Anonymous
2026-10-08 21:37:14
(4 minutes ago)
Fail2Ban apache-noscript
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-08 21:18:07
(23 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.86.211.117 (117.211.86.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.86.211.117 (117.211.86.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 17:18:01.499767 2026] [security2:error] [pid 20714:tid 20718] [client 34.86.211.117:43182] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "metrobaselexpoforum.org"] [uri "/.htpasswd"] [unique_id "asgIifSOl4Rchu7w4LoDTwAAAQI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
ruusvuu
2026-10-08 21:06:20
(35 minutes ago)
Automated abuse report: 25 attack/probe requests from Google LLC / US.
Targeted paths: /.npmrc, /@fs ...
show more
Automated abuse report: 25 attack/probe requests from Google LLC / US.
Targeted paths: /.npmrc, /@fs/..%252f..%252f..%252f..%252f..%252fproc/self/environ, /@fs/var/run/secrets/kubernetes.io/serviceaccount/token, /@fs/proc/self/cmdline, /__vite_rsc_findSourceMapURL.
Sample log lines:
[mirassertions] 2026-10-08 14:06:20: 10/8/2026 14:06:20 34.86.211.117 GET /@fs/var/run/secrets/kubernetes.io/serviceaccount/token?raw?? 404 - 0.767 ms -
[mirassertions] 2026-10-08 14:06:20: 10/8/2026 14:06:20 34.86.211.117 GET /@fs/proc/self/cmdline?raw?? 404 - 0.935 ms -
[mirassertions] 2026-10-08 14:06:20: 10/8/2026 14:06:20 34.86.211.117 GET /__vite_rsc_findSourceMapURL?filename=file:///app/.env&environmentName=rsc 404 - 0.999 ms -
Detected by an automated web-server log monitor.
show less
Web App Attack
๐ณ๐ฑ
melroy89
2026-10-08 21:05:21
(36 minutes ago)
34.86.211.117 - - [08/Oct/2026:23:05:01 +0200] "GET /i3g2x5ug43tgtspx4b7t HTTP/2.0" 403 93 "-" "Duc ...
show more
34.86.211.117 - - [08/Oct/2026:23:05:01 +0200] "GET /i3g2x5ug43tgtspx4b7t HTTP/2.0" 403 93 "-" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)" "melroy.org" 0.000
34.86.211.117 - - [08/Oct/2026:23:05:01 +0200] "GET /z9x8c7v6b5-debug-trigger-melroy.org HTTP/2.0" 403 93 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] )" "melroy.org" 0.000
34.86.211.117 - - [08/Oct/2026:23:05:01 +0200] "POST / HTTP/2.0" 403 93 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)" "melroy.org" 0.000
34.86.211.117 - - [08/Oct/2026:23:05:01 +0200] "GET /assets/manifest.json HTTP/2.0" 403 64 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 Edg/153.0.0.0" "melroy.org" 0.000
34.86.211.117 - - [08/Oct/2026:23:05:01 +0200] "POST /graphql HTTP/2.0" 403 64 "https://melroy.org" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, li
...
show less
Web App Attack
๐ฉ๐ช
konseptit
2026-10-08 20:56:28
(45 minutes ago)
(mod_security) mod_security triggered on hostname [redacted] 34.86.211.117 (US/United States/117.211 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.86.211.117 (US/United States/117.211.86.34.bc.googleusercontent.com)
show less
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-10-08 20:28:01
(1 hour ago)
(mod_security) mod_security (id:218420) triggered by 34.86.211.117 (117.211.86.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:218420) triggered by 34.86.211.117 (117.211.86.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 16:27:56.398959 2026] [security2:error] [pid 6343:tid 6343] [client 34.86.211.117:59486] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i)php://(std(in|out|err)|(in|out)put|fd|memory|temp|filter)" at ARGS_NAMES:\\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/21_PHP_PHPGen.conf"] [line "22"] [id "218420"] [rev "2"] [msg "COMODO WAF: PHP Injection Attack: I/O Stream Found||mavikalem.org|F|2"] [data "Matched Data: php://input found within ARGS_NAMES:\\x5cxadd allow_url_include=1 \\x5cxadd auto_prepend_file=php://input: \\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input"] [severity "CRITICAL"] [tag "CWAF"] [tag "PHPGen"] [hostname "mavikalem.org"] [uri "/index.php"] [unique_id "asf8zDHAbVhO6-0PMrjkSgAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-10-08 20:11:41
(1 hour ago)
Web attack/malicious scanning detected
Web App Attack
๐ซ๐ท
LoneRider
2026-10-08 20:11:05
(1 hour ago)
[08/Oct/2026:22:11:05.192113 +0200] asf42ZzwAMCfmFiPg4b8zQAAAAM 34.86.211.117 36574 127.0.0.1 7081
[ ...
show more
[08/Oct/2026:22:11:05.192113 +0200] asf42ZzwAMCfmFiPg4b8zQAAAAM 34.86.211.117 36574 127.0.0.1 7081
[08/Oct/2026:22:11:05.360303 +0200] asf42QITRYB9UfJZEvR_PAAAAAw 34.86.211.117 36608 127.0.0.1 7081
[08/Oct/2026:22:11:05.489224 +0200] asf42Z3AhiwB3obJm7JkCwAAAAY 34.86.211.117 36666 127.0.0.1 7081
...
show less
Hacking
๐ฉ๐ช
bazter.pro
2026-10-08 20:07:22
(1 hour ago)
Fail2Ban: plesk-bot-aggressive - 15 failures
Port Scan
Bad Web Bot
Web App Attack
๐บ๐ธ
Sonoflet
2026-10-08 19:34:28
(2 hours ago)
CrowdSec detection | scenario: http-probing
Port Scan
Web App Attack
๐บ๐ธ
koinkash.org
2026-10-08 19:29:25
(2 hours ago)
They are fraudulent. Malicious threat actor requesting php file /document.php
Web App Attack
๐ซ๐ฎ
JimArchon72
2026-10-08 19:10:04
(2 hours ago)
2026/10/08 19:06:26 "GET /wp-admin/ HTTP/2.0"
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 19:07:48
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.86.211.117 (117.211.86.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.86.211.117 (117.211.86.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 15:07:41.091159 2026] [security2:error] [pid 22655:tid 22655] [client 34.86.211.117:56888] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "honer.org"] [uri "/appearance/../../.env"] [unique_id "asfp_Z6_ei5YH4Wpqnd8FQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
EvilTurkey
2026-10-08 18:59:10
(2 hours ago)
Web app attack against financial institution website.
Web App Attack
Hacking
๐บ๐ธ
etu brutus
2026-10-08 18:53:12
(2 hours ago)
34.86.211.117 has been banned for [WebApp Attack]
...
Hacking
Bad Web Bot
Web App Attack