๐บ๐ธ
TPI-Abuse
2026-09-04 01:40:04
(18 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.142.218.13 (13.218.142.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.142.218.13 (13.218.142.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 21:39:55.944123 2026] [security2:error] [pid 14101:tid 14101] [client 34.142.218.13:54308] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.shhcenter.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "apoha7gBT1XUCkk_G_GD3gAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-04 01:37:09
(21 minutes ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-196)
Hacking
Web App Attack
๐ฉ๐ช
Vegascosmetics
2026-09-04 00:42:34
(1 hour ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after first-seen suspicion / AbuseIPDB repu ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after first-seen suspicion / AbuseIPDB reputation policy (no URL signature). Evidence: Suspicion-Ban (Score 85>=65, Abuse 100, NonEU, first-seen)
show less
Hacking
Exploited Host
Web App Attack
Anonymous
2026-09-04 00:07:59
(1 hour ago)
Multiple web server 400 error codes from same source ip
Web App Attack
๐ท๐ด
iulianh
2026-09-04 00:07:02
(1 hour ago)
80,443
Brute-Force
SSH
๐ณ๐ฑ
BlueWire Hosting
2026-09-03 23:34:25
(2 hours ago)
High-confidence malicious configuration/VCS probe
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-03 23:28:06
(2 hours ago)
Excessive multi-domain requests
Brute-Force
๐ง๐ช
cmbplf
2026-09-03 23:06:35
(2 hours ago)
11.397 requests from abuseipdb.com blacklisted IP (10mos1w6d)
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-03 22:08:14
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.142.218.13 (13.218.142.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.142.218.13 (13.218.142.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 18:08:05.784699 2026] [security2:error] [pid 23573:tid 23573] [client 34.142.218.13:2372] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "female-strippers-los-angeles.com"] [uri "/@fs/../.env"] [unique_id "apnvxfmUG-ij737osonS-QAAAGo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-03 21:50:32
(4 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-03 21:47:47
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.142.218.13 (13.218.142.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.142.218.13 (13.218.142.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 17:47:43.096944 2026] [security2:error] [pid 26066:tid 26066] [client 34.142.218.13:14304] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.irishsetterclubofseattle.com"] [uri "/@fs/root/.env"] [unique_id "apnq_24m6mx2PC9VDNVGWgAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-03 20:59:47
(4 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
๐ฆ๐บ
aranguren.org
2026-09-03 20:45:40
(5 hours ago)
34.142.218.13 - - [04/Sep/2026:06:45:39 +1000] "GET /@fs/.env.staging?raw?? HTTP/1.1" 404 1172 "http ...
show more
34.142.218.13 - - [04/Sep/2026:06:45:39 +1000] "GET /@fs/.env.staging?raw?? HTTP/1.1" 404 1172 "https://faucet.luis.im/@fs/.env.staging?raw??" "Mozilla/5.0 (Windows NT 11.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; +https://www.anthropic.com/claude-user) Chrome/91.0.6126.233 Safari/537.36"
34.142.218.13 - - [04/Sep/2026:06:45:39 +1000] "GET /@fs/root/.aws/credentials.backup?raw?? HTTP/1.1" 404 1204 "https://faucet.luis.im/@fs/root/.aws/credentials.backup?raw??" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko; compatible; Slackbot-LinkExpanding/1.0; +https://api.slack.com/robots) Chrome/126.0.7350.75 Safari/537.36"
34.142.218.13 - - [04/Sep/2026:06:45:39 +1000] "GET /@fs/.env.local?raw?? HTTP/1.1" 404 1168 "https://faucet.luis.im/@fs/.env.local?raw??" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; OAI-SearchBot/1.3; +https://openai.com/searchbot)"
34.142.218.13 - - [04/Sep/2026:06:45:39 +1000] "GET /@fs/app/.
...
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-03 20:39:38
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.142.218.13 (13.218.142.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.142.218.13 (13.218.142.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 16:39:30.714310 2026] [security2:error] [pid 787:tid 787] [client 34.142.218.13:17032] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "seacorre.seacorre.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "apnbAhLSXd9ZXZqIUe52DgAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
metaldaze80
2026-09-03 20:37:57
(5 hours ago)
Fail2ban: 5 bad attempts in 10m on tcp port http,https
Web App Attack