๐บ๐ธ
TPI-Abuse
2026-10-05 11:08:36
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.141.136.132 (132.136.141.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.141.136.132 (132.136.141.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 07:08:28.269231 2026] [security2:error] [pid 7109:tid 7109] [client 34.141.136.132:40908] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.railsolutions.mx"] [uri "/uploads../.env"] [unique_id "asOFLHjayWD0XOtcrd-awwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 02:00:35
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.141.136.132 (132.136.141.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.141.136.132 (132.136.141.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 22:00:27.261968 2026] [security2:error] [pid 373:tid 373] [client 34.141.136.132:33282] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.sierrablue.farm"] [uri "/userfiles/x"] [unique_id "asMEuzXotdFiqe2GIHdDrwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-04 23:20:23
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.141.136.132 (132.136.141.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.141.136.132 (132.136.141.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 19:20:17.728386 2026] [security2:error] [pid 23643:tid 23643] [client 34.141.136.132:59754] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ultratecnologia.com.mx"] [uri "/.htpasswd"] [unique_id "asLfMQwd4smbZMxf3robSgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-04 22:53:49
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.141.136.132 (132.136.141.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.141.136.132 (132.136.141.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 18:53:42.971851 2026] [security2:error] [pid 5328:tid 5328] [client 34.141.136.132:48672] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "radiofamilia.com.mx"] [uri "/.env.development::$DATA"] [unique_id "asLY9kc4DCJyHxJFPtCvxQAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-04 22:19:43
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.141.136.132 (132.136.141.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.141.136.132 (132.136.141.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 18:19:36.268309 2026] [security2:error] [pid 16957:tid 16957] [client 34.141.136.132:41080] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lightningbug.farm"] [uri "/.htpasswd"] [unique_id "asLQ-AtRjpFp2Bwm1dnxQQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-10-04 22:17:44
(14 hours ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-04 21:52:53
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.141.136.132 (132.136.141.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.141.136.132 (132.136.141.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 17:52:48.360166 2026] [security2:error] [pid 13406:tid 13406] [client 34.141.136.132:50384] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "imerka.com.mx"] [uri "/.htpasswd"] [unique_id "asLKsI5JrQdCF4asKu5q_gAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
macrob
2026-10-04 21:18:00
(15 hours ago)
2026/10/04 21:17:59 [error] 3447622#3447622: *16560729 access forbidden by rule, client: 34.141.136. ...
show more
2026/10/04 21:17:59 [error] 3447622#3447622: *16560729 access forbidden by rule, client: 34.141.136.132, server: finami.mx, request: "GET /.ssh/id_ed25519 HTTP/2.0", host: "finami.mx"
2026/10/04 21:17:59 [error] 3447622#3447622: *16562951 access forbidden by rule, client: 34.141.136.132, server: finami.mx, request: "GET /.ssh/id_rsa HTTP/2.0", host: "finami.mx"
2026/10/04 21:17:59 [error] 3447621#3447621: *16566924 access forbidden by rule, client: 34.141.136.132, server: finami.mx, request: "GET /.npmrc HTTP/2.0", host: "finami.mx"
...
show less
Web App Attack
๐ซ๐ท
Omar Martรญnez
2026-10-04 21:00:33
(15 hours ago)
[Sun Oct 04 15:00:22.158770 2026] [core:error] [pid 2683961:tid 139864792475200] [remote 34.141.136. ...
show more
[Sun Oct 04 15:00:22.158770 2026] [core:error] [pid 2683961:tid 139864792475200] [remote 34.141.136.132:58466] AH10244: invalid URI path (/public/plugins/text/../../../../../../../../proc/self/environ)
[Sun Oct 04 15:00:31.113065 2026] [core:error] [pid 2683961:tid 139864750511680] [remote 34.141.136.132:58466] AH10244: invalid URI path (/%2e%2e/%2e%2e/%2e%2e/%2e%2e/.env)
...
show less
Phishing
Email Spam
Blog Spam
๐บ๐ธ
TPI-Abuse
2026-10-04 20:59:49
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.141.136.132 (132.136.141.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.141.136.132 (132.136.141.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 16:59:43.142988 2026] [security2:error] [pid 1685:tid 1685] [client 34.141.136.132:39762] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "elgarage.com.mx"] [uri "/.htpasswd"] [unique_id "asK-PzyPzfE7d-3ogRoMsQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
rzk
2026-10-04 20:39:03
(16 hours ago)
CrowdSec scenario: crowdsecurity/http-sensitive-files. Banned by Koru Cloud platform after multi-eve ...
show more
CrowdSec scenario: crowdsecurity/http-sensitive-files. Banned by Koru Cloud platform after multi-event detection. ASN: GOOGLE-CLOUD-PLATFORM. Country: NL. Timestamp: 2026-10-04T20:39:03+00:00.
show less
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-10-04 20:08:55
(16 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-04 20:08:08
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.141.136.132 (132.136.141.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.141.136.132 (132.136.141.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 16:08:00.322819 2026] [security2:error] [pid 28941:tid 28941] [client 34.141.136.132:60542] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "calentadoresdemexico.com.mx"] [uri "/static../.env"] [unique_id "asKyIBFCNa343m2N6VJTEgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
masterguru
2026-10-04 19:34:12
(17 hours ago)
Inbound Anomaly Score Exceeded (Total Score: 5). Operator GE matched 5 at TX:anomaly_score. (949110- ...
show more
Inbound Anomaly Score Exceeded (Total Score: 5). Operator GE matched 5 at TX:anomaly_score. (949110-122)
show less
Hacking
Anonymous
2026-10-04 19:26:29
(17 hours ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection