|
๐ฆ๐บ
user-01
|
|
Multiple WAF violations
|
Web App Attack
|
|
|
๐ง๐ช
sid3windr
|
|
GET /config/aws.json (Tarpitted for 1d15h8m29s, wasted 8.06MB)
|
Web App Attack
|
|
|
๐ณ๐ฑ
Savvii
|
|
20 attempts against mh-misbehave-ban on gold
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐ฉ๐ช
strxmpp
|
|
34.93.33.218 - - [30/May/2026:04:36:33 +0200] "GET /actuator/heapdump HTTP/1.1" 404 495 "-" "Mozilla ...
show more
34.93.33.218 - - [30/May/2026:04:36:33 +0200] "GET /actuator/heapdump HTTP/1.1" 404 495 "-" "Mozilla/5.0 (Linux; Android 9; Mi A2) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.111 Mobile Safari/537.36"
...
show less
|
Bad Web Bot
|
|
|
๐บ๐ธ
mnsf
|
|
Too many Status 40X (365)
Too many Status 50X (199)
Scanning/Probing (52)
Request Overload (564)
|
Brute-Force
Web App Attack
|
|
|
๐บ๐ฆ
URAN Publishing Service
|
|
34.93.33.218 - - [30/May/2026:02:58:46 +0300] "GET /config.env HTTP/1.1" 404 3065 "-" "Mozilla/5.0 ( ...
show more
34.93.33.218 - - [30/May/2026:02:58:46 +0300] "GET /config.env HTTP/1.1" 404 3065 "-" "Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.100 Safari/537.36"
34.93.33.218 - - [30/May/2026:02:58:46 +0300] "GET /secrets.env HTTP/1.1" 404 3064 "-" "Mozilla/5.0 (Linux; U; Android 7.0; en-US; PRA-LX1 Build/HUAWEIPRA-LX1) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/57.0.2987.108 UCBrowser/12.13.0.1207 Mobile Safari/537.36"
...
show less
|
Web App Attack
|
|
|
๐ณ๐ฟ
Antinson
|
|
Scraping with a high error ratio and request rate
|
Bad Web Bot
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210730) triggered by 34.93.33.218 (218.33.93.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.93.33.218 (218.33.93.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 29 18:44:02.321120 2026] [security2:error] [pid 8202:tid 8211] [client 34.93.33.218:44206] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||192.64.150.82|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "192.64.150.82"] [uri "/.config/gcloud/credentials.db"] [unique_id "ahoWst9z6JHSdLYpEuN0zgAAAMQ"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
Anonymous
|
|
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
|
Exploited Host
|
|
|
๐ซ๐ท
Baking333
|
|
[redacted] 34.93.33.218 - - [29/May/2026:03:08:25 +0100] "GET /.aws/config HTTP/1.1" 307 386 "-" "Mo ...
show more
[redacted] 34.93.33.218 - - [29/May/2026:03:08:25 +0100] "GET /.aws/config HTTP/1.1" 307 386 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/65.0.3325.181 Safari/537.36" [redacted] 34.93.33.218 - - [29/May/2026:03:08:25 +0100] "GET /.aws/credentials HTTP/1.1" 307 386 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.87 Safari/537.36"
show less
|
Bad Web Bot
Web App Attack
|
|
|
๐ณ๐ฑ
Savvii
|
|
20 attempts against mh-misbehave-ban on guava
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐ณ๐ฑ
Savvii
|
|
20 attempts against mh-misbehave-ban on ship
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210831) triggered by 34.93.33.218 (218.33.93.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210831) triggered by 34.93.33.218 (218.33.93.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 28 20:54:18.499030 2026] [security2:error] [pid 11938:tid 12058] [client 34.93.33.218:53214] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||192.64.150.21|F|4"] [data "Web Downloader"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "192.64.150.21"] [uri "/api/configprops"] [unique_id "ahjjuiy5caERQk65l6qKMgAAAQA"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|