🇳🇱
Mangelot Hosting
2026-09-15 17:43:35
(14 minutes ago)
(modsecurity) srv102 ModSecurity 34.148.125.166 (US/United States/166.125.148.34.bc.googleuserconten ...
show more
(modsecurity) srv102 ModSecurity 34.148.125.166 (US/United States/166.125.148.34.bc.googleusercontent.com): 30 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-15 17:36:21
(21 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.148.125.166 (166.125.148.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.148.125.166 (166.125.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 13:36:17.501709 2026] [security2:error] [pid 32458:tid 32591] [client 34.148.125.166:57730] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "arthansl.com"] [uri "/.git/config"] [unique_id "aqmCEcXai-ozQd4PiFRT7QAAAE0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
Major Hostility
2026-09-15 17:00:11
(58 minutes ago)
"GET /build/manifest.json HTTP/1.1" 404
"GET /rclone.conf HTTP/1.1" 404
"GET /proc/self/cmdline HTTP ...
show more
"GET /build/manifest.json HTTP/1.1" 404
"GET /rclone.conf HTTP/1.1" 404
"GET /proc/self/cmdline HTTP/1.1" 404
"GET /.dockerenv HTTP/1.1" 404
"GET /proc/self/cgroup HTTP/1.1" 404
"GET /z9x8c7v6b5-debug-trigger-[DOMAIN] HTTP/1.1" 404
"GET /.env?import&raw HTTP/1.1" 404
"POST /graphql HTTP/1.1" 404
"POST /api/graphql HTTP/1.1" 404
"GET /.env.local?raw HTTP/1.1" 404
"GET /.env.local?import&raw HTTP/1.1" 404
"GET /.vite/manifest.json HTTP/1.1" 404
"GET /.env?raw HTTP/1.1" 404
"GET /.env.production?raw HTTP/1.1" 404
"GET /.env.production?import&raw HTTP/1.1" 404
"GET /.env.development?raw HTTP/1.1" 404
"GET /.env.development?import&raw HTTP/1.1" 404
"GET /@fs/app/.env.pro
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-15 16:42:57
(1 hour ago)
(mod_security) mod_security (id:210580) triggered by 34.148.125.166 (166.125.148.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210580) triggered by 34.148.125.166 (166.125.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 12:42:49.962295 2026] [security2:error] [pid 28895:tid 28895] [client 34.148.125.166:38966] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at ARGS:filename. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||artandthebible.com|F|2"] [data "Matched Data: proc/self/environ found within ARGS:filename: file:/proc/self/environ"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "artandthebible.com"] [uri "/__vite_rsc_findSourceMapURL"] [unique_id "aql1iXQjSQeChY6Q1CsV7wAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-15 16:13:23
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.148.125.166 (166.125.148.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.148.125.166 (166.125.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 12:13:19.310189 2026] [security2:error] [pid 31490:tid 31490] [client 34.148.125.166:49698] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "arsenaultartistmanagement.com"] [uri "/%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env"] [unique_id "aqlun-estxAtYhe51FduTgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-09-15 16:05:44
(1 hour ago)
Scanning/Probing (28)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-15 15:56:25
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.148.125.166 (166.125.148.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.148.125.166 (166.125.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 11:56:18.356335 2026] [security2:error] [pid 4553:tid 4553] [client 34.148.125.166:51210] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||arroceraomoa.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "arroceraomoa.com"] [uri "/rclone.conf"] [unique_id "aqlqovomdwCDuGJlwA57OAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-15 15:45:03
(2 hours ago)
suspicious request in access.log
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-15 15:30:23
(2 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-cve-2021-41773
Web App Attack
Hacking
🇷🇴
clauss
2026-09-15 15:20:27
(2 hours ago)
34.148.125.166 - - [15/Sep/2026:18:20:26 +0300] "GET /secrets.yml HTTP/2.0" 301 0 "-" "Mozilla/5.0 A ...
show more
34.148.125.166 - - [15/Sep/2026:18:20:26 +0300] "GET /secrets.yml HTTP/2.0" 301 0 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)"
34.148.125.166 - - [15/Sep/2026:18:20:26 +0300] "GET /firebase-adminsdk.json HTTP/2.0" 301 0 "-" "Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)"
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-15 15:08:01
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.148.125.166 (166.125.148.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.148.125.166 (166.125.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 11:07:56.049469 2026] [security2:error] [pid 5829:tid 5829] [client 34.148.125.166:46738] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||aroilcontrolsystem.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "aroilcontrolsystem.com"] [uri "/rclone.conf"] [unique_id "aqlfTJaAQCFkQl_zGyIdYAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-15 15:03:00
(2 hours ago)
Excessive 404/403 errors
Brute-Force
🇩🇪
big-cloud.nl
2026-09-15 15:02:47
(2 hours ago)
Try to access /.env?import&url&inline
Web App Attack
🇨🇿
antihack.anarchista.xyz
2026-09-15 14:48:27
(3 hours ago)
404 burst: 20 hits in 5 min, URI /openapi.json, Ref , UA Mozilla/5.0 (compatible; Meta-ExternalAgent ...
show more
404 burst: 20 hits in 5 min, URI /openapi.json, Ref , UA Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)
show less
Brute-Force
Web App Attack
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-15 14:41:23
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.148.125.166 (166.125.148.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.148.125.166 (166.125.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 10:41:19.770273 2026] [security2:error] [pid 9423:tid 9423] [client 34.148.125.166:50672] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||armrms.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "armrms.com"] [uri "/rclone.conf"] [unique_id "aqlZD2G2tNmAqh_npJpfrQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack