๐บ๐ธ
TPI-Abuse
2026-09-03 17:19:08
(3 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.147.3.173 (173.3.147.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.147.3.173 (173.3.147.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 13:19:04.435600 2026] [security2:error] [pid 18442:tid 18442] [client 34.147.3.173:26780] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.dunbartonucc.org"] [uri "/@fs/root/.env"] [unique_id "apmsCC9_rsqO9TpZEUwn_AAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alboweb B.V.
2026-09-03 17:11:09
(11 minutes ago)
Bad web bot activity detected by Fail2Ban in plesk-apache-badbot jail
Bad Web Bot
Anonymous
2026-09-03 17:06:08
(16 minutes ago)
Trying to access config files
Web App Attack
๐ฎ๐น
VHosting
2026-09-03 17:05:03
(17 minutes ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-03 17:02:38
(19 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.147.3.173 (173.3.147.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.147.3.173 (173.3.147.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 13:02:33.303358 2026] [security2:error] [pid 11184:tid 11184] [client 34.147.3.173:13316] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "energyworker.us"] [uri "/@fs/.env"] [unique_id "apmoKcLHvOfM0zfIcdLVkwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-09-03 17:00:17
(21 minutes ago)
189 requests with url.path *config.json
103 requests with url.path *.config/*
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-03 16:44:30
(37 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.147.3.173 (173.3.147.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.147.3.173 (173.3.147.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 12:44:24.825805 2026] [security2:error] [pid 30752:tid 30752] [client 34.147.3.173:32450] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.innerstreammedia.com"] [uri "/@fs/app/.env"] [unique_id "apmj6JaTO1y6ymuZre5xUQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Mendip_Defender
2026-09-03 16:42:36
(39 minutes ago)
34.147.3.173 - - [03/Sep/2026:17:42:48 +0100] "GET /@fs/home/debian/.aws/credentials?raw?? HTTP/1.1" ...
show more
34.147.3.173 - - [03/Sep/2026:17:42:48 +0100] "GET /@fs/home/debian/.aws/credentials?raw?? HTTP/1.1" 404 6446 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.4; +https://openai.com/gptbot) Chrome/114.0.8046.5 Safari/537.36"
...
show less
Bad Web Bot
๐ซ๐ท
masterguru
2026-09-03 16:38:39
(43 minutes ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.147.3.173 (NL/The Netherlands/173. ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.147.3.173 (NL/The Netherlands/173.3.147.34.bc.googleusercontent.com): 2 in the last 3600 secs (0-196)
show less
Hacking
๐ฟ๐ฆ
conure.sh
2026-09-03 16:36:26
(45 minutes ago)
csagent: score 20.0: secrets grab x2; 1 domain(s) in 6s
Web App Attack
Anonymous
2026-09-03 16:20:19
(1 hour ago)
Aggressive web scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-03 16:17:13
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.147.3.173 (173.3.147.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.147.3.173 (173.3.147.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 12:17:08.759390 2026] [security2:error] [pid 1871:tid 1871] [client 34.147.3.173:32202] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.webtony.net"] [uri "/@fs/root/.env"] [unique_id "apmdhGcag9AmRTfrTNIpRQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack