๐ง๐ช
cmbplf
2026-09-30 05:36:25
(2 days ago)
336 requests with url.path */@fs/*
Brute-Force
Bad Web Bot
Anonymous
2026-09-30 04:24:06
(2 days ago)
Bot / scanning and/or hacking attempts: POST /api/v1/node-load-method/customMCP HTTP/2.0, POST /api/ ...
show more
Bot / scanning and/or hacking attempts: POST /api/v1/node-load-method/customMCP HTTP/2.0, POST /api/templates/preview HTTP/2.0, GET /privatekey.key HTTP/2.0, POST /flowise/api/v1/node-load-method/customMCP HTTP/2.0, POST /exec-py HTTP/2.0, POST /cgi-bin/php-cgi?-d+allow_url_include%3don+-d+auto_prepend
show less
Hacking
Web App Attack
๐ฉ๐ช
Marco711
2026-09-30 04:21:40
(2 days ago)
port/URL scanning
Port Scan
Web App Attack
Anonymous
2026-09-30 03:03:45
(2 days ago)
$f2bV_matches
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 01:38:50
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.95.4.198 (198.4.95.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.95.4.198 (198.4.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 21:38:43.164344 2026] [security2:error] [pid 30999:tid 30999] [client 34.95.4.198:44228] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||notepromd.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "notepromd.com"] [uri "/z9x8c7v6b5-debug-trigger-notepromd.com"] [unique_id "arxoIxf4ezouBeOH-2guMAAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 00:40:29
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.95.4.198 (198.4.95.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.95.4.198 (198.4.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 20:40:24.947534 2026] [security2:error] [pid 12388:tid 12388] [client 34.95.4.198:50618] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||northernlightsbev.printorganic.com|F|2"] [data ".printorganic.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "northernlightsbev.printorganic.com"] [uri "/z9x8c7v6b5-debug-trigger-northernlightsbev.printorganic.com"] [unique_id "arxaeD8KW1v2qRgRvC7GrgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
rellik
2026-09-29 21:46:00
(2 days ago)
Brute Force Scanning Critical Files & Directories
Hacking
Brute-Force
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-29 21:43:43
(2 days ago)
[ti-04al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-04al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.95.4.198 - - [29/Sep/2026:23:43:34 +0200] "GET /phpinfo.php HTTP/2.0" 301 303 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 21:37:04
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.95.4.198 (198.4.95.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.95.4.198 (198.4.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 17:36:56.924011 2026] [security2:error] [pid 24297:tid 24297] [client 34.95.4.198:33970] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||norkyn.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "norkyn.com"] [uri "/z9x8c7v6b5-debug-trigger-norkyn.com"] [unique_id "arwveJ55umCU6VIuKkWTMgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 20:54:48
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.95.4.198 (198.4.95.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.95.4.198 (198.4.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 16:54:45.173927 2026] [security2:error] [pid 26501:tid 26521] [client 34.95.4.198:35470] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nordicatrio.com"] [uri "/@fs/app/.env"] [unique_id "arwlldVQDzWogfB9Dy8CKwAAAEs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 20:36:22
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.95.4.198 (198.4.95.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.95.4.198 (198.4.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 16:36:14.147596 2026] [security2:error] [pid 31191:tid 31191] [client 34.95.4.198:47280] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||normajeanebook.banis-associates.com|F|2"] [data ".banis-associates.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "normajeanebook.banis-associates.com"] [uri "/z9x8c7v6b5-debug-trigger-normajeanebook.banis-associates.com"] [unique_id "arwhPqlv1l1ZXuWFXn9sbQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
sefinek.net
2026-09-29 20:15:07
(2 days ago)
Triggered Cloudflare WAF (firewallCustom) from CA.
Action: BLOCK | Protocol: HTTP/2 (POST) | Endpoin ...
show more
Triggered Cloudflare WAF (firewallCustom) from CA.
Action: BLOCK | Protocol: HTTP/2 (POST) | Endpoint: /cgi-bin/php | UA: DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot) โข Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฉ๐ช
konseptit
2026-09-29 20:09:39
(2 days ago)
(mod_security) mod_security triggered on hostname [redacted] 34.95.4.198 (CA/Canada/198.4.95.34.bc.g ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.95.4.198 (CA/Canada/198.4.95.34.bc.googleusercontent.com)
show less
SQL Injection
Anonymous
2026-09-29 19:50:06
(2 days ago)
| [Normal/Canada] Aggressive IP 34.95.4.198 (~350 hits). Type: DoS Defender- Web server 400 error co ...
show more
| [Normal/Canada] Aggressive IP 34.95.4.198 (~350 hits). Type: DoS Defender- Web server 400 error code
show less
Web App Attack
Hacking
SQL Injection
๐บ๐ธ
SLSLLC
2026-09-29 18:43:21
(2 days ago)
34.95.4.198 - - [29/Sep/2026:18:43:20 +0000] "GET /.env.example HTTP/2.0" 403 1858 "-" "Mozilla/5.0 ...
show more
34.95.4.198 - - [29/Sep/2026:18:43:20 +0000] "GET /.env.example HTTP/2.0" 403 1858 "-" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)"
...
show less
Brute-Force
Web App Attack