๐บ๐ธ
TPI-Abuse
2026-10-09 05:52:39
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.148.206.83 (83.206.148.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.148.206.83 (83.206.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 01:52:33.555018 2026] [security2:error] [pid 15490:tid 15490] [client 34.148.206.83:55748] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "whiterhinogroup.net"] [uri "/img../.env"] [unique_id "asiBIdmgrRfJVCqxoStp8gAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-10-09 05:23:07
(6 hours ago)
20 attempts against mh-misbehave-ban on ozone
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
openstrike.co.uk
2026-10-09 05:15:04
(6 hours ago)
147 attacks on env grabbing URLs (type 2), password/key grabbing URLs, directory traversals, PHP URL ...
show more
147 attacks on env grabbing URLs (type 2), password/key grabbing URLs, directory traversals, PHP URLs, config grabbing URLs (type 2), VC URLs, env grabbing URLs, shell probes:
GET /userfiles/x?path=../../../../proc/self/environ HTTP/1.1
GET /.git-credentials HTTP/1.1
GET /..%2f..%2f.env HTTP/1.1
POST /index.php?-d+allow_url_include%3don+-d+auto_prepend_file%3dphp://input HTTP/1.1
GET /secrets.yml HTTP/1.1
GET /.git/HEAD HTTP/1.1
GET /.//.env HTTP/1.1
POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1
show less
Hacking
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-09 05:10:46
(6 hours ago)
[ti-12al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 34. ...
show more
[ti-12al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 34.148.206.83 - - \[09/Oct/2026:07:10:40 +0200\] "GET /public../.env HTTP/2.0" 301 370 "-" "Mozilla/5.0 \(compatible\; Meta-ExternalAgent/1.0\; +https://developers.facebook.com/docs/sharing/webmasters/crawler\)"
...
show less
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-10-09 05:08:24
(6 hours ago)
Web attack/malicious scanning detected
Web App Attack
Anonymous
2026-10-09 04:18:28
(7 hours ago)
Fuzzing/Looking for credentials files.
Brute-Force
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-10-09 04:16:31
(7 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 04:14:02
(7 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.148.206.83 (83.206.148.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.148.206.83 (83.206.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 00:13:54.206656 2026] [security2:error] [pid 19728:tid 19728] [client 34.148.206.83:52590] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||whatyouhear.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "whatyouhear.com"] [uri "/z9x8c7v6b5-debug-trigger-whatyouhear.com"] [unique_id "ashqAvYau7l8-CHIs5leZwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-10-09 03:54:35
(7 hours ago)
[FriOct0905:54:28.6972172026][security2:error][pid2122164:tid2122239][client34.148.206.83:0]ModSecur ...
show more
[FriOct0905:54:28.6972172026][security2:error][pid2122164:tid2122239][client34.148.206.83:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:queryintrospectionquery\?\|__schema\\\\\\\\\?{\?\(\?:querytype\|types\?\)\)\?\\\\\\\\{\"atREQUEST_BODY.[file\"/etc/apache2/conf.d/modsec_rules/10_asl_rules.conf\"][line\"234\"][id\"344378\"][rev\"2\"][msg\"Atomicorp.comWAFRules:GraphQLInjectionAttackattempt\"][data\"MatchedData:__schema{types{foundwithinREQUEST_BODY:{\\\\x22query\\\\x22:\\\\x22{__schema{types{namefields{nameargs{namedefaultvalue}}}}}\\\\x22}\"][severity\"CRITICAL\"][tag\"SQLi\"][hostname\"whatsdecor.ch\"][uri\"/graphql\"][unique_id\"ashldFxjLVXf5MsATgXOiQAAAQY\"]\,referer:https://whatsdecor.ch
show less
Hacking
Web App Attack
๐ฉ๐ช
arnisolutions
2026-10-09 03:53:00
(7 hours ago)
Vulnerability scanning (requests for admin panels, shells, backup files etc.) against a production s ...
show more
Vulnerability scanning (requests for admin panels, shells, backup files etc.) against a production server. Observed on 1 day(s) between 2026-10-09 and 2026-10-09 (UTC). Sample request: GET /pages/api/index.astro.mjs.map HTTP/2.0
show less
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-09 03:30:26
(8 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.148.206.83 (83.206.148.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.148.206.83 (83.206.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 23:30:21.526813 2026] [security2:error] [pid 6493:tid 6493] [client 34.148.206.83:36434] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||whaletailpuckerbutt.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "whaletailpuckerbutt.com"] [uri "/z9x8c7v6b5-debug-trigger-whaletailpuckerbutt.com"] [unique_id "ashfzdlrAtZQFSoL-5Uo0QAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 03:15:12
(8 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.148.206.83 (83.206.148.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.148.206.83 (83.206.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 23:15:05.499899 2026] [security2:error] [pid 10009:tid 10009] [client 34.148.206.83:46762] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||wgalleria.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "wgalleria.com"] [uri "/z9x8c7v6b5-debug-trigger-wgalleria.com"] [unique_id "ashcOWHtL24LW26zSQSeQQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ท
Peregrine
2026-10-09 03:12:15
(8 hours ago)
Fail2Ban ct101 Jail: tomcat-404 | Evidence: 34.148.206.83 104.22.1.98 - - [08/Oct/2026:17:12:40 -030 ...
show more
Fail2Ban ct101 Jail: tomcat-404 | Evidence: 34.148.206.83 104.22.1.98 - - [08/Oct/2026:17:12:40 -0300] "GET /z9x8c7v6b5-debug-trigger-decise.com.br HTTP/1.1" 404 18149
34.148.206.83 104.22.1.99 - - [08/Oct/2026:17:12:40 -0300] "GET /m7zhu232sluhqt8zaoi6 HTTP/1.1" 404 18149
34.148.206.83 104.22.1.99 - - [08/Oct/2026:17:12:40 -0300] "GET /dist/manifest.json HTTP/1.1" 404 18149
34.148.206.83 104.22.1.99 - - [08/Oct/2026:17:12:40 -0300] "GET /.vite/manifest.json HTTP/1.1" 404 18149
34.148.206.83 104.22.1.41 - - [08/Oct/2026:17:12:40 -0300] "GET /dist/.vite/manifest.json HTTP/1.1" 404 18149
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 02:54:35
(8 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.148.206.83 (83.206.148.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.148.206.83 (83.206.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 22:54:28.901042 2026] [security2:error] [pid 20508:tid 20508] [client 34.148.206.83:47876] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||wexfordcap.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "wexfordcap.com"] [uri "/z9x8c7v6b5-debug-trigger-wexfordcap.com"] [unique_id "ashXZBWyk5CX2Ud2SV2M5wAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฟ๐ฆ
vanderhost
2026-10-09 02:39:29
(8 hours ago)
[Laravel HoneypotPlus] Automated report - Honeypot access detected on path: /.env.js via rule: regex ...
show more
[Laravel HoneypotPlus] Automated report - Honeypot access detected on path: /.env.js via rule: regex:/^\/\.env/i
show less
Web App Attack
Bad Web Bot