๐ฎ๐น
CoreTech srl
2026-08-08 12:39:05
(2 months ago)
cloudlinux2 fail2ban: 2026-08-08 14:33:58,938 fail2ban.filter [1467]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-08-08 14:33:58,938 fail2ban.filter [1467]: INFO [plesk-modsecurity] Found 34.12.191.202 - 2026-08-08 14:33:58cloudlinux2 fail2ban: 2026-08-08 14:34:08,060 fail2ban.filter [1467]: INFO [plesk-modsecurity] Found 34.12.191.202 - 2026-08-08 14:34:07cloudlinux2 fail2ban: 2026-08-08 14:34:08,070 fail2ban.filter [1467]: INFO [plesk-modsecurity] Found 34.12.191.202 - 2026-08-08 14:34:07cloudlinux2 fail2ban: 2026-08-08 14:34:08,816 fail2ban.actions [1467]: NOTICE [plesk-modsecurity] Ban 34.12.191.202cloudlinux2 fail2ban: 2026-08-08 14:34:08,913 fail2ban.filter [1467]: INFO [recidive] Found 34.12.191.202 - 2026-08-08 14:34:08cloudlinux2 fail2ban: 2026-08-08 14:34:47,457 fail2ban.filter [1467]: INFO [plesk-modsecurity] Found 86.121.252.53 - 2026-08-08 14:34:47cloudlinux2 fail2ban: 2026-08-08 14:34:45,073 fail2ban.actions [1467]: NOTICE [plesk-modsecurity] Unban 202.63.210.174cloudlinux2 fail2ban: 2026-08-08 14:35:23,412 fai
show less
Brute-Force
๐ณ๐ฑ
e.fierstra
2026-08-08 12:13:40
(2 months ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐บ๐ธ
Operator873
2026-08-08 12:12:07
(2 months ago)
2026/08/08 07:12:04 [error] 92694#0: *1216588 access forbidden by rule, client: 34.85.66.109, server ...
show more
2026/08/08 07:12:04 [error] 92694#0: *1216588 access forbidden by rule, client: 34.85.66.109, server: [OBFUSCATED], request: "GET /@fs/proc/self/environ?import&raw?? HTTP/1.1", host: "mail.ntars.net"
2026/08/08 07:12:04 [error] 92694#0: *1216588 access forbidden by rule, client: 34.85.66.109, server: [OBFUSCATED], request: "GET /@fs/proc/self/environ?import&raw?? HTTP/1.1", host: "mail.ntars.net"
2026/08/08 07:12:04 [error] 92694#0: *1216587 access forbidden by rule, client: 34.85.66.109, server: [OBFUSCATED], request: "GET /media../home/ec2-user/.aws/credentials HTTP/1.1", host: "mail.ntars.net"
2026/08/08 07:12:04 [error] 92694#0: *1216587 access forbidden by rule, client: 34.85.66.109, server: [OBFUSCATED], request: "GET /media../home/ec2-user/.aws/credentials HTTP/1.1", host: "mail.ntars.net"
2026/08/08 07:12:04 [error] 92694#0: *1216589 access forbidden by rule, client: 34.85.66.109, server: [OBFUSCATED], request: "GET /@fs/proc/self/environ?raw?? HTTP/1.1", host: "
...
show less
Brute-Force
Web App Attack
๐ฉ๐ช
klaus_ph
2026-08-08 11:33:05
(2 months ago)
...
Bad Web Bot
๐ณ๐ฑ
BlueWire Hosting
2026-08-08 11:27:15
(2 months ago)
Bad bot ignoring robot.txt
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-08 06:54:08
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 34.85.66.109 (109.66.85.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.85.66.109 (109.66.85.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 08 02:54:04.645901 2026] [security2:error] [pid 3251620:tid 3251655] [client 34.85.66.109:34218] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||hollyandandreproperties.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "hollyandandreproperties.com"] [uri "/z9x8c7v6b5-debug-trigger-hollyandandreproperties.com"] [unique_id "anbSjLOzYlbB0dw-nP-8OAAAAcQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Mundo Bueno
2026-08-08 06:30:45
(2 months ago)
[ISILIA Protection v2.1] Tentative d'accรจs: /.git/config | Pays: JP | UA: anthropic-ai
Hacking
Web App Attack
๐ฎ๐ณ
evicky2002
2026-08-08 06:00:00
(2 months ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ณ๐ด
Bots.go.to.hell
2026-08-08 05:58:48
(2 months ago)
This IP was detected by CrowdSec triggering custom/http-bad-crawler-ban
Web App Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-08 05:26:08
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 34.85.66.109 (109.66.85.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.85.66.109 (109.66.85.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 08 01:26:04.062252 2026] [security2:error] [pid 3443910:tid 3443910] [client 34.85.66.109:41826] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.buynorthwest.com|F|2"] [data ".buynorthwest.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.buynorthwest.com"] [uri "/z9x8c7v6b5-debug-trigger-www.buynorthwest.com"] [unique_id "ana97MByzLr9rbWJEe5CrQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐น๐ญ
thaizone.com
2026-08-08 04:56:51
(2 months ago)
Brute Force Attack on a Web Resources (probe) #2
DDoS Attack
Web Spam
Brute-Force
Web App Attack
Anonymous
2026-08-08 03:59:46
(2 months ago)
By Attack Lagwatch(waf)
DDoS Attack
Web Spam
Hacking
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-08-08 03:29:13
(2 months ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-08 03:24:17
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 34.85.66.109 (109.66.85.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.85.66.109 (109.66.85.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 23:24:12.741659 2026] [security2:error] [pid 4675:tid 4675] [client 34.85.66.109:56480] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "horse7.com"] [uri "/.git/config"] [unique_id "anahXMwxJDqlpx1qBI-xnQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
revslowmo
2026-08-08 02:25:36
(2 months ago)
Bot attempt ssh bruteforce
Brute-Force
SSH