๐ฟ๐ฆ
conure.sh
2026-10-02 12:09:55
(3 hours ago)
csagent: score 24.0: secrets grab x2, botnet path probe x1; 1 domain(s) in 17s
Web App Attack
๐ซ๐ท
Octopuce
2026-10-01 15:28:31
(1 day ago)
Aggressive web search of vulnerable pages: /public../.env /media../.env /dist../.env /files../.env / ...
show more
Aggressive web search of vulnerable pages: /public../.env /media../.env /dist../.env /files../.env /static//home/user/.env ...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 15:19:39
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.12.243.11 (11.243.12.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.12.243.11 (11.243.12.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 11:19:32.589048 2026] [security2:error] [pid 8989:tid 8989] [client 34.12.243.11:55986] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.praedari.com"] [uri "/.env.js"] [unique_id "ar56BBoopVZEvUaZbF0Q4gAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
updown.io
2026-10-01 15:11:03
(1 day ago)
{"level":"info","ts":1790867461.974088,"logger":"http.log.access.log1","msg":"handled request","requ ...
show more
{"level":"info","ts":1790867461.974088,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.12.243.11","remote_port":"39002","client_ip":"34.12.243.11","proto":"HTTP/2.0","method":"GET","host":"status.questioncove.com","uri":"/webpack-stats.json","headers":{"Accept":["text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8"],"Upgrade-Insecure-Requests":["1"],"Sec-Ch-Ua-Mobile":["?0"],"Sec-Fetch-Site":["none"],"Sec-Ch-Ua-Platform":["\"Windows\""],"Sec-Fetch-User":["?1"],"User-Agent":["Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36"],"Sec-Fetch-Dest":["document"],"Sec-Ch-Ua":["\"Chromium\";v=\"152\", \"Not?A_Brand\";v=\"24\", \"Brave\";v=\"152\""],"Sec-Fetch-Mode":["navigate"],"Accept-Encoding":["gzip, deflate, br, zstd"],"Priority":["u=0, i"],"X-Nextjs-Data":["1"],"Accept-Language":["en-US,en;q=0.9"],"X-Middleware-Subrequest":["src/middleware:nowaf:src/middleware:
...
show less
DDoS Attack
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-10-01 15:10:37
(1 day ago)
csagent: score 22.7: spoofed crawler UA x1, botnet path probe x1, secrets grab x1; 2 domain(s) in 17 ...
show more
csagent: score 22.7: spoofed crawler UA x1, botnet path probe x1, secrets grab x1; 2 domain(s) in 17s
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 14:46:57
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.12.243.11 (11.243.12.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.12.243.11 (11.243.12.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 10:46:53.684505 2026] [security2:error] [pid 27391:tid 27391] [client 34.12.243.11:48978] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ramoundos-systems.com"] [uri "/css../.env"] [unique_id "ar5yXfzI_CthxgJM7q2spQAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 14:04:00
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.12.243.11 (11.243.12.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.12.243.11 (11.243.12.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 10:03:53.362016 2026] [security2:error] [pid 21382:tid 21382] [client 34.12.243.11:48376] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.oceansgift.com"] [uri "/.htpasswd"] [unique_id "ar5oSXt7R-3rEJTIL8e5QQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 13:44:58
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.12.243.11 (11.243.12.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.12.243.11 (11.243.12.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 09:44:54.288206 2026] [security2:error] [pid 30271:tid 30271] [client 34.12.243.11:58564] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.mprise.com|F|2"] [data ".mprise.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.mprise.com"] [uri "/z9x8c7v6b5-debug-trigger-autodiscover.mprise.com"] [unique_id "ar5j1hm-5vPAE0m9P2tVtwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 13:19:30
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.12.243.11 (11.243.12.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.12.243.11 (11.243.12.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 09:19:26.305041 2026] [security2:error] [pid 19212:tid 19212] [client 34.12.243.11:57126] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.paleopathologist.com|F|2"] [data ".paleopathologist.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.paleopathologist.com"] [uri "/z9x8c7v6b5-debug-trigger-autodiscover.paleopathologist.com"] [unique_id "ar5d3u3pIuxWlMbc1WQ1EQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 13:01:50
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.12.243.11 (11.243.12.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.12.243.11 (11.243.12.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 09:01:44.011612 2026] [security2:error] [pid 4492:tid 4492] [client 34.12.243.11:46888] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.openheartwellness.com"] [uri "/cache/original/%2e%2e/%2e%2e/.env"] [unique_id "ar5ZuMEjwVDhJBVGaSKrOAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-10-01 13:00:21
(1 day ago)
Multiple WAF Violations
Web App Attack
๐ฎ๐น
VHosting
2026-10-01 12:50:03
(1 day ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 12:42:30
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.12.243.11 (11.243.12.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.12.243.11 (11.243.12.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 08:42:21.548697 2026] [security2:error] [pid 26334:tid 26334] [client 34.12.243.11:56796] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.ontrek.com"] [uri "/.env.js"] [unique_id "ar5VLRdXIQDMWQ4dv1z62gAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
Mediashaker
2026-10-01 12:39:52
(1 day ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 34.12.243.11 (11.243 ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 34.12.243.11 (11.243.12.34.bc.googleusercontent.com)
show less
Bad Web Bot