๐บ๐ธ
mnsf
2026-08-29 00:07:41
(4 days ago)
Scanning/Probing (26)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 14:39:18
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.125.10.254 (254.10.125.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.10.254 (254.10.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 10:39:10.967996 2026] [security2:error] [pid 9033:tid 9071] [client 34.125.10.254:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.humanet.io"] [uri "/@fs/usr/src/app/.env"] [unique_id "apGdjmYAD95Oz2JiGSEMxgAAAEU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 13:44:36
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.125.10.254 (254.10.125.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.10.254 (254.10.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 09:44:31.296959 2026] [security2:error] [pid 27211:tid 27211] [client 34.125.10.254:51806] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.title37.itaxcenter.com"] [uri "/@fs/.env"] [unique_id "apGQvy9jdFhQGglKR249XQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
ConsulHosting
2026-08-28 13:24:07
(5 days ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 11:56:13
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.125.10.254 (254.10.125.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.10.254 (254.10.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 07:56:05.934944 2026] [security2:error] [pid 28745:tid 28745] [client 34.125.10.254:59624] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.rohn.com"] [uri "/@fs/.env"] [unique_id "apF3VWcrwc0pEormOlWr2AAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
masterguru
2026-08-28 10:31:06
(5 days ago)
BAD BOT - Detected and Blocked.. Matched phrase "amazonbot" at REQUEST_HEADERS:User-Agent. (1100000- ...
show more
BAD BOT - Detected and Blocked.. Matched phrase "amazonbot" at REQUEST_HEADERS:User-Agent. (1100000-122)
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-28 09:55:26
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.125.10.254 (254.10.125.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.10.254 (254.10.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 05:55:18.228606 2026] [security2:error] [pid 921:tid 921] [client 34.125.10.254:37184] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rubypines.com"] [uri "/@fs/.env"] [unique_id "apFbBtYIH6SPVwr8Ym7hfAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Octopuce
2026-08-28 08:44:52
(5 days ago)
Aggressive web search of vulnerable pages: /.env /.env.local /api/.env /v2/.env /app/.env ...
Web App Attack
๐บ๐ธ
snappic
2026-08-28 06:57:54
(5 days ago)
Scanning for config [GET /config.json.js] [Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compa ...
show more
Scanning for config [GET /config.json.js] [Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexity-user]
show less
Bad Web Bot
Web App Attack
Anonymous
2026-08-28 06:46:52
(5 days ago)
Banned by Fail2Ban on server
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 06:20:10
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.125.10.254 (254.10.125.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.10.254 (254.10.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 02:20:05.406183 2026] [security2:error] [pid 14726:tid 14726] [client 34.125.10.254:55730] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.sicktrax.com"] [uri "/@fs/app/.env"] [unique_id "apEolRGqB8oSz_CiHuL5owAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-08-28 05:19:09
(5 days ago)
Restricted File Access Attempt. Matched phrase "/@fs/" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
๐ฉ๐ช
findlab
2026-08-28 05:15:01
(5 days ago)
Backdrop CMS module - malicious activity detected
Bad Web Bot
Web App Attack
Anonymous
2026-08-28 04:10:12
(5 days ago)
(mod_security) mod_security triggered on hostname [redacted] 34.125.10.254 (US/United States/254.10. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.125.10.254 (US/United States/254.10.125.34.bc.googleusercontent.com)
show less
SQL Injection
๐ช๐ธ
masterguru
2026-08-28 03:50:57
(5 days ago)
Inbound Anomaly Score Exceeded (Total Score: 5). Operator GE matched 5 at TX:anomaly_score. (949110- ...
show more
Inbound Anomaly Score Exceeded (Total Score: 5). Operator GE matched 5 at TX:anomaly_score. (949110-122)
show less
Hacking