🇺🇸
TPI-Abuse
2026-09-12 10:34:05
(42 minutes ago)
(mod_security) mod_security (id:210730) triggered by 34.156.129.223 (223.129.156.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.156.129.223 (223.129.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 06:33:59.766174 2026] [security2:error] [pid 16588:tid 16588] [client 34.156.129.223:46036] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.fydelitybags.com|F|2"] [data ".fydelitybags.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.fydelitybags.com"] [uri "/z9x8c7v6b5-debug-trigger-mail.fydelitybags.com"] [unique_id "aqUql11S9AgaNp8ELOKaUAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 10:18:37
(57 minutes ago)
(mod_security) mod_security (id:210730) triggered by 34.156.129.223 (223.129.156.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.156.129.223 (223.129.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 06:18:30.388333 2026] [security2:error] [pid 16030:tid 16030] [client 34.156.129.223:34510] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.funkerecords.com|F|2"] [data ".funkerecords.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.funkerecords.com"] [uri "/z9x8c7v6b5-debug-trigger-mail.funkerecords.com"] [unique_id "aqUm9pUWk5sopecNmzltTgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
Progetto1
2026-09-11 18:30:13
(16 hours ago)
Multiple exploit attempts
Hacking
Brute-Force
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 18:25:42
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.156.129.223 (223.129.156.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.156.129.223 (223.129.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 14:25:36.033734 2026] [security2:error] [pid 23471:tid 23471] [client 34.156.129.223:52992] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fxbgsanta.com"] [uri "/img../.env"] [unique_id "aqRHoFN7US9Z6RfxkmSR-QAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 18:06:08
(17 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.156.129.223 (223.129.156.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.156.129.223 (223.129.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 14:06:04.689427 2026] [security2:error] [pid 20296:tid 20296] [client 34.156.129.223:44210] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||futuresgrowhere.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "futuresgrowhere.com"] [uri "/rclone.conf"] [unique_id "aqRDDNNDgnH4DbQYebjJFQAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 17:47:40
(17 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.156.129.223 (223.129.156.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.156.129.223 (223.129.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 13:47:33.271342 2026] [security2:error] [pid 25257:tid 25257] [client 34.156.129.223:42366] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||fusionrep.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "fusionrep.com"] [uri "/rclone.conf"] [unique_id "aqQ-tV6ZIzPO4hEzqqVSAQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇪🇸
pydsoluciones
2026-09-11 17:46:28
(17 hours ago)
PrestaShop Security Module: Suspicious path detected (/.env)
Web App Attack
Anonymous
2026-09-11 17:41:58
(17 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇵🇱
wielorzeczownik
2026-09-11 17:38:02
(17 hours ago)
5 failed attempts
2026-09-11 19:38:01 GET /.env?raw?? -> 404
2026-09-11 19:38:01 GET /static/app ...
show more
5 failed attempts
2026-09-11 19:38:01 GET /.env?raw?? -> 404
2026-09-11 19:38:01 GET /static/app/.env -> 404
2026-09-11 19:38:01 GET /static/.env -> 404
2026-09-11 19:38:01 GET /.env -> 404
2026-09-11 19:38:01 GET /.env -> 404
show less
Web App Attack
Hacking
Anonymous
2026-09-11 17:22:52
(17 hours ago)
FUNDATCOM WEBEXPLOIT 34.156.129.223 (223.129.156.34.bc.googleusercontent.com)
Web App Attack
🇮🇹
VHosting
2026-09-11 17:15:04
(18 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇫🇷
dynamix
2026-09-11 17:06:40
(18 hours ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 16:26:25
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.156.129.223 (223.129.156.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.156.129.223 (223.129.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 12:26:18.078520 2026] [security2:error] [pid 30372:tid 30372] [client 34.156.129.223:34142] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fulltime-life.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "aqQrqrs85IF29ebjNwJ3JAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack