🇳🇱
MM-bot
2026-09-07 01:26:47
(8 hours ago)
URL-probe: HTTP/2 GET request on /wp-json (2026-09-07 03:26:47 UTC+2)
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-07 00:52:05
(9 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.10.125.218 (218.125.10.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.10.125.218 (218.125.10.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 20:51:57.016542 2026] [security2:error] [pid 32319:tid 32388] [client 34.10.125.218:52214] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.financialcertified.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.financialcertified.com"] [uri "/rclone.conf"] [unique_id "ap4KrYPWi7cZU5t_6uMs6QAAARM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇭🇺
whitehoodie
2026-09-07 00:43:10
(9 hours ago)
AUTOMATED REPORT: Attempting to access .env file
Hacking
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 22:39:50
(11 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.10.125.218 (218.125.10.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.10.125.218 (218.125.10.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 18:39:44.952556 2026] [security2:error] [pid 26137:tid 26137] [client 34.10.125.218:39344] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.hawkeyeibp.com|F|2"] [data ".hawkeyeibp.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.hawkeyeibp.com"] [uri "/z9x8c7v6b5-debug-trigger-www.hawkeyeibp.com"] [unique_id "ap3rsCHDN_wuw6L5lBGs3QAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
cmbplf
2026-09-06 20:35:10
(13 hours ago)
533 requests with url.path */@fs/*
197 requests with url.path */proc/*
195 requests with url.path ...
show more
533 requests with url.path */@fs/*
197 requests with url.path */proc/*
195 requests with url.path *.oci/*
show less
Brute-Force
Bad Web Bot
🇳🇱
Site.eu
2026-09-06 20:10:31
(13 hours ago)
Excessive multi-domain requests
Brute-Force
🇬🇧
consul.to
2026-09-06 19:05:43
(14 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
mnsf
2026-09-06 19:05:27
(14 hours ago)
Too many Status 40X (13)
Too many Status 50X (259)
Scanning/Probing (114)
Request Overload (272)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 18:59:15
(14 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.10.125.218 (218.125.10.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.10.125.218 (218.125.10.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 14:59:09.657733 2026] [security2:error] [pid 29923:tid 29923] [client 34.10.125.218:40894] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||scraggw.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "scraggw.com"] [uri "/z9x8c7v6b5-debug-trigger-scraggw.com"] [unique_id "ap23_YdA98ywqF-M2osusAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
big-cloud.nl
2026-09-06 17:44:50
(16 hours ago)
Try to access /@fs/.env?import&?raw??
Web App Attack
🇧🇪
madeit
2026-09-06 17:14:19
(16 hours ago)
Web App Attack
Anonymous
2026-09-06 16:56:25
(17 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
Anonymous
2026-09-06 15:40:06
(18 hours ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection
Anonymous
2026-09-06 15:34:48
(18 hours ago)
34.10.125.218 - - [06/Sep/2026:17:34:36 +0200] "GET /__vite_rsc_findSourceMapURL?filename=file:///ap ...
show more
34.10.125.218 - - [06/Sep/2026:17:34:36 +0200] "GET /__vite_rsc_findSourceMapURL?filename=file:///app/.env&environmentName=rsc HTTP/2.0" 403 272 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)"
show less
Web Spam
Blog Spam
Brute-Force
Web App Attack
🇩🇪
iNetWorker
2026-09-06 13:41:49
(20 hours ago)
trying to access non-authorized port
Port Scan