๐บ๐ธ
kbeezie
2026-09-23 18:48:00
(2 minutes ago)
2026/09/23 12:08:44 [error] 356958#356958: *130979 access forbidden by rule, client: 34.95.186.71, s ...
show more
2026/09/23 12:08:44 [error] 356958#356958: *130979 access forbidden by rule, client: 34.95.186.71, server: rawemotionvisuals.com, request: "GET /config/env/aws_credentials.env HTTP/1.1", host: "rawemotionvisuals.com"
2026/09/23 14:07:06 [error] 356958#356958: *132599 access forbidden by rule, client: 34.95.186.71, server: bboutit.com, request: "GET /.dockerenv HTTP/1.1", host: "bboutit.com"
2026/09/23 14:48:00 [error] 356958#356958: *136969 access forbidden by rule, client: 34.95.186.71, server: bboutit.com, request: "GET /.env.prod HTTP/1.1", host: "www.bboutit.com"
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 18:32:12
(18 minutes ago)
(mod_security) mod_security (id:210730) triggered by 34.95.186.71 (71.186.95.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.95.186.71 (71.186.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 14:32:05.318145 2026] [security2:error] [pid 27797:tid 27797] [client 34.95.186.71:54440] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||321q.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "321q.com"] [uri "/z9x8c7v6b5-debug-trigger-321q.com"] [unique_id "arQbJZAm_qAPbtgp7RyaDAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-23 18:30:04
(20 minutes ago)
CrowdSec decision: crowdsecurity/http-bad-user-agent (origin: crowdsec)
Port Scan
๐บ๐ธ
TPI-Abuse
2026-09-23 17:55:29
(55 minutes ago)
(mod_security) mod_security (id:210730) triggered by 34.95.186.71 (71.186.95.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.95.186.71 (71.186.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 13:55:25.742100 2026] [security2:error] [pid 2796130:tid 2796130] [client 34.95.186.71:33498] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||catholicshopper.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "catholicshopper.com"] [uri "/z9x8c7v6b5-debug-trigger-catholicshopper.com"] [unique_id "arQSjUtdD4eW23IqNBisfQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 17:18:12
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 34.95.186.71 (71.186.95.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.95.186.71 (71.186.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 13:18:05.198468 2026] [security2:error] [pid 13226:tid 13226] [client 34.95.186.71:46166] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||goatedlottosecrets.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "goatedlottosecrets.com"] [uri "/z9x8c7v6b5-debug-trigger-goatedlottosecrets.com"] [unique_id "arQJzR57YypZ1l6fKldHxAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Phenix Info
2026-09-23 17:10:40
(1 hour ago)
SmallGuard.fr/Prestashop Forbidden Ext.
Web App Attack
๐ฉ๐ช
itsolon
2026-09-23 17:02:21
(1 hour ago)
[23/Sep/2026:19:02:20 +0200] 179018294057.611975 34.95.186.71 59034 217.154.7.177 443
[23/Sep/2026:1 ...
show more
[23/Sep/2026:19:02:20 +0200] 179018294057.611975 34.95.186.71 59034 217.154.7.177 443
[23/Sep/2026:19:02:20 +0200] 179018294025.206744 34.95.186.71 59034 217.154.7.177 443
[23/Sep/2026:19:02:20 +0200] 179018294089.470340 34.95.186.71 59034 217.154.7.177 443
[23/Sep/2026:19:02:20 +0200] 179018294017.268223 34.95.186.71 42462 217.154.7.177 443
[23/Sep/2026:19:02:20 +0200] 179018294085.980384 34.95.186.71 42462 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 16:59:31
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 34.95.186.71 (71.186.95.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.95.186.71 (71.186.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 12:59:28.436767 2026] [security2:error] [pid 19603:tid 19603] [client 34.95.186.71:40724] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||joesteiner.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "joesteiner.com"] [uri "/z9x8c7v6b5-debug-trigger-joesteiner.com"] [unique_id "arQFcDxaI6DbU71Z_ye1XQAAADI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
Mediashaker
2026-09-23 16:29:56
(2 hours ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 34.95.186.71 (BR/Bra ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 34.95.186.71 (BR/Brazil/71.186.95.34.bc.googleusercontent.com)
show less
Bad Web Bot
๐ณ๐ฑ
Alt255
2026-09-23 16:22:41
(2 hours ago)
[ti-22al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-22al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.95.186.71 - - [23/Sep/2026:18:22:35 +0200] "GET /.env.save HTTP/2.0" 301 49 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 16:19:44
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.95.186.71 (71.186.95.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.95.186.71 (71.186.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 12:19:37.429682 2026] [security2:error] [pid 20187:tid 20219] [client 34.95.186.71:44228] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||piazza9.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "piazza9.com"] [uri "/z9x8c7v6b5-debug-trigger-piazza9.com"] [unique_id "arP8GWjdMxlOlU_DMYKIKgAAAEg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
kbeezie
2026-09-23 16:08:43
(2 hours ago)
34.95.186.71 - - [23/Sep/2026:12:08:43 -0400] "POST /graphql HTTP/1.1" 429 564 "https://rawemotionvi ...
show more
34.95.186.71 - - [23/Sep/2026:12:08:43 -0400] "POST /graphql HTTP/1.1" 429 564 "https://rawemotionvisuals.com" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Mobile Safari/537.36"
34.95.186.71 - - [23/Sep/2026:12:08:43 -0400] "GET /backoffice HTTP/1.1" 429 564 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Mobile Safari/537.36"
34.95.186.71 - - [23/Sep/2026:12:08:43 -0400] "GET /dashboard HTTP/1.1" 429 564 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Mobile Safari/537.36"
34.95.186.71 - - [23/Sep/2026:12:08:43 -0400] "GET /app HTTP/1.1" 429 564 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Mobile Safari/537.36"
34.95.186.71 - - [23/Sep/2026:12:08:43 -0400] "GET /console HTTP/1.1" 429 564 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Mobile Safari/537.36"
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 15:52:43
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.95.186.71 (71.186.95.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.95.186.71 (71.186.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 11:52:39.968494 2026] [security2:error] [pid 23143:tid 23161] [client 34.95.186.71:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||raytbrown.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "raytbrown.com"] [uri "/z9x8c7v6b5-debug-trigger-raytbrown.com"] [unique_id "arP1x6uFkkkwiTpzmjsvPwAAAVA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-09-23 15:45:05
(3 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 15:26:46
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.95.186.71 (71.186.95.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.95.186.71 (71.186.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 11:26:39.114461 2026] [security2:error] [pid 14777:tid 14777] [client 34.95.186.71:47502] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||rcjlawfirm.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "rcjlawfirm.com"] [uri "/z9x8c7v6b5-debug-trigger-rcjlawfirm.com"] [unique_id "arPvr9KVf38gmW55PmzOegAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack