Anonymous
2026-10-09 05:30:04
(9 minutes ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection
๐บ๐ธ
jormaster3k
2026-10-09 05:23:27
(16 minutes ago)
Attack against Apache (too many 404s)
Web App Attack
๐จ๐ฆ
Mediashaker
2026-10-09 04:53:00
(46 minutes ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 34.140.42.145 (BE/Be ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 34.140.42.145 (BE/Belgium/145.42.140.34.bc.googleusercontent.com)
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-09 04:49:36
(50 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.140.42.145 (145.42.140.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.140.42.145 (145.42.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 00:49:33.027506 2026] [security2:error] [pid 16769:tid 16769] [client 34.140.42.145:40206] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "modelengines.info"] [uri "/%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env"] [unique_id "ashyXQ_estTS5_K4s7xJTAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 04:12:00
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.140.42.145 (145.42.140.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.140.42.145 (145.42.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 00:11:56.588101 2026] [security2:error] [pid 18755:tid 18755] [client 34.140.42.145:49790] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hisfavorite.net"] [uri "/userfiles"] [unique_id "ashpjEIGIdh5VegvlzLxngAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-09 04:04:31
(1 hour ago)
Aggressive web scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 03:54:46
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.140.42.145 (145.42.140.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.140.42.145 (145.42.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 23:54:39.454930 2026] [security2:error] [pid 20312:tid 20312] [client 34.140.42.145:51856] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ficklepassionproductions.com"] [uri "/static/../../../a/../../../../.env"] [unique_id "ashlfzn-qQA1INsTsrRCBQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
demomodule
2026-10-09 03:36:23
(2 hours ago)
PrestaShop Security Module: suspicious probe path detected (/.env)
Web App Attack
Anonymous
2026-10-09 03:20:11
(2 hours ago)
34.140.42.145 - - [09/Oct/2026:05:20:03 +0200] "GET /z9x8c7v6b5-debug-trigger-crypcool.com HTTP/1.1" ...
show more
34.140.42.145 - - [09/Oct/2026:05:20:03 +0200] "GET /z9x8c7v6b5-debug-trigger-crypcool.com HTTP/1.1" 404 30151
34.140.42.145 - - [09/Oct/2026:05:20:03 +0200] "GET /srv8g957a447247ep8q5 HTTP/1.1" 404 30151
34.140.42.145 - - [09/Oct/2026:05:20:03 +0200] "GET /dist/.vite/manifest.json HTTP/1.1" 404 30151
34.140.42.145 - - [09/Oct/2026:05:20:03 +0200] "GET /build/manifest.json HTTP/1.1" 404 30151
34.140.42.145 - - [09/Oct/2026:05:20:03 +0200] "POST /lib/terminal-xhr.php HTTP/1.1" 404 29513
34.140.42.145 - - [09/Oct/2026:05:20:03 +0200] "GET /dist/manifest.json HTTP/1.1" 404 30151
34.140.42.145 - - [09/Oct/2026:05:20:03 +0200] "GET /1mwkeil5ffyl2j0udhhj HTTP/1.1" 404 30151
34.140.42.145 - - [09/Oct/2026:05:20:06 +0200] "POST /graphql HTTP/1.1" 404 29513
34.140.42.145 - - [09/Oct/2026:05:20:09 +0200] "GET /%2Fdashboard HTTP/1.1" 404 2103
34.140.42.145 - - [09/Oct/2026:05:20:07 +0200] "POST /icecoder/lib/terminal-xhr.php HTTP/1.1" 404 27973
...
show less
Web Spam
Web App Attack
๐ฉ๐ช
rzk
2026-10-09 02:37:02
(3 hours ago)
CrowdSec scenario: crowdsecurity/http-sensitive-files. Banned by Koru Cloud platform after multi-eve ...
show more
CrowdSec scenario: crowdsecurity/http-sensitive-files. Banned by Koru Cloud platform after multi-event detection. ASN: GOOGLE-CLOUD-PLATFORM. Country: BE. Timestamp: 2026-10-09T02:37:02+00:00.
show less
Bad Web Bot
Web App Attack
๐ซ๐ฎ
Christopher Hughes
2026-10-09 02:23:08
(3 hours ago)
34.140.42.145 - - [09/Oct/2026:03:23:07 +0100] "GET /wp-json HTTP/2.0" 200 6011 "-" "Mozilla/5.0 (co ...
show more
34.140.42.145 - - [09/Oct/2026:03:23:07 +0100] "GET /wp-json HTTP/2.0" 200 6011 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
...
show less
Web App Attack
Anonymous
2026-10-09 02:15:37
(3 hours ago)
34.140.42.145 - - [09/Oct/2026:04:15:35 +0200] "GET / HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Macintosh; ...
show more
34.140.42.145 - - [09/Oct/2026:04:15:35 +0200] "GET / HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
34.140.42.145 - - [09/Oct/2026:04:15:35 +0200] "GET /signin HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
34.140.42.145 - - [09/Oct/2026:04:15:36 +0200] "GET /users/login HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
34.140.42.145 - - [09/Oct/2026:04:15:36 +0200] "GET /user/login HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
34.140.42.145 - - [09/Oct/2026:04:15:36 +0200] "GET /secure HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Sa
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
creoline GmbH
2026-10-09 02:11:46
(3 hours ago)
[WAF] Multiple suspicious HTTP requests has been blocked
Bad Web Bot
Web App Attack
Anonymous
2026-10-09 02:02:32
(3 hours ago)
Fail2Ban apache-noscript
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-09 02:00:57
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.140.42.145 (145.42.140.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.140.42.145 (145.42.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 22:00:51.863442 2026] [security2:error] [pid 29918:tid 29923] [client 34.140.42.145:53616] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||credit-card-cap.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "credit-card-cap.com"] [uri "/z9x8c7v6b5-debug-trigger-credit-card-cap.com"] [unique_id "ashK0y3UCAqnXBrG73Bc6wAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack