๐ณ๐จ
ACE-INFORMATIQUE.NC
2026-10-02 06:00:11
(3 hours ago)
Malicious CGI/web attack blocked by Fail2ban
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-01 17:30:24
(15 hours ago)
[ti-07al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apac ...
show more
[ti-07al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apache-404. Example: 34.87.52.199 - - [01/Oct/2026:19:30:22 +0200] "GET /model/info HTTP/1.1" 404 2050 "-" "Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)"
34.87.52.199 - - [01/Oct/2026:19:30:22 +0200] "GET /z9x8c7v6b5-debug-trigger-ictdokters.nl HTTP/1.1" 404 2050 "-" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)"
34.87.52.199 - - [01/Oct/2026:19:30:22 +0200] "GET /3tvrp9rr1c2sfu748fcw HTTP/1.1" 404 7386 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)"
34.87.52.199 - - [01/Oct/2026:19:30:22 +0200] "GET /model/info HTTP/1.1" 404 7386 "-" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)"
34.87.52.199
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 17:21:29
(15 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.87.52.199 (199.52.87.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.87.52.199 (199.52.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 13:21:24.714842 2026] [security2:error] [pid 17313:tid 17313] [client 34.87.52.199:43280] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.asiabeef.network|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.asiabeef.network"] [uri "/server.key"] [unique_id "ar6WlDVEghx9zIf8J2o8ZQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฟ๐ฆ
simon boshoff
2026-10-01 16:38:36
(16 hours ago)
RdpGuard detected brute-force attempt on HTTP
Brute-Force
๐ฎ๐น
alessio loto
2026-10-01 15:59:00
(17 hours ago)
WAF Detection: URI_Injection_Detected (High Risk IP). AI Confirmed Attack Payload.
Web App Attack
๐ช๐ธ
robotstxt
2026-10-01 15:58:34
(17 hours ago)
34.87.52.199 - - [01/Oct/2026:15:58:16 +0000] "GET / HTTP/2.0" 403 38440 "-" "Mozilla/5.0 (Linux; An ...
show more
34.87.52.199 - - [01/Oct/2026:15:58:16 +0000] "GET / HTTP/2.0" 403 38440 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36 EdgA/152.0.0.0" "34.87.52.199" edge="172.71.211.37"
34.87.52.199 - - [01/Oct/2026:15:58:18 +0000] "GET /manifest.json HTTP/2.0" 403 34082 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36 EdgA/152.0.0.0" "34.87.52.199" edge="172.71.211.37"
34.87.52.199 - - [01/Oct/2026:15:58:18 +0000] "GET /static/manifest.json HTTP/2.0" 403 34122 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36 EdgA/152.0.0.0" "34.87.52.199" edge="172.71.211.37"
34.87.52.199 - - [01/Oct/2026:15:58:18 +0000] "GET /assets/manifest.json HTTP/2.0" 403 34120 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36 EdgA/152.0.0.0" "34.87.52.199"
...
show less
Web App Attack
Anonymous
2026-10-01 15:09:02
(18 hours ago)
34.87.52.199 - - [01/Oct/2026:16:08:59 +0100] "POST /cgi-bin/php-cgi.exe?%ADd+allow_url_include%3d1+ ...
show more
34.87.52.199 - - [01/Oct/2026:16:08:59 +0100] "POST /cgi-bin/php-cgi.exe?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input HTTP/1.1" 404 118 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)"
34.87.52.199 - - [01/Oct/2026:16:08:59 +0100] "POST /cgi-bin/php?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input HTTP/1.1" 404 118 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)"
34.87.52.199 - - [01/Oct/2026:16:08:59 +0100] "POST /cgi-bin/php-cgi?-d+allow_url_include%3don+-d+auto_prepend_file%3dphp://input HTTP/1.1" 404 118 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)"
34.87.52.199 - - [01/Oct/2026:16:08:59 +0100] "POST /cgi-bin/php?-d+allow_url_include%3don+-d+auto_prepend_file%3dphp://input HTTP/1.1" 404 118 "-" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)"
...
show less
Bad Web Bot
Web App Attack
๐ต๐ฑ
wHosts
2026-10-01 13:14:46
(20 hours ago)
Blocked by Fail2Ban
Web App Attack
Anonymous
2026-10-01 12:22:44
(20 hours ago)
Portscan: TCP/8443 (3x), TCP/8080 (3x), TCP/80, TCP/443
Port Scan
๐ช๐ธ
robotstxt
2026-10-01 11:18:11
(21 hours ago)
34.87.52.199 - - [01/Oct/2026:11:17:29 +0000] "GET /manifest.json HTTP/2.0" 403 34114 "https://ccoo. ...
show more
34.87.52.199 - - [01/Oct/2026:11:17:29 +0000] "GET /manifest.json HTTP/2.0" 403 34114 "https://ccoo.cat/manifest.json" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36 EdgA/152.0.0.0" "34.87.52.199" edge="162.158.163.134"
34.87.52.199 - - [01/Oct/2026:11:17:29 +0000] "GET /dist/manifest.json HTTP/2.0" 403 34278 "https://ccoo.cat/dist/manifest.json" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36 EdgA/152.0.0.0" "34.87.52.199" edge="162.158.163.134"
34.87.52.199 - - [01/Oct/2026:11:17:29 +0000] "GET /static/manifest.json HTTP/2.0" 403 34127 "https://ccoo.cat/static/manifest.json" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36 EdgA/152.0.0.0" "34.87.52.199" edge="162.158.163.134"
34.87.52.199 - - [01/Oct/2026:11:17:29 +0000] "GET /assets/manifest.json HTTP/2.0" 403 34266 "https://ccoo.cat/assets/
...
show less
Web App Attack
๐ณ๐ฑ
Site.eu
2026-10-01 10:57:26
(22 hours ago)
Excessive multi-domain requests
Brute-Force
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-10-01 10:43:38
(22 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐ง๐ช
cmbplf
2026-10-01 10:33:07
(22 hours ago)
305 requests with url.path */@fs/*
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-01 10:24:39
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.87.52.199 (199.52.87.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.52.199 (199.52.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 06:24:31.642617 2026] [security2:error] [pid 28464:tid 28530] [client 34.87.52.199:39096] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/Web.config" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.aspencommission.com"] [uri "/web.config"] [unique_id "ar4033j1P4yjetc8l4UmxAAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-01 10:15:31
(23 hours ago)
[ti-02ov] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-02ov] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.87.52.199 - - [01/Oct/2026:12:15:23 +0200] "GET /static//.env HTTP/2.0" 404 2004 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)"
...
show less
Bad Web Bot
Web App Attack