๐บ๐ธ
TPI-Abuse
2026-09-04 01:13:41
(38 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.125.0.55 (55.0.125.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.0.55 (55.0.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 21:13:35.175622 2026] [security2:error] [pid 5333:tid 5333] [client 34.125.0.55:21496] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.sekizinci.com"] [uri "/@fs/root/.env"] [unique_id "apobP66NuR0wDhPbhqU3kgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
andypiper
2026-09-04 01:00:18
(52 minutes ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
๐ซ๐ท
โจ
2026-09-04 00:55:09
(57 minutes ago)
Domain : newsite2020.ability6.com
Rule : hack
2026-09-04 00:54:05 ***hidden-privacy*** GET /@fs/proc ...
show more
Domain : newsite2020.ability6.com
Rule : hack
2026-09-04 00:54:05 ***hidden-privacy*** GET /@fs/proc/self/environ import
show less
Hacking
SQL Injection
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-04 00:16:45
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.125.0.55 (55.0.125.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.0.55 (55.0.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 20:16:39.688411 2026] [security2:error] [pid 26773:tid 26773] [client 34.125.0.55:52222] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.sharkfamily.com"] [uri "/@fs/root/.env"] [unique_id "apoN54TmDBi-0gx7l6pCBwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
todix
2026-09-03 23:54:19
(1 hour ago)
Web App Attack Exploid from 34.125.0.55
Web App Attack
๐ณ๐ฑ
debestelapp
2026-09-03 23:30:10
(2 hours ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-03 23:28:29
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.125.0.55 (55.0.125.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.0.55 (55.0.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 19:28:26.029608 2026] [security2:error] [pid 31919:tid 31919] [client 34.125.0.55:32550] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.portfolio-realestate.com"] [uri "/@fs/.env"] [unique_id "apoCmnkY7ysbcKt8U4DuiwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-09-03 23:25:23
(2 hours ago)
9.437 requests from abuseipdb.com blacklisted IP (1yr7mos3w)
Brute-Force
Bad Web Bot
๐ฉ๐ช
Tha_14
2026-09-03 23:25:06
(2 hours ago)
Multiple erroneous requests
Web App Attack
๐ช๐ธ
elcruzado.es
2026-09-03 23:20:48
(2 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.125.0.55 (US/United States/55.0.125. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.125.0.55 (US/United States/55.0.125.34.bc.googleusercontent.com)
show less
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-09-03 22:43:21
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.125.0.55 (55.0.125.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.0.55 (55.0.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 18:43:14.829582 2026] [security2:error] [pid 15628:tid 15628] [client 34.125.0.55:20140] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "riccardiagency.com"] [uri "/@fs/.env"] [unique_id "apn4AtHH21yNAffhHUNKGwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
maxpower
2026-09-03 22:06:49
(3 hours ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.125.0.55 (US/United States/55.0.125.3 ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.125.0.55 (US/United States/55.0.125.34.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.125.0.55 - - [04/Sep/2026:00:06:45 +0200] "GET /@fs/home/debian/.aws/credentials?raw?? HTTP/1.1" 200 12010 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; OAI-SearchBot/1.4; robots.txt; +https://openai.com/searchbot" "-" host=ip116.ip-51-77-95.eu
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-09-03 21:42:27
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.125.0.55 (55.0.125.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.0.55 (55.0.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 17:42:22.177206 2026] [security2:error] [pid 24530:tid 24530] [client 34.125.0.55:28630] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.cayman-islands-real-estate.com"] [uri "/@fs/.env"] [unique_id "apnpvkiEZOXJjWEIY-cJMgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
ConsulHosting
2026-09-03 21:29:55
(4 hours ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-03 21:00:17
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.125.0.55 (55.0.125.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.0.55 (55.0.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 17:00:13.568348 2026] [security2:error] [pid 27327:tid 27327] [client 34.125.0.55:33906] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.alianzallc.com"] [uri "/@fs/src/.env"] [unique_id "apnf3aF9N0HUNh3Im_6GTAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack