π§πͺ
cmbplf
2026-10-03 09:43:39
(5 days ago)
433 requests with url.path *.env
Brute-Force
Bad Web Bot
π³π±
Alt255
2026-10-03 07:37:13
(5 days ago)
[ti-30al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-30al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.9.6.210 - - [03/Oct/2026:09:37:12 +0200] "GET /build../.env HTTP/2.0" 301 524 "-" "Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)"
...
show less
Bad Web Bot
Web App Attack
π©πͺ
LRob
2026-10-03 06:57:35
(5 days ago)
Secret file probe | method: GET | path: /.npmrc, /serverless.yml, /.htpasswd (+17 more) | ua: Mozill ...
show more
Secret file probe | method: GET | path: /.npmrc, /serverless.yml, /.htpasswd (+17 more) | ua: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot), Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot), Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/) (+12 more)
show less
Hacking
Web App Attack
π©πͺ
dbmwebdesign
2026-10-03 05:25:13
(5 days ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
π©πͺ
updown.io
2026-10-03 04:38:05
(5 days ago)
{"level":"info","ts":1791002282.8456311,"logger":"http.log.access.log1","msg":"handled request","req ...
show more
{"level":"info","ts":1791002282.8456311,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.9.6.210","remote_port":"35946","client_ip":"34.9.6.210","proto":"HTTP/2.0","method":"GET","host":"status.copicake.com","uri":"/9i3rv0ltqkhont7i13co","headers":{"Accept":["*/*"],"Accept-Encoding":["gzip"],"X-Middleware-Subrequest":["src/middleware:nowaf:src/middleware:src/middleware:src/middleware:src/middleware:middleware:middleware:nowaf:middleware:middleware:middleware:pages/_middleware"],"X-Nextjs-Data":["1"],"User-Agent":["Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"h2","server_name":"status.copicake.com","ech":false}},"bytes_read":0,"user_id":"","duration":0.00023072,"size":0,"status":429,"resp_headers":{"Server":["Caddy"],"Alt-Svc":["h3=\":443\"; ma=2592000"],"Retry-After":["1"]}}
{"level":"info","ts":1791002282.9730794,"logger":"http.log.access.log1","msg":"handled reque
...
show less
DDoS Attack
Web App Attack
π²π½
octageeks.com
2026-10-03 04:07:51
(5 days ago)
Wordpress malicious attack:[octablocked]
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-03 01:16:19
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 34.9.6.210 (210.6.9.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210730) triggered by 34.9.6.210 (210.6.9.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 21:16:15.936666 2026] [security2:error] [pid 6179:tid 6179] [client 34.9.6.210:42476] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||spyasociados.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "spyasociados.com"] [uri "/z9x8c7v6b5-debug-trigger-spyasociados.com"] [unique_id "asBXX-lX3L3SsIkcFCyJgQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-02 23:59:38
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 34.9.6.210 (210.6.9.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210730) triggered by 34.9.6.210 (210.6.9.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 19:59:33.279763 2026] [security2:error] [pid 1957265:tid 1957265] [client 34.9.6.210:39404] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||nakedtyro.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "nakedtyro.com"] [uri "/z9x8c7v6b5-debug-trigger-nakedtyro.com"] [unique_id "asBFZTnIW4ShYK2clG58uQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π·π΄
iulianh
2026-10-02 23:39:19
(5 days ago)
80,443
Brute-Force
SSH
π©πͺ
Petros Stefanakis
2026-10-02 20:12:02
(5 days ago)
(mod_security) mod_security triggered on hostname [redacted] 34.9.6.210 (US/United States/210.6.9.34 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.9.6.210 (US/United States/210.6.9.34.bc.googleusercontent.com)
show less
SQL Injection
πΊπΈ
TPI-Abuse
2026-10-02 18:52:12
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.9.6.210 (210.6.9.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.9.6.210 (210.6.9.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 14:52:09.876970 2026] [security2:error] [pid 7726:tid 7726] [client 34.9.6.210:51198] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "countrysideinnkingston.com"] [uri "/.env"] [unique_id "ar_9Wd8Q8xrVe9X2sMrhtQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Site.eu
2026-10-02 16:11:11
(6 days ago)
Excessive multi-domain requests
Brute-Force
πΊπΈ
TPI-Abuse
2026-10-02 15:43:07
(6 days ago)
(mod_security) mod_security (id:210730) triggered by 34.9.6.210 (210.6.9.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210730) triggered by 34.9.6.210 (210.6.9.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 11:43:01.175278 2026] [security2:error] [pid 10318:tid 10318] [client 34.9.6.210:49734] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.cottrellfamily.com.cottrel.com|F|2"] [data ".cottrellfamily.com.cottrel.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.cottrellfamily.com.cottrel.com"] [uri "/z9x8c7v6b5-debug-trigger-www.cottrellfamily.com.cottrel.com"] [unique_id "ar_RBQ3kBdocKK8g5A-cggAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-02 14:35:32
(6 days ago)
(mod_security) mod_security (id:210730) triggered by 34.9.6.210 (210.6.9.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210730) triggered by 34.9.6.210 (210.6.9.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 10:35:26.165495 2026] [security2:error] [pid 15097:tid 15097] [client 34.9.6.210:47392] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||valkyriepanthers.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "valkyriepanthers.com"] [uri "/z9x8c7v6b5-debug-trigger-valkyriepanthers.com"] [unique_id "ar_BLpzYDXNGjASctQtYAQAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-02 14:12:34
(6 days ago)
(mod_security) mod_security (id:949110) triggered by 34.9.6.210 (210.6.9.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:949110) triggered by 34.9.6.210 (210.6.9.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 10:12:28.903929 2026] [security2:error] [pid 27693:tid 27693] [client 34.9.6.210:57352] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "maricotippett.com"] [uri "/z9x8c7v6b5-debug-trigger-maricotippett.com"] [unique_id "ar-7zAzRu6tItUvVh-3M3gAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack