🇩🇪
bazter.pro
2026-09-11 02:27:18
(12 minutes ago)
Fail2Ban: apache-ratelimit - 20 failures
Port Scan
Bad Web Bot
Web App Attack
🇫🇮
Shaik Sai Meera
2026-09-11 02:25:07
(14 minutes ago)
IM360 WAF: Hidden file access
Brute-Force
🇳🇱
mieg
2026-09-11 02:11:59
(27 minutes ago)
Web vulnerability probing
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 01:47:56
(51 minutes ago)
(mod_security) mod_security (id:210730) triggered by 34.88.197.229 (229.197.88.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.88.197.229 (229.197.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 21:47:48.309355 2026] [security2:error] [pid 16893:tid 16893] [client 34.88.197.229:59936] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||dismain.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "dismain.com"] [uri "/z9x8c7v6b5-debug-trigger-dismain.com"] [unique_id "aqNdxJLNPfhCsxqUUNM-rAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
big-cloud.nl
2026-09-11 01:25:12
(1 hour ago)
Try to access /admin%2F.env
Web App Attack
🇸🇪
vaia.cloud
2026-09-11 01:15:03
(1 hour ago)
crowdsecurity/http-cve-2021-41773
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 01:04:23
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 34.88.197.229 (229.197.88.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.88.197.229 (229.197.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 21:04:18.273174 2026] [security2:error] [pid 13901:tid 13901] [client 34.88.197.229:60104] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||cruisingforsex.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "cruisingforsex.com"] [uri "/rclone.conf"] [unique_id "aqNTkmSr280sAZ9sASWL0AAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
andypiper
2026-09-11 01:02:39
(1 hour ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 00:42:58
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 34.88.197.229 (229.197.88.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.88.197.229 (229.197.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 20:42:55.072594 2026] [security2:error] [pid 29566:tid 29566] [client 34.88.197.229:51398] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||comobarbershop.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "comobarbershop.com"] [uri "/rclone.conf"] [unique_id "aqNOj274fFKL9uc__qVMCgAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
cmbplf
2026-09-11 00:22:50
(2 hours ago)
1.036 requests with url.path */@fs/*
480 requests with url.path */proc/*
Brute-Force
Bad Web Bot
🇨🇭
backslash
2026-09-11 00:21:12
(2 hours ago)
block ruleset WAF detection and high score on abuseIPDB 149EB1B42C242111FADBBC2EF8F90219570691E1
Bad Web Bot
Anonymous
2026-09-11 00:12:47
(2 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇩🇪
LRob
2026-09-10 23:58:28
(2 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /rclone.conf | 2026-09-10 23:58 UTC
show less
Hacking
Web App Attack
🇳🇱
Savvii
2026-09-10 23:52:47
(2 hours ago)
20 attempts against mh_ha-misbehave-ban on pf221105
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-10 23:31:54
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.88.197.229 (229.197.88.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.197.229 (229.197.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 19:31:45.469845 2026] [security2:error] [pid 31739:tid 31739] [client 34.88.197.229:38220] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "calvarycavaliers.org"] [uri "/__vite_rsc_findSourceMapURL"] [unique_id "aqM94ckaCVB27tJY-fgvVQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack