๐บ๐ธ
TPI-Abuse
2026-09-22 02:03:05
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.140.13.139 (139.13.140.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.140.13.139 (139.13.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 22:02:56.856166 2026] [security2:error] [pid 18870:tid 18870] [client 34.140.13.139:57482] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.ecodesarrollourbano.com"] [uri "/wp-config.php.swp"] [unique_id "arHh0LyZY9V3gbdyNUCaHAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-09-22 01:51:06
(4 days ago)
183 requests with url.path */@fs/*
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-22 01:30:46
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.140.13.139 (139.13.140.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.140.13.139 (139.13.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 21:30:41.488990 2026] [security2:error] [pid 14013:tid 14013] [client 34.140.13.139:48102] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "drlaurengardner.com"] [uri "/@fs/src/.env"] [unique_id "arHaQVHfdmTpE6tO7dUVgQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 01:08:42
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.140.13.139 (139.13.140.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.140.13.139 (139.13.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 21:08:39.093320 2026] [security2:error] [pid 13447:tid 13447] [client 34.140.13.139:38058] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.drumez.com"] [uri "/model/.env"] [unique_id "arHVF6zCw1SpXD2npQ_xswAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
regishoussin
2026-09-22 01:05:26
(4 days ago)
Automated web scanning detected by Wazuh (rule 100241): repeated 400/404 errors from mass probing of ...
show more
Automated web scanning detected by Wazuh (rule 100241): repeated 400/404 errors from mass probing of admin/backdoor paths (e.g. wp-login.php, known CMS shell filenames) on an Apache web server, on 2026-09-22 01:05 UTC.
show less
Bad Web Bot
Web App Attack
๐ฎ๐ช
tarlabs
2026-09-22 00:59:19
(4 days ago)
IP banned by Fail2Ban (traefik-404 jail)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 00:40:09
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.140.13.139 (139.13.140.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.140.13.139 (139.13.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 20:40:04.550083 2026] [security2:error] [pid 15034:tid 15034] [client 34.140.13.139:45510] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.ecrecorp.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "arHOZECaa_UiYpvpLPYvzAAAAEQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-22 00:31:45
(4 days ago)
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encod ...
show more
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encoding/ /proxy/ /lock-token/ /content-range/ /if/ /x-http-method-override/ /x-http-method/ /x-method-override/ /x-middleware-subrequest/ /expect/" at TX:header_name_920450_x-middleware-subrequest. (920450-197)
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-22 00:23:47
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 34.140.13.139 (139.13.140.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.140.13.139 (139.13.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 20:23:39.671592 2026] [security2:error] [pid 15920:tid 15920] [client 34.140.13.139:37588] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||drendels.com|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "drendels.com"] [uri "/localhost.key"] [unique_id "arHKi6ykNuLQjgEJiVd_-wAAAD0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
โจ
2026-09-22 00:17:06
(4 days ago)
Domain : douglasbarry.com
Rule : config
2026-09-22 00:14:52 ***hidden-privacy*** GET /.bash_profile ...
show more
Domain : douglasbarry.com
Rule : config
2026-09-22 00:14:52 ***hidden-privacy*** GET /.bash_profile - 80 - 34.140.13.139 HTTP/1.1 Mozilla/5.0 (compatible; xAI-Grok/1.0; https://x.ai/) - www.douglasbarry.com 404 0 2 1509 426 10 - -
show less
Hacking
SQL Injection
๐ช๐ธ
scaballe
2026-09-21 23:26:47
(4 days ago)
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-21 22:52:12
(4 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-21 22:11:59
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.140.13.139 (139.13.140.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.140.13.139 (139.13.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 18:11:52.639635 2026] [security2:error] [pid 19488:tid 19488] [client 34.140.13.139:40186] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.ed-co-corp.com"] [uri "/.git/config"] [unique_id "arGrqFVLe3O1KxYYyNs8MgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 21:34:39
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.140.13.139 (139.13.140.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.140.13.139 (139.13.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 17:34:32.081997 2026] [security2:error] [pid 27697:tid 27697] [client 34.140.13.139:55268] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.dougscomputers.com"] [uri "/.env.old"] [unique_id "arGi6HOtVjaSjKweckDtJQAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 20:24:21
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.140.13.139 (139.13.140.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.140.13.139 (139.13.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 16:24:15.361076 2026] [security2:error] [pid 28864:tid 28864] [client 34.140.13.139:33394] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dscampbell.com"] [uri "/.env.old"] [unique_id "arGSbz2YjPgIbcVyA9Z6ZQAAADI"]
show less
Brute-Force
Bad Web Bot
Web App Attack