๐บ๐ธ
TPI-Abuse
2026-08-26 19:22:40
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.125.134.48 (48.134.125.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.134.48 (48.134.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 15:22:35.953932 2026] [security2:error] [pid 24357:tid 24357] [client 34.125.134.48:46670] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.jacksonpropertyrentals.com"] [uri "/static../.env"] [unique_id "ao88-wodMvwB3jwaW1AxHgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-26 19:19:00
(17 hours ago)
Excessive crawling/scraping. Vulnerable file probing.
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
COMAITE
2026-08-26 18:59:06
(17 hours ago)
Common web attack from 34.125.134.48.
Web App Attack
๐ธ๐ช
vaia.cloud
2026-08-26 18:50:02
(17 hours ago)
crowdsecurity/http-wordpress_wpconfig
Brute-Force
Web App Attack
๐ซ๐ท
Octopuce
2026-08-26 18:24:08
(18 hours ago)
Aggressive web search of vulnerable pages: /app/.env /.env /media../.env /.env.local /admin/.env .. ...
show more
Aggressive web search of vulnerable pages: /app/.env /.env /media../.env /.env.local /admin/.env ...
show less
Web App Attack
Anonymous
2026-08-26 17:50:26
(18 hours ago)
| Common web attack.
Web App Attack
Hacking
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-08-26 16:51:36
(19 hours ago)
(mod_security) mod_security (id:210580) triggered by 34.125.134.48 (48.134.125.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210580) triggered by 34.125.134.48 (48.134.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 12:51:30.975475 2026] [security2:error] [pid 24999:tid 24999] [client 34.125.134.48:34254] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at ARGS:url. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||www.voodooshop.com|F|2"] [data "Matched Data: proc/self/environ found within ARGS:url: file:/proc/self/environ"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "www.voodooshop.com"] [uri "/read"] [unique_id "ao8ZkklvpiKuxSnGVvFSrAAAAFU"], referer: http://mojo2go.com/read?url=file:///proc/self/environ
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
middelkoopcc
2026-08-26 16:32:01
(20 hours ago)
2026-08-26 18:29:59 GET /download?file=../../../../etc/passwd [301] && 2026-08-26 18:29:59 GET /@fs/ ...
show more
2026-08-26 18:29:59 GET /download?file=../../../../etc/passwd [301] && 2026-08-26 18:29:59 GET /@fs/home/ec2-user/.aws/credentials?raw?? [301] && 2026-08-26 18:29:59 GET /.git/HEAD [301] && 122 more within 20 minutes
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 15:44:49
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.125.134.48 (48.134.125.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.134.48 (48.134.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 11:44:41.810094 2026] [security2:error] [pid 16978:tid 16978] [client 34.125.134.48:38324] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "leirstein.com"] [uri "/.git/HEAD"] [unique_id "ao8J6Ug16rYWBE0Rx8xldQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 14:54:41
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.125.134.48 (48.134.125.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.134.48 (48.134.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 10:54:36.521938 2026] [security2:error] [pid 9383:tid 9383] [client 34.125.134.48:2322] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "heckenbach.org"] [uri "/static../.env"] [unique_id "ao7-LF8eqnS_95FLWmtd2QAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐พ
Rizzy
2026-08-26 13:36:54
(22 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ฉ๐ช
dbmwebdesign
2026-08-26 13:15:04
(23 hours ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
Anonymous
2026-08-26 12:56:26
(23 hours ago)
Web attack blocked by Wordfence on limburgsekunstkring.nl (1 hit). Reported by CRMON.
Web App Attack
๐ธ๐ช
vaia.cloud
2026-08-26 12:50:02
(23 hours ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2026-08-26 12:05:19
(1 day ago)
Scanning/Probing (12)
Brute-Force
Web App Attack