🇺🇸
IndigoRidge
2026-09-11 18:51:56
(17 hours ago)
34.122.124.104 - - [11/Sep/2026:14:51:55 -0400] "GET /phpinfo.php HTTP/1.1" 404 73727 "https://carol ...
show more
34.122.124.104 - - [11/Sep/2026:14:51:55 -0400] "GET /phpinfo.php HTTP/1.1" 404 73727 "https://carolinacreativegroup.com/phpinfo.php" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)"
34.122.124.104 - - [11/Sep/2026:14:51:55 -0400] "GET /info.php HTTP/1.1" 404 73724 "https://carolinacreativegroup.com/info.php" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)"
34.122.124.104 - - [11/Sep/2026:14:51:55 -0400] "GET /test.php HTTP/1.1" 403 4870 "https://carolinacreativegroup.com/test.php" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)"
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 18:20:41
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.122.124.104 (104.124.122.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.122.124.104 (104.124.122.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 14:20:34.805506 2026] [security2:error] [pid 3806:tid 3806] [client 34.122.124.104:45030] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "carlsvoice.com"] [uri "/.env"] [unique_id "aqRGcrVIkxqCsUwNJXeGPQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇦
Sakusen
2026-09-11 17:42:05
(19 hours ago)
Automated web attack: 389 reqs, 277 paths probed, 336 returned 404; probed: 90 other, 58 .env, 45 .j ...
show more
Automated web attack: 389 reqs, 277 paths probed, 336 returned 404; probed: 90 other, 58 .env, 45 .json, 21 secret, 13 .php, 11 ssh-key, 10 .yml, 7 config, 6 .git, 6 cloud-cred, 4 script, 3 backup, 1 .jsp, 1 .xml, 1 log
show less
Hacking
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 17:35:20
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.122.124.104 (104.124.122.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.122.124.104 (104.124.122.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 13:35:12.245384 2026] [security2:error] [pid 6653:tid 6666] [client 34.122.124.104:45554] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cargosanibel.com"] [uri "/.env"] [unique_id "aqQ70JheESlYQguXcmSxlAAAAMs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 17:13:26
(19 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.122.124.104 (104.124.122.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.122.124.104 (104.124.122.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 13:13:22.075348 2026] [security2:error] [pid 14344:tid 14344] [client 34.122.124.104:54056] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||carefreesol.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "carefreesol.com"] [uri "/z9x8c7v6b5-debug-trigger-carefreesol.com"] [unique_id "aqQ2sh9-OSuFtflpybP03QAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
IndigoRidge
2026-09-11 17:02:05
(19 hours ago)
34.122.124.104 - - [11/Sep/2026:13:02:04 -0400] "GET /.aws/credentials HTTP/1.1" 404 5540 "-" "CCBot ...
show more
34.122.124.104 - - [11/Sep/2026:13:02:04 -0400] "GET /.aws/credentials HTTP/1.1" 404 5540 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)"
34.122.124.104 - - [11/Sep/2026:13:02:04 -0400] "GET /.git/config HTTP/1.1" 404 5540 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)"
34.122.124.104 - - [11/Sep/2026:13:02:04 -0400] "GET /.env HTTP/1.1" 404 5540 "-" "Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)"
...
show less
Web App Attack
🇸🇪
vaia.cloud
2026-09-11 16:25:01
(20 hours ago)
crowdsecurity/http-cve-2021-41773
Brute-Force
Web App Attack
🇦🇺
screwlooseit.com.au
2026-09-11 16:08:26
(20 hours ago)
Blocked by CSF 13 firewall - Rule: config-dotfile
US/United States/104.124.122.34.bc.googleuserconte ...
show more
Blocked by CSF 13 firewall - Rule: config-dotfile
US/United States/104.124.122.34.bc.googleusercontent.com
show less
Web App Attack
🇺🇸
mnsf
2026-09-11 16:06:16
(20 hours ago)
Abuse Detected (2)
Brute-Force
Web App Attack
🇮🇹
VHosting
2026-09-11 16:00:05
(20 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 15:59:14
(20 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.122.124.104 (104.124.122.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:949110) triggered by 34.122.124.104 (104.124.122.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 11:59:07.420657 2026] [security2:error] [pid 26819:tid 26819] [client 34.122.124.104:36690] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "captaincookfj.com"] [uri "/z9x8c7v6b5-debug-trigger-captaincookfj.com"] [unique_id "aqQlSy71ig4HbsATcKO40QAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-11 15:55:17
(20 hours ago)
Multiple WAF Violations
Web App Attack
🇬🇧
consul.to
2026-09-11 15:51:33
(20 hours ago)
Web attack/malicious scanning detected
Web App Attack