๐บ๐ธ
TPI-Abuse
2026-06-15 17:32:32
(10 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.101.43.240 (240.43.101.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.101.43.240 (240.43.101.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 13:32:27.645085 2026] [security2:error] [pid 2180:tid 2180] [client 34.101.43.240:59734] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||russellforcongress.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "russellforcongress.com"] [uri "/.config/gcloud/credentials.db"] [unique_id "ajA3KxO8IDgnU2Ho_QsfxgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
pixiekat
2026-06-15 15:10:20
(12 hours ago)
[Mon Jun 15 16:10:19.858438 2026] [authz_core:error] [pid 2357191:tid 2357225] [client 34.101.43.240 ...
show more
[Mon Jun 15 16:10:19.858438 2026] [authz_core:error] [pid 2357191:tid 2357225] [client 34.101.43.240:46296] AH01630: client denied by server configuration: /var/www/html/heapdump
[Mon Jun 15 16:10:19.858438 2026] [authz_core:error] [pid 2357191:tid 2357227] [client 34.101.43.240:46284] AH01630: client denied by server configuration: /var/www/html/actuator
[Mon Jun 15 16:10:19.861771 2026] [authz_core:error] [pid 2357286:tid 2357327] [client 34.101.43.240:46272] AH01630: client denied by server configuration: /var/www/html/actuator
[Mon Jun 15 16:10:19.874877 2026] [authz_core:error] [pid 2357286:tid 2357328] [client 34.101.43.240:46310] AH01630: client denied by server configuration: /var/www/html/app
[Mon Jun 15 16:10:19.910708 2026] [authz_core:error] [pid 2357286:tid 2357323] [client 34.101.43.240:46320] AH01630: client denied by server configuration: /var/www/html/app
...
show less
Brute-Force
๐ฉ๐ช
Nightreaver
2026-06-15 14:06:36
(13 hours ago)
34.101.43.240 - - [15/Jun/2026:16:06:35 0200] "GET /actuator/env HTTP/1.1" 404 456 "-" "Mozilla/5.0 ...
show more
34.101.43.240 - - [15/Jun/2026:16:06:35 0200] "GET /actuator/env HTTP/1.1" 404 456 "-" "Mozilla/5.0 (Linux; Android 4.4.2; SM-T230NU Build/KOT49H) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.81 Safari/537.36"
34.101.43.240 - - [15/Jun/2026:16:06:35 0200] "GET /trace HTTP/1.1" 404 456 "-" "Mozilla/5.0 (OS/2; Warp 4.5; rv:24.0) Gecko/20100101 Firefox/24.0 SeaMonkey/2.21"
34.101.43.240 - - [15/Jun/2026:16:06:35 0200] "GET /api/actuator/env HTTP/1.1" 404 456 "-" "SonyEricssonK610i/R1CB Browser/NetFront/3.3 Profile/MIDP-2.0 Configuration/CLDC-1.1"
34.101.43.240 - - [15/Jun/2026:16:06:35 0200] "GET /dump HTTP/1.1" 404 456 "-" "Mozilla/5.0 (Linux; Android 9; Pixel XL) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.111 Mobile Safari/537.36"
34.101.43.240 - - [15/Jun/2026:16:06:35 0200] "GET /threaddump HTTP/1.1" 404 456 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3835.0 Safari/537.36"[...]
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
febrian.de
2026-06-15 08:12:08
(19 hours ago)
HTTP(S) probing or brute-force attack detected by Fail2Ban
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 07:17:26
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.101.43.240 (240.43.101.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.101.43.240 (240.43.101.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 03:17:20.204729 2026] [security2:error] [pid 1865:tid 1865] [client 34.101.43.240:37224] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "haroparquet.com"] [uri "/api/v2/.env"] [unique_id "ai-nAHHBsivYmHWVJuw91QAAAEE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
WebNiraj
2026-06-15 07:05:59
(20 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.101.43.240 (ID/Indonesia/240.43.101.34.bc.go ...
show more
(mod_security) mod_security (id:949110) triggered by 34.101.43.240 (ID/Indonesia/240.43.101.34.bc.googleusercontent.com): 5 in the last 3600 secs [SIGMA]
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-15 03:49:24
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.101.43.240 (240.43.101.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.101.43.240 (240.43.101.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 23:49:17.114900 2026] [security2:error] [pid 29623:tid 29623] [client 34.101.43.240:58412] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "alexlacruz.com"] [uri "/.env.production.bak"] [unique_id "ai92PYEnSelbG3NVWZlIpgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-06-15 02:48:54
(1 day ago)
Blocked by CSF 13 firewall - Rule: SG/Singapore/240.43.101.34.bc.googleusercontent.com
Web App Attack
Anonymous
2026-06-14 22:55:04
(1 day ago)
Bot / scanning and/or hacking attempts: GET /services/.env.local HTTP/1.1, GET /src/.env HTTP/1.1, G ...
show more
Bot / scanning and/or hacking attempts: GET /services/.env.local HTTP/1.1, GET /src/.env HTTP/1.1, GET /.env.backup HTTP/1.1, GET /frontend/.env.staging HTTP/1.1, GET /service/.env HTTP/1.1, GET /frontend/.env.prod HTTP/1.1, GET /src/.env.local HTTP/1.1, GET /frontend/.env HTTP/1.1, GET /backend/.env.dev HTTP/1.1, GET /.env.sample HTTP/1.1, GET /v2/.env HTTP/1.1, GET /.env.testing HTTP/1.1, GET /services/.env HTTP/1.1, GET /test/.env HTTP/1.1, GET /.env.prod HTTP/1.1
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 22:54:12
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.101.43.240 (240.43.101.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.101.43.240 (240.43.101.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 18:54:04.472932 2026] [security2:error] [pid 25927:tid 26012] [client 34.101.43.240:43964] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tnccivic.org"] [uri "/.env.backup"] [unique_id "ai8xDBwAJM5trOnT7S38sQAAAdI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-06-14 21:25:42
(1 day ago)
[SunJun1423:25:37.1377712026][security2:error][pid2397640:tid2397712][client34.101.43.240:0]ModSecur ...
show more
[SunJun1423:25:37.1377712026][security2:error][pid2397640:tid2397712][client34.101.43.240:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:10\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.9\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"www.casacarmen.ch.136-243-54-122.cpanel.site\"][uri\"/.env.uat\"][unique_id\"ai8cURdi3Jy3jZW4V59J-gAAAIs\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-06-14 11:20:09
(1 day ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2026-06-14 05:06:04
(1 day ago)
Scanning/Probing (44)
Brute-Force
Web App Attack
๐ซ๐ท
dynamix
2026-06-14 04:49:24
(1 day ago)
Multiple WAF Violations
Web App Attack
๐ฎ๐น
VHosting
2026-06-14 02:45:03
(2 days ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack