๐บ๐ธ
TPI-Abuse
2026-06-15 17:29:17
(17 hours ago)
(mod_security) mod_security (id:210831) triggered by 34.101.204.255 (255.204.101.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210831) triggered by 34.101.204.255 (255.204.101.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 13:29:13.828530 2026] [security2:error] [pid 7167:tid 7167] [client 34.101.204.255:41200] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||todddavis.net|F|4"] [data "EmailWolf"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "todddavis.net"] [uri "/v2/actuator/configprops"] [unique_id "ajA2afxhg5OAptgCcGN8OwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-06-15 16:32:09
(18 hours ago)
Multiple WAF Violations
Web App Attack
๐ณ๐ฑ
Savvii
2026-06-15 14:11:15
(20 hours ago)
15 attempts against mh-modsecurity-ban on pf221102
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 09:36:09
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.101.204.255 (255.204.101.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.101.204.255 (255.204.101.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 05:36:01.827349 2026] [security2:error] [pid 8188:tid 8211] [client 34.101.204.255:50342] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hoffmanandassoc.com"] [uri "/.env.default"] [unique_id "ai_HgffGW3CfDn7rb7CHGgAAANU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 09:19:59
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.101.204.255 (255.204.101.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.101.204.255 (255.204.101.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 05:19:50.173590 2026] [security2:error] [pid 18214:tid 18214] [client 34.101.204.255:40094] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bolivarbulletintimes.com"] [uri "/api/.env.prod"] [unique_id "ai_DtihLzzw_FWDJ536oFwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
updown.io
2026-06-15 09:13:42
(1 day ago)
{"level":"info","ts":1781514819.757052,"logger":"http.log.access.log1","msg":"handled request","requ ...
show more
{"level":"info","ts":1781514819.757052,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.101.204.255","remote_port":"32968","client_ip":"34.101.204.255","proto":"HTTP/1.1","method":"GET","host":"whm.whm.whm.mvd.4020vnqyx210en.status.quarks-erp.com","uri":"/backend/.env.dev","headers":{"User-Agent":["Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3792.0 Safari/537.36"],"Accept-Charset":["utf-8"],"Accept-Encoding":["gzip"],"Connection":["close"]}},"bytes_read":0,"user_id":"","duration":0.000084692,"size":0,"status":308,"resp_headers":{"Server":["Caddy"],"Connection":["close"],"Location":["https://whm.whm.whm.mvd.4020vnqyx210en.status.quarks-erp.com/backend/.env.dev"],"Content-Type":[]}}
{"level":"info","ts":1781514819.9610963,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.101.204.255","remote_port":"33032","client_ip":"34.101.204.255","proto":"HTTP/1.1","method":"GET",
...
show less
DDoS Attack
Web App Attack
๐ซ๐ท
โจ
2026-06-15 02:02:10
(1 day ago)
Domain : datarun.uk
Rule : hack
2026-06-15 02:00:29 ***hidden-privacy*** GET /.env.production.bak - ...
show more
Domain : datarun.uk
Rule : hack
2026-06-15 02:00:29 ***hidden-privacy*** GET /.env.production.bak - 443 - 34.101.204.255 HTTP/1.1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.142 Safari/537.36 - datarun.uk 404 0 2 12879 255 234 - -
show less
Hacking
SQL Injection
Brute-Force
๐จ๐ญ
zynex
2026-06-14 23:47:55
(1 day ago)
URL Probing: /uploads/.env
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 21:57:43
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.101.204.255 (255.204.101.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.101.204.255 (255.204.101.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 17:57:36.194458 2026] [security2:error] [pid 9936:tid 9936] [client 34.101.204.255:54052] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "flamberge.com"] [uri "/api/.env.local"] [unique_id "ai8j0FKoIohD3mYtAWBsEwAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-06-14 07:12:56
(2 days ago)
Excessive 404/403 errors
Brute-Force
๐บ๐ธ
mnsf
2026-06-14 07:06:53
(2 days ago)
Too many Status 40X (112)
Scanning/Probing (107)
Request Overload (112)
Brute-Force
Web App Attack
๐ซ๐ท
Octopuce
2026-06-14 05:24:22
(2 days ago)
Aggressive web search of vulnerable pages: /.env /api/v3/.env /api/.env /v1/.env /stage/.env ...
Web App Attack
Anonymous
2026-06-14 01:09:49
(2 days ago)
Aggressive web scan
Web App Attack