๐บ๐ธ
TPI-Abuse
2026-10-02 15:33:42
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.141.78.112 (112.78.141.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.141.78.112 (112.78.141.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 11:33:35.186496 2026] [security2:error] [pid 19170:tid 19170] [client 34.141.78.112:35296] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.accredo.net"] [uri "/static//home/user/.env"] [unique_id "ar_Oz2_9E7asSav2oxCVDgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-10-02 15:18:08
(3 days ago)
Crawler ignoring refusals | ua: Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/), Mozilla/5.0 ...
show more
Crawler ignoring refusals | ua: Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/), Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Mobile Safari/537.36 EdgA/153.0.0.0, Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler) (+11 more) | path: /b1fbx4urhvazi67rb2jd, /build/manifest.json, /dist/.vite/manifest.json (+16 more)
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-02 15:04:50
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.141.78.112 (112.78.141.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.141.78.112 (112.78.141.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 11:04:43.918251 2026] [security2:error] [pid 1966:tid 1966] [client 34.141.78.112:45686] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.vrmapping.net"] [uri "/.htpasswd"] [unique_id "ar_ICz3ozUAcssDn3gh_LQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
ciccio diddo
2026-10-02 14:41:46
(3 days ago)
URL Scanner multiple 30X port:Tcp/80,443
Brute-Force
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-02 14:35:11
(3 days ago)
[backup01al] Web exploit scanning: 3 suspicious requests detected by fail2ban jail apache-scanner. E ...
show more
[backup01al] Web exploit scanning: 3 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.141.78.112 - - [02/Oct/2026:16:35:05 +0200] "GET /assets../.env HTTP/2.0" 403 350 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
monn45888
2026-10-02 14:33:38
(3 days ago)
$f2bV_matches
Web App Attack
๐ณ๐ฑ
Site.eu
2026-10-02 14:19:29
(3 days ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-10-02 14:06:34
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.141.78.112 (112.78.141.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.141.78.112 (112.78.141.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 10:06:27.807780 2026] [security2:error] [pid 10726:tid 10726] [client 34.141.78.112:48662] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "zmgmt.net"] [uri "/config/.env.php"] [unique_id "ar-6Y4Hwy8Lc2ti9Cy5togAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 13:44:45
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.141.78.112 (112.78.141.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.141.78.112 (112.78.141.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 09:44:37.642121 2026] [security2:error] [pid 18441:tid 18441] [client 34.141.78.112:49044] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.whysong.net"] [uri "/.htpasswd"] [unique_id "ar-1RXggJU0ZmQfLXdoi2QAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-10-02 13:18:39
(3 days ago)
Restricted File Access Attempt. Matched phrase ".ssh/" at REQUEST_FILENAME. (930130-196)
Hacking
Web App Attack
๐ฌ๐ง
noise.agency
2026-10-02 12:45:34
(3 days ago)
34.141.78.112 (DE/Germany/112.78.141.34.bc.googleusercontent.com), more than 10 Apache 403 hits
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-02 12:22:56
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.141.78.112 (112.78.141.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.141.78.112 (112.78.141.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 08:22:53.190676 2026] [security2:error] [pid 27937:tid 27937] [client 34.141.78.112:56772] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.iberhome.net"] [uri "/.htpasswd"] [unique_id "ar-iHUrOCXCrs6N6h8GDfAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
zumbo.net
2026-10-02 11:33:53
(3 days ago)
[Fri Oct 02 14:33:52.293445 2026] [proxy_fcgi:error] [pid 213039:tid 213063] [client 34.141.78.112:0 ...
show more
[Fri Oct 02 14:33:52.293445 2026] [proxy_fcgi:error] [pid 213039:tid 213063] [client 34.141.78.112:0] AH01071: Got error 'Primary script unknown'
[Fri Oct 02 14:33:52.356351 2026] [proxy_fcgi:error] [pid 213246:tid 213254] [client 34.141.78.112:0] AH01071: Got error 'Primary script unknown'
[Fri Oct 02 14:33:52.389967 2026] [proxy_fcgi:error] [pid 213278:tid 213304] [client 34.141.78.112:0] AH01071: Got error 'Primary script unknown'
[Fri Oct 02 14:33:52.393799 2026] [proxy_fcgi:error] [pid 213039:tid 213057] [client 34.141.78.112:0] AH01071: Got error 'Primary script unknown'
[Fri Oct 02 14:33:52.398172 2026] [proxy_fcgi:error] [pid 213039:tid 213060] [client 34.141.78.112:0] AH01071: Got error 'Primary script unknown'
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 11:26:24
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.141.78.112 (112.78.141.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.141.78.112 (112.78.141.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 07:26:17.601132 2026] [security2:error] [pid 22828:tid 22828] [client 34.141.78.112:32926] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.coolray.net"] [uri "/.env.js"] [unique_id "ar-U2e-FLgb9qeOBZ8k3GQAAAEo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 10:15:07
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.141.78.112 (112.78.141.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.141.78.112 (112.78.141.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 06:14:57.944113 2026] [security2:error] [pid 1034:tid 1034] [client 34.141.78.112:59942] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.icbsmonitor.net"] [uri "/.env.js"] [unique_id "ar-EIaGa2CJQKn7JTY6ApwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack