๐ณ๐ฑ
Savvii
2026-09-30 16:20:45
(7 minutes ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 15:51:29
(36 minutes ago)
(mod_security) mod_security (id:210730) triggered by 34.95.161.200 (200.161.95.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.95.161.200 (200.161.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 11:51:25.487588 2026] [security2:error] [pid 26643:tid 26643] [client 34.95.161.200:36048] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.robcruickshank.com|F|2"] [data ".robcruickshank.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.robcruickshank.com"] [uri "/z9x8c7v6b5-debug-trigger-www.robcruickshank.com"] [unique_id "ar0v_S_biNFE8Zq8SETC9wAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 15:27:11
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.95.161.200 (200.161.95.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.95.161.200 (200.161.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 11:27:06.435216 2026] [security2:error] [pid 31172:tid 31172] [client 34.95.161.200:41762] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.smogsandiego.com"] [uri "/.env.php.bak"] [unique_id "ar0qSgv_ApJvV-QdoNIZSAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-30 14:29:08
(1 hour ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-30 12:29:47
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.95.161.200 (200.161.95.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.95.161.200 (200.161.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 08:29:40.781693 2026] [security2:error] [pid 6027:tid 6027] [client 34.95.161.200:54092] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ronnycarrera.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ronnycarrera.com"] [uri "/z9x8c7v6b5-debug-trigger-ronnycarrera.com"] [unique_id "ar0AtGISIY8xSfY5flQZ6AAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 11:37:44
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.95.161.200 (200.161.95.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.95.161.200 (200.161.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 07:37:39.906969 2026] [security2:error] [pid 23865:tid 23865] [client 34.95.161.200:54454] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.robcohn.com|F|2"] [data ".robcohn.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.robcohn.com"] [uri "/z9x8c7v6b5-debug-trigger-www.robcohn.com"] [unique_id "arz0g5epxThEYblfQ1LQ1gAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
updown.io
2026-09-30 11:30:18
(4 hours ago)
{"level":"info","ts":1790767811.2466788,"logger":"http.log.access.log1","msg":"handled request","req ...
show more
{"level":"info","ts":1790767811.2466788,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.95.161.200","remote_port":"39516","client_ip":"34.95.161.200","proto":"HTTP/2.0","method":"GET","host":"status.gpltimes.com","uri":"/webpack-stats.json","headers":{"Priority":["u=0, i"],"Sec-Fetch-Site":["none"],"X-Middleware-Subrequest":["src/middleware:nowaf:src/middleware:src/middleware:src/middleware:src/middleware:middleware:middleware:nowaf:middleware:middleware:middleware:pages/_middleware"],"Sec-Ch-Ua-Platform":["\"Windows\""],"Sec-Ch-Ua-Mobile":["?0"],"Sec-Ch-Ua":["\"Chromium\";v=\"152\", \"Not?A_Brand\";v=\"24\", \"Brave\";v=\"152\""],"Accept":["text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8"],"Sec-Fetch-Dest":["document"],"Accept-Encoding":["gzip, deflate, br, zstd"],"Sec-Fetch-User":["?1"],"User-Agent":["Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36"
...
show less
DDoS Attack
Web App Attack
Anonymous
2026-09-30 11:30:03
(4 hours ago)
CrowdSec decision: crowdsecurity/http-admin-interface-probing (origin: crowdsec)
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-09-30 11:27:07
(5 hours ago)
excessive HTTP 404 errors
Bad Web Bot
๐บ๐ธ
nyt
2026-09-30 11:15:12
(5 hours ago)
POST to Unknown PHP, Accessing restricted file path, potential probing attempt.
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-30 11:13:18
(5 hours ago)
20 attempts against mh_ha-misbehave-ban on ethyl
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
pipeline.es
2026-09-30 10:58:02
(5 hours ago)
Web scanning / probing for vulnerable paths | URL: /pages/api/index.astro.mjs.map | Evidence: micros ...
show more
Web scanning / probing for vulnerable paths | URL: /pages/api/index.astro.mjs.map | Evidence: microsites.grupoeuropa.com 34.95.161.200 - - [30/Sep/2026:12:55:53 +0200] \"GET /pages/api/index.astro.mjs.map HTTP/1.1\" 404 - \"-\" \"CCBot/2.0 (https://commoncrawl.org/faq/)\" GEOIP_COUNTRY_CODE=BR | ASN: GOOGLE-CLOUD-PLATFORM | Country: BR
show less
Port Scan
Web App Attack
๐บ๐ธ
solantex
2026-09-30 10:56:41
(5 hours ago)
Unauthorized automated scanning and reconnaissance against Solantex resources. No crawl, scan or tes ...
show more
Unauthorized automated scanning and reconnaissance against Solantex resources. No crawl, scan or test permission has been granted to this source.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 10:54:11
(5 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.95.161.200 (200.161.95.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.95.161.200 (200.161.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 06:54:03.744091 2026] [security2:error] [pid 1286:tid 1286] [client 34.95.161.200:38370] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.wolter-hausser.com|F|2"] [data ".wolter-hausser.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.wolter-hausser.com"] [uri "/z9x8c7v6b5-debug-trigger-www.wolter-hausser.com"] [unique_id "arzqS2mFiJ-f4QPfF4TEeQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-09-30 10:45:04
(5 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack