago)
Scanning for web/db/file exploits on shop.moviewalks.com
SQL Injection
Bad Web Bot
Web App Attack
Anonymous
2026-09-24 05:14:58
(21 hours ago)
Aggressive web scan
Web App Attack
π©πͺ
itsolon
2026-09-24 04:11:23
(22 hours ago)
[24/Sep/2026:06:11:22 +0200] 179022308258.343265 34.85.231.157 0 217.154.7.177 443
[24/Sep/2026:06:1 ...
show more
[24/Sep/2026:06:11:22 +0200] 179022308258.343265 34.85.231.157 0 217.154.7.177 443
[24/Sep/2026:06:11:22 +0200] 179022308279.167596 34.85.231.157 0 217.154.7.177 443
[24/Sep/2026:06:11:22 +0200] 179022308284.115945 34.85.231.157 0 217.154.7.177 443
[24/Sep/2026:06:11:22 +0200] 179022308291.909439 34.85.231.157 0 217.154.7.177 443
[24/Sep/2026:06:11:22 +0200] 17902230824.920198 34.85.231.157 0 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
Anonymous
2026-09-24 04:04:34
(22 hours ago)
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: US, Attack patterns: Word ...
show more
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: US, Attack patterns: WordPress scanning, Backup file probing, Cloud secrets probing
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-24 02:14:52
(1 day ago)
PSCSERV WPSCAN 34.85.231.157
Bad Web Bot
Web App Attack
Anonymous
2026-09-24 02:10:17
(1 day ago)
34.85.231.157 - - [23/Sep/2026:20:43:34 -0500] "GET /.env.prod HTTP/1.1" 403 199 "-" "Mozilla/5.0 (c ...
show more
34.85.231.157 - - [23/Sep/2026:20:43:34 -0500] "GET /.env.prod HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/)" 104.22.101.98
34.85.231.157 - - [23/Sep/2026:21:10:15 -0500] "GET /.env.dev HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36; compatible; OAI-SearchBot/1.4; +https://openai.com/searchbot" 34.85.231.157
34.85.231.157 - - [23/Sep/2026:21:10:15 -0500] "GET /.env.php.bak HTTP/1.1" 403 199 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] )" 34.85.231.157
34.85.231.157 - - [23/Sep/2026:21:10:15 -0500] "GET /.env.swp HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)" 34.85.231.157
34.85.231.157 - - [23/Sep/2026:21:10:16 -0500] "GET /.env.development HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)" 34.85.231.157
34.85.231.157
...
show less
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
andypiper
2026-09-24 01:00:50
(1 day ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-24 00:15:22
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.85.231.157 (157.231.85.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.85.231.157 (157.231.85.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 20:15:17.997166 2026] [security2:error] [pid 17554:tid 17554] [client 34.85.231.157:45960] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.robertmcatee.com|F|2"] [data ".robertmcatee.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.robertmcatee.com"] [uri "/z9x8c7v6b5-debug-trigger-www.robertmcatee.com"] [unique_id "arRrlaLSJvDo_FbpehpglgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
itsolon
2026-09-23 21:38:05
(1 day ago)
[23/Sep/2026:23:38:02 +0200] 17901994823.020398 34.85.231.157 41130 217.154.7.177 443
[23/Sep/2026:2 ...
show more
[23/Sep/2026:23:38:02 +0200] 17901994823.020398 34.85.231.157 41130 217.154.7.177 443
[23/Sep/2026:23:38:02 +0200] 179019948292.101979 34.85.231.157 41130 217.154.7.177 443
[23/Sep/2026:23:38:02 +0200] 179019948232.089074 34.85.231.157 41130 217.154.7.177 443
[23/Sep/2026:23:38:04 +0200] 179019948489.710966 34.85.231.157 41130 217.154.7.177 443
[23/Sep/2026:23:38:04 +0200] 179019948450.342279 34.85.231.157 41130 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
π¨π
lufi
2026-09-23 21:02:10
(1 day ago)
2026-09-23 23:02:09 34.85.231.157: blacklistedPath: /env.bak
...
Web Spam
Brute-Force
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-23 20:58:16
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.85.231.157 (157.231.85.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.85.231.157 (157.231.85.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 16:58:08.832916 2026] [security2:error] [pid 29368:tid 29368] [client 34.85.231.157:51588] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||aguasolar.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "aguasolar.com"] [uri "/z9x8c7v6b5-debug-trigger-aguasolar.com"] [unique_id "arQ9YBDTwIeMCEOV0FO6lwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
bazter.pro
2026-09-23 20:19:14
(1 day ago)
Fail2Ban: plesk-bot-aggressive - 15 failures
Port Scan
Bad Web Bot
Web App Attack