๐บ๐ธ
TPI-Abuse
2026-08-29 09:57:29
(15 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.140.210.140 (140.210.140.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.140.210.140 (140.210.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 05:57:25.889907 2026] [security2:error] [pid 19144:tid 19237] [client 34.140.210.140:36934] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.movetodc.com"] [uri "/@fs/app/.env"] [unique_id "apKtBfVYPZhOLi9qXiDp9gAAAVM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 09:21:19
(52 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.140.210.140 (140.210.140.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.140.210.140 (140.210.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 05:21:11.652628 2026] [security2:error] [pid 10863:tid 10863] [client 34.140.210.140:22454] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.scaleiq.group"] [uri "/@fs/app/.env"] [unique_id "apKkh5CblZmijIWp10VigQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Aetherweb Ark
2026-08-29 09:19:56
(53 minutes ago)
(mod_security) mod_security (id:949110) triggered by 34.140.210.140 (BE/Belgium/140.210.140.34.bc.go ...
show more
(mod_security) mod_security (id:949110) triggered by 34.140.210.140 (BE/Belgium/140.210.140.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 08:45:00
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.140.210.140 (140.210.140.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.140.210.140 (140.210.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 04:44:52.306202 2026] [security2:error] [pid 32335:tid 32335] [client 34.140.210.140:9742] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.miz-art.com"] [uri "/@fs/.env.staging"] [unique_id "apKcBC2h_AxS2pnI_HrxbwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-29 08:34:20
(1 hour ago)
XSS Attempt
Hacking
๐ฉ๐ช
creoline GmbH
2026-08-29 07:22:20
(2 hours ago)
[WAF] Multiple suspicious HTTP requests has been blocked
Bad Web Bot
Web App Attack
๐ฉ๐ช
Petros Stefanakis
2026-08-29 06:54:08
(3 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.140.210.140 (BE/Belgium/140.210.140. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.140.210.140 (BE/Belgium/140.210.140.34.bc.googleusercontent.com)
show less
SQL Injection
๐ฉ๐ช
FeG Deutschland
2026-08-29 06:25:30
(3 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 12
Exploited Host
Web App Attack
๐ฆ๐น
nomzamo
2026-08-29 05:54:12
(4 hours ago)
Fail2Ban reported: nginx-noscript
Brute-Force
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-08-29 05:46:01
(4 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-29 05:29:04
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.140.210.140 (140.210.140.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.140.210.140 (140.210.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 01:29:01.084436 2026] [security2:error] [pid 106473:tid 106479] [client 34.140.210.140:44816] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.travelusa.us"] [uri "/@fs/.env"] [unique_id "apJuHQT0nhezPdooEOnCiQAAAMI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
OptimusGO
2026-08-29 05:04:29
(5 hours ago)
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show more
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-08-29 06:04:29 UTC
Log evidence:
34.140.210.140 - - [29/Aug/2026:06:04:23 +0100] "GET / HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Safari/537.36"
08/29/2026-06:04:27.639093 [wDrop] [**] [1:7000500:1] FINSERV CRITICAL: Aggressive Port Scan [**] [Classification: Attempted Information Leak] [Priority: 2] {TCP} 34.140.210.140:35930 -> 185.127.18.66:443
08/29/2026-06:04:27.639093 [**] [1:9000060:2] AUTONOMOUS Long-term Reconnaissance [**] [Classification: (null)] [Priority: 2] {TCP} 34.140.210.140:35930 -> 185.127.18.66:443
show less
Port Scan
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-29 04:56:15
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.140.210.140 (140.210.140.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.140.210.140 (140.210.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 00:56:08.895860 2026] [security2:error] [pid 23259:tid 23259] [client 34.140.210.140:2102] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.realstorybooks.com"] [uri "/@fs/app/.env"] [unique_id "apJmaCrRFVRjmCAZlHqKlAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
zumbo.net
2026-08-29 04:47:47
(5 hours ago)
[Sat Aug 29 07:47:23.273007 2026] [proxy_fcgi:error] [pid 1758813:tid 1758841] [client 34.140.210.14 ...
show more
[Sat Aug 29 07:47:23.273007 2026] [proxy_fcgi:error] [pid 1758813:tid 1758841] [client 34.140.210.140:0] AH01071: Got error 'Primary script unknown'
[Sat Aug 29 07:47:23.275044 2026] [proxy_fcgi:error] [pid 1758813:tid 1758836] [client 34.140.210.140:0] AH01071: Got error 'Primary script unknown'
[Sat Aug 29 07:47:29.015267 2026] [proxy_fcgi:error] [pid 1758813:tid 1758836] [client 34.140.210.140:0] AH01071: Got error 'Primary script unknown'
[Sat Aug 29 07:47:29.015664 2026] [proxy_fcgi:error] [pid 1758813:tid 1758844] [client 34.140.210.140:0] AH01071: Got error 'Primary script unknown'
[Sat Aug 29 07:47:46.113786 2026] [proxy_fcgi:error] [pid 1758813:tid 1758834] [client 34.140.210.140:0] AH01071: Got error 'Primary script unknown'
...
show less
Brute-Force
Web App Attack
๐ฉ๐ช
mravb
2026-08-29 04:33:08
(5 hours ago)
34.140.210.140 - - [29/Aug/2026:07:33:07 +0300] "GET /api/.env HTTP/1.1" 404 28 "-" "Mozilla/5.0 (co ...
show more
34.140.210.140 - - [29/Aug/2026:07:33:07 +0300] "GET /api/.env HTTP/1.1" 404 28 "-" "Mozilla/5.0 (compatible; OAI-SearchBot/1.4; robots.txt; +https://openai.com/searchbot)"
...
show less
Web App Attack
Hacking