π¬π§
abivia
2026-10-01 17:58:11
(2 days ago)
Abivia WAF trigger: Rule scriptKiddies: Credential probing uri: /asset-manifest.json
Hacking
πΊπΈ
TPI-Abuse
2026-10-01 17:37:58
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.139.10.75 (75.10.139.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.139.10.75 (75.10.139.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 13:37:52.457633 2026] [security2:error] [pid 4550:tid 4550] [client 34.139.10.75:38368] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.discountphotogifts.com|F|2"] [data ".discountphotogifts.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.discountphotogifts.com"] [uri "/z9x8c7v6b5-debug-trigger-www.discountphotogifts.com"] [unique_id "ar6acJG05NGKpICmZ60nxgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-01 17:22:24
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.139.10.75 (75.10.139.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.139.10.75 (75.10.139.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 13:22:19.061753 2026] [security2:error] [pid 12966:tid 12966] [client 34.139.10.75:59036] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.camouflagebikinis.com"] [uri "/.htpasswd"] [unique_id "ar6Wy7_wxnFNyY9efPKkvAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-01 16:51:21
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.139.10.75 (75.10.139.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.139.10.75 (75.10.139.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 12:51:17.645158 2026] [security2:error] [pid 27804:tid 27804] [client 34.139.10.75:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.distro.media"] [uri "/.env.php.bak"] [unique_id "ar6PhfwyGHFvTX3G-zyyiAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-01 16:22:54
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.139.10.75 (75.10.139.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.139.10.75 (75.10.139.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 12:22:48.959743 2026] [security2:error] [pid 30811:tid 30811] [client 34.139.10.75:49816] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.armstrongpartnersllc.com"] [uri "/static//home/user/.env"] [unique_id "ar6I2MHPTulagpelsTGi8QAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΏπ¦
conure.sh
2026-10-01 16:17:58
(2 days ago)
csagent: score 21.4: 404 noise floor x6, secrets grab x2; 1 domain(s) in 2s
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-01 16:07:06
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.139.10.75 (75.10.139.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.139.10.75 (75.10.139.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 12:06:59.417914 2026] [security2:error] [pid 24700:tid 24700] [client 34.139.10.75:60990] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.cipcug.org"] [uri "/build../.env"] [unique_id "ar6FI0rSqydkXgenRu2YfwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-01 15:46:08
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.139.10.75 (75.10.139.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.139.10.75 (75.10.139.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 11:46:03.008271 2026] [security2:error] [pid 3781:tid 3781] [client 34.139.10.75:55206] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.bradjohnsonqh.com|F|2"] [data ".bradjohnsonqh.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.bradjohnsonqh.com"] [uri "/z9x8c7v6b5-debug-trigger-www.bradjohnsonqh.com"] [unique_id "ar6AO_zZxXcSrhdF1EYkTQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-01 15:35:01
(2 days ago)
suspicious request in access.log
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-01 15:30:15
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.139.10.75 (75.10.139.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.139.10.75 (75.10.139.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 11:30:07.512982 2026] [security2:error] [pid 18236:tid 18236] [client 34.139.10.75:34136] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.callahan-co.com"] [uri "/.env.js"] [unique_id "ar58f_jmYRO7lhGNB8bWYgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
Stara
2026-10-01 15:19:52
(2 days ago)
ModSecurity detected web attack - .env/config probing or SQLi/Code injection (Rule 949110)
Brute-Force
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-01 15:09:09
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.139.10.75 (75.10.139.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.139.10.75 (75.10.139.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 11:09:02.559730 2026] [security2:error] [pid 6507:tid 6507] [client 34.139.10.75:59286] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "civilwarzone.com"] [uri "/dist../.env"] [unique_id "ar53juQpyesC_vh-uVOO8wAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-01 14:43:38
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.139.10.75 (75.10.139.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.139.10.75 (75.10.139.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 10:43:32.374541 2026] [security2:error] [pid 20387:tid 20387] [client 34.139.10.75:51948] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.davefortier.com"] [uri "/.htpasswd"] [unique_id "ar5xlFAw90Nyu5Wk922KFgAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-01 14:07:42
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.139.10.75 (75.10.139.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.139.10.75 (75.10.139.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 10:07:38.654672 2026] [security2:error] [pid 26734:tid 26734] [client 34.139.10.75:44364] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.buccinet.com"] [uri "/.git/HEAD"] [unique_id "ar5pKmTCEk8bqGzUHOFcrwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-01 13:47:46
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.139.10.75 (75.10.139.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.139.10.75 (75.10.139.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 09:47:39.941734 2026] [security2:error] [pid 13299:tid 13299] [client 34.139.10.75:49238] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aticom.es"] [uri "/static../.env"] [unique_id "ar5kew_CEPsnBkrVOwTukQAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack