π©πͺ
klaus_ph
2026-09-27 14:18:55
(1 week ago)
2026-09-26 07:05:10,608 fail2ban.actions [594716]: NOTICE [ipblocklist] Ban 35.234.18.34
...
Bad Web Bot
πΏπ¦
conure.sh
2026-09-23 12:13:47
(2 weeks ago)
csagent: score 17.2: 404 noise floor x29, secrets grab x1; 1 domain(s) in 1s
Web App Attack
π³π±
Savvii
2026-09-23 02:12:55
(2 weeks ago)
22 attempts against mh-misbehave-ban on twig
Brute-Force
Bad Web Bot
Web App Attack
π«π·
β¨
2026-09-23 01:57:08
(2 weeks ago)
Domain : fiveseasonspress.com
Rule : hack
2026-09-23 01:55:17 ***hidden-privacy*** GET /z9x8c7v6b5-d ...
show more
Domain : fiveseasonspress.com
Rule : hack
2026-09-23 01:55:17 ***hidden-privacy*** GET /z9x8c7v6b5-debug-trigger-www.fiveseasonspress.com - 443 - 35.234.18.34 HTTP/2 Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; https://developers.facebook.com/docs/sharing/webmasters/crawler) - www.fiveseasonspress.com 301 0 0 201 502 235 - -
show less
Hacking
SQL Injection
Brute-Force
π©πͺ
TheDjRider
2026-09-22 23:38:34
(2 weeks ago)
CrowdSec detected Sensitive file or backup discovery attempt. Scenario: local/apache-sensitive-paths ...
show more
CrowdSec detected Sensitive file or backup discovery attempt. Scenario: local/apache-sensitive-paths. Automatic ban triggered. Detection time (UTC): 2026-09-22T23:38:30.291148524Z. Context: http_status=301
show less
Hacking
Web App Attack
πΊπΈ
dot.mg
2026-09-22 20:33:50
(2 weeks ago)
Scan of vulnerable files
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-22 18:57:56
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 35.234.18.34 (34.18.234.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.234.18.34 (34.18.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 14:57:51.959598 2026] [security2:error] [pid 30934:tid 30934] [client 35.234.18.34:50630] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||five21.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "five21.com"] [uri "/z9x8c7v6b5-debug-trigger-five21.com"] [unique_id "arLPr2xl4SJC6MHXe9wLtQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-22 18:41:05
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 35.234.18.34 (34.18.234.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.234.18.34 (34.18.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 14:41:01.391058 2026] [security2:error] [pid 31523:tid 31523] [client 35.234.18.34:50346] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||fixmyland.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "fixmyland.com"] [uri "/z9x8c7v6b5-debug-trigger-fixmyland.com"] [unique_id "arLLvWFGN5dRvFLN6gs_cgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Site.eu
2026-09-22 18:13:40
(2 weeks ago)
Excessive 404/403 errors
Brute-Force
πΊπΈ
interbiznw.com
2026-09-22 17:49:24
(2 weeks ago)
fail2ban-ban
Hacking
Brute-Force
Exploited Host
Web App Attack
πΉπ
thaizone.com
2026-09-22 17:08:53
(2 weeks ago)
Hacking attempts against websites (D1) #1
Web App Attack
Hacking
π©πͺ
konseptit
2026-09-22 16:32:39
(2 weeks ago)
(mod_security) mod_security triggered on hostname [redacted] 35.234.18.34 (TW/Taiwan/34.18.234.35.bc ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.234.18.34 (TW/Taiwan/34.18.234.35.bc.googleusercontent.com)
show less
SQL Injection
πΊπΈ
TPI-Abuse
2026-09-22 14:54:50
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 35.234.18.34 (34.18.234.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.234.18.34 (34.18.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 10:54:43.943710 2026] [security2:error] [pid 31265:tid 31265] [client 35.234.18.34:37148] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||footshufflerz.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "footshufflerz.com"] [uri "/z9x8c7v6b5-debug-trigger-footshufflerz.com"] [unique_id "arKWszPcOVY2Y4hrQ8hGIAAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
netclix.gr
2026-09-22 14:35:12
(2 weeks ago)
(mod_security) mod_security triggered on hostname [redacted] 35.234.18.34 (TW/Taiwan/34.18.234.35.bc ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.234.18.34 (TW/Taiwan/34.18.234.35.bc.googleusercontent.com): (CF_ENABLE)
show less
SQL Injection
πΊπΈ
TPI-Abuse
2026-09-22 14:28:45
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 35.234.18.34 (34.18.234.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.234.18.34 (34.18.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 10:28:39.316355 2026] [security2:error] [pid 7933:tid 7975] [client 35.234.18.34:57340] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||forestvalleyranch.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "forestvalleyranch.com"] [uri "/z9x8c7v6b5-debug-trigger-forestvalleyranch.com"] [unique_id "arKQl6YtTkFWwP-GXBfOVwAAAQs"]
show less
Brute-Force
Bad Web Bot
Web App Attack