Anonymous
2026-09-11 20:48:01
(6 minutes ago)
Bot / scanning and/or hacking attempts: GET /userfiles?path=../../../../proc/self/environ HTTP/2.0, ...
show more
Bot / scanning and/or hacking attempts: GET /userfiles?path=../../../../proc/self/environ HTTP/2.0, GET /_astro/pages/index.astro.mjs.map HTTP/2.0, GET /.env?.svg?.wasm?init HTTP/2.0, GET /userfiles?path=../../../../.env HTTP/2.0, GET /.env.local?.svg?.wasm?init HTTP/2.0, GET /core/.env HTTP/2.0, GET /wp-config.php.bak HTTP/2.0, GET /@fs/../.env?import&raw?? HTTP/2.0, GET /proc/self/cgroup HTTP/2.0, GET /@fs/app/.env.local?import&raw?? HTTP/2.0, GET /..%2f..%2f.env HTTP/2.0, GET /wp-config.php.old HTTP/2.0, GET /userfiles?path=../../.env HTTP/2.0, GET /config/.env.php HTTP/2.0
show less
Hacking
Web App Attack
Anonymous
2026-09-11 19:08:19
(1 hour ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-11 18:47:46
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.138.154.242 (242.154.138.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.138.154.242 (242.154.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 14:47:43.517248 2026] [security2:error] [pid 9534:tid 9534] [client 34.138.154.242:57604] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "circlethreefl.com"] [uri "/.git/HEAD"] [unique_id "aqRMz-uQJCvDJzjO_cmjdgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-11 18:31:49
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.138.154.242 (242.154.138.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.138.154.242 (242.154.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 14:31:44.660585 2026] [security2:error] [pid 14251:tid 14251] [client 34.138.154.242:34744] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||cinziallc.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "cinziallc.com"] [uri "/z9x8c7v6b5-debug-trigger-cinziallc.com"] [unique_id "aqRJEKe3Lwplmt_f_jI8oAAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-11 18:31:23
(2 hours ago)
Web attack/malicious scanning detected
Web App Attack
Anonymous
2026-09-11 18:24:54
(2 hours ago)
Banned by Fail2Ban on server
Web App Attack
๐ซ๐ท
dynamix
2026-09-11 17:41:11
(3 hours ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-11 17:21:16
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.138.154.242 (242.154.138.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.138.154.242 (242.154.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 13:21:10.048054 2026] [security2:error] [pid 28388:tid 28428] [client 34.138.154.242:33480] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cibernetic.com"] [uri "/img../.env"] [unique_id "aqQ4hqzhOc0z3Ld63n0igwAAAMk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-09-11 17:20:04
(3 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2026-09-11 17:05:39
(3 hours ago)
Scanning/Probing (11)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-11 17:04:03
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.138.154.242 (242.154.138.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.138.154.242 (242.154.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 13:03:58.385628 2026] [security2:error] [pid 27707:tid 27707] [client 34.138.154.242:38024] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "churchtop.com"] [uri "/.env"] [unique_id "aqQ0fkWc2OVnPO33dtQKJQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-11 16:32:17
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.138.154.242 (242.154.138.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.138.154.242 (242.154.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 12:32:12.787216 2026] [security2:error] [pid 31217:tid 31217] [client 34.138.154.242:47040] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||chronoton.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "chronoton.com"] [uri "/z9x8c7v6b5-debug-trigger-chronoton.com"] [unique_id "aqQtDJQlQsz6fRa_XUO3iQAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-11 16:29:59
(4 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-11 16:25:30
(4 hours ago)
20 attempts against mh-misbehave-ban on yuzu
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-11 16:09:44
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.138.154.242 (242.154.138.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.138.154.242 (242.154.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 12:09:38.599176 2026] [security2:error] [pid 13472:tid 13472] [client 34.138.154.242:59824] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "christmascardsprinted.com"] [uri "/.env"] [unique_id "aqQnwriIJJwTM6KSEXmp9wAAAC0"]
show less
Brute-Force
Bad Web Bot
Web App Attack