๐ฌ๐ง
consul.to
2026-10-02 15:48:28
(11 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 15:41:27
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.95.177.57 (57.177.95.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.95.177.57 (57.177.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 11:41:21.626101 2026] [security2:error] [pid 6882:tid 6882] [client 34.95.177.57:34706] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.zimmerscheidt.org"] [uri "/media../.env"] [unique_id "ar_QoWpnY2tq49tKHqUFZAAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
bigscoots.com
2026-10-02 14:57:14
(12 hours ago)
(PERMBLOCK) 34.95.177.57 (US/United States/57.177.95.34.bc.googleusercontent.com) has had more than ...
show more
(PERMBLOCK) 34.95.177.57 (US/United States/57.177.95.34.bc.googleusercontent.com) has had more than 4 temp blocks in the last 86400 secs; Ports: *; Direction: 1; Trigger: LF_PERMBLOCK_COUNT; Logs:
show less
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-10-02 14:17:27
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.95.177.57 (57.177.95.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.95.177.57 (57.177.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 10:17:22.418190 2026] [security2:error] [pid 15950:tid 15950] [client 34.95.177.57:53100] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.valueproducersalliance.org"] [uri "/.htpasswd"] [unique_id "ar-88h-WYMETrLClciF_gAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 13:39:51
(13 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.95.177.57 (57.177.95.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.95.177.57 (57.177.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 09:39:44.367939 2026] [security2:error] [pid 5399:tid 5399] [client 34.95.177.57:51042] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.wpcoc.org|F|2"] [data ".axd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.wpcoc.org"] [uri "/elmah.axd"] [unique_id "ar-0IFJEx1id_xs-WTi8jwAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
macrob
2026-10-02 13:02:22
(14 hours ago)
2026/10/02 13:02:20 [error] 2231820#2231820: *8647380 access forbidden by rule, client: 34.95.177.57 ...
show more
2026/10/02 13:02:20 [error] 2231820#2231820: *8647380 access forbidden by rule, client: 34.95.177.57, server: fn.binixo.es, request: "GET /dist/.vite/manifest.json HTTP/2.0", host: "preview.wynspire.org"
2026/10/02 13:02:20 [error] 2231815#2231815: *8647402 access forbidden by rule, client: 34.95.177.57, server: fn.binixo.es, request: "GET /.vite/manifest.json HTTP/2.0", host: "preview.wynspire.org"
2026/10/02 13:02:20 [error] 2231819#2231819: *8647442 access forbidden by rule, client: 34.95.177.57, server: fn.binixo.es, request: "GET /admin HTTP/2.0", host: "preview.wynspire.org"
...
show less
Web App Attack
๐ต๐น
rncbc
2026-10-02 11:34:16
(15 hours ago)
[Fri Oct 02 12:34:04.604806 2026] [authz_core:error] [pid 347544:tid 347544] [client 34.95.177.57:36 ...
show more
[Fri Oct 02 12:34:04.604806 2026] [authz_core:error] [pid 347544:tid 347544] [client 34.95.177.57:36362] AH01630: client denied by server configuration: /srv/www/vhosts/rncbc/server-status, referer: https://rncbc.org/server-status
[Fri Oct 02 12:34:12.978596 2026] [authz_core:error] [pid 347546:tid 347546] [client 34.95.177.57:36376] AH01630: client denied by server configuration: /srv/www/cgi-bin/php-cgi.exe, referer: https://rncbc.org/cgi-bin/php-cgi.exe?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input
[Fri Oct 02 12:34:15.552551 2026] [authz_core:error] [pid 347546:tid 347546] [client 34.95.177.57:36376] AH01630: client denied by server configuration: /srv/www/cgi-bin/php-cgi, referer: https://rncbc.org/cgi-bin/php-cgi?-d+allow_url_include%3don+-d+auto_prepend_file%3dphp://input
...
show less
Brute-Force
Bad Web Bot
Web App Attack
SSH
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-10-02 10:24:10
(17 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-bad-user-agent
Web App Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-02 09:54:42
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.95.177.57 (57.177.95.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.95.177.57 (57.177.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 05:54:35.289197 2026] [security2:error] [pid 26835:tid 26835] [client 34.95.177.57:36844] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.vandermeerlab.org"] [uri "/uploads../.env"] [unique_id "ar9_WwROQ2mXDRWndn_G4QAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 09:16:59
(18 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.95.177.57 (57.177.95.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.95.177.57 (57.177.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 05:16:54.386658 2026] [security2:error] [pid 10528:tid 10528] [client 34.95.177.57:33456] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||marxistphilosophy.org|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "marxistphilosophy.org"] [uri "/config.php.bak"] [unique_id "ar92hrf5KPGSGgamYeduJgAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
macrob
2026-10-02 08:28:23
(19 hours ago)
2026/10/02 08:28:21 [error] 2173945#2173945: *7842456 access forbidden by rule, client: 34.95.177.57 ...
show more
2026/10/02 08:28:21 [error] 2173945#2173945: *7842456 access forbidden by rule, client: 34.95.177.57, server: fn.binixo.es, request: "GET /.vite/manifest.json HTTP/2.0", host: "stg.wynspire.org"
2026/10/02 08:28:21 [error] 2173945#2173945: *7842461 access forbidden by rule, client: 34.95.177.57, server: fn.binixo.es, request: "GET /dist/.vite/manifest.json HTTP/2.0", host: "stg.wynspire.org"
2026/10/02 08:28:22 [error] 2173940#2173940: *7842493 access forbidden by rule, client: 34.95.177.57, server: fn.binixo.es, request: "GET /admin HTTP/2.0", host: "stg.wynspire.org"
...
show less
Web App Attack
๐ฉ๐ช
paissangroup
2026-10-02 08:20:00
(19 hours ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 07:56:56
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.95.177.57 (57.177.95.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.95.177.57 (57.177.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 03:56:50.585593 2026] [security2:error] [pid 27333:tid 27333] [client 34.95.177.57:55328] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.votefordave.org"] [uri "/static../.env"] [unique_id "ar9jwn0wBaudLtawJCIngAAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-10-02 07:20:02
(20 hours ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
๐ณ๐ฑ
EGP Abuse Dept
2026-10-02 07:19:52
(20 hours ago)
Unauthorized connection to proxy port 8080
Port Scan
Hacking