π¦πΊ
Klaverstyn
2026-08-17 05:05:51
(1 week ago)
Persistent attacker, repeat offender
Hacking
π³π±
i-turnradio.nl
2026-08-15 22:07:57
(1 week ago)
2026-08-16 @ 00:07:56 (CET) ~ Blocked for trying to access: /.gitlab-ci.yml
Web App Attack
π¦πΊ
Klaverstyn
2026-08-15 21:05:29
(1 week ago)
Cross-vhost secrets/RCE probing campaign
Web App Attack
Hacking
π³π±
i-turnradio.nl
2026-08-15 20:54:27
(1 week ago)
2026-08-15 @ 22:54:27 (CET) ~ Blocked for trying to access: /__/firebase/init.json
Web App Attack
π³π±
i-turnradio.nl
2026-08-15 20:34:26
(1 week ago)
2026-08-15 @ 22:34:25 (CET) ~ Blocked for trying to access: /env.json
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-15 19:53:58
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.158.8.107 (107.8.158.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.158.8.107 (107.8.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 15 15:53:51.233236 2026] [security2:error] [pid 22489:tid 22489] [client 34.158.8.107:43594] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "secure.scc1.us"] [uri "/public/.env"] [unique_id "aoDDz1R82GZIgF7-62tt2gAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
i-turnradio.nl
2026-08-15 18:51:03
(1 week ago)
2026-08-15 @ 20:51:03 (CET) ~ Blocked for trying to access: /api/v2/config
Web App Attack
π©πͺ
Hazzard
2026-08-15 18:46:30
(1 week ago)
(PERMBLOCK) 34.158.8.107 (US/United States/Oregon/The Dalles/107.8.158.34.bc.googleusercontent.com/[ ...
show more
(PERMBLOCK) 34.158.8.107 (US/United States/Oregon/The Dalles/107.8.158.34.bc.googleusercontent.com/[redacted]) has had more than 4 temp blocks
show less
Hacking
πΊπΈ
TPI-Abuse
2026-08-15 18:08:25
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 34.158.8.107 (107.8.158.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.158.8.107 (107.8.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 15 14:08:18.297568 2026] [security2:error] [pid 23073:tid 23073] [client 34.158.8.107:39352] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||secure.sunsettrailsardmore.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "secure.sunsettrailsardmore.com"] [uri "/rclone.conf"] [unique_id "aoCrEv8h3DhOK8jZCmEc_QAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-15 17:48:24
(1 week ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-15 17:46:19
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.158.8.107 (107.8.158.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.158.8.107 (107.8.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 15 13:46:12.938670 2026] [security2:error] [pid 25164:tid 25164] [client 34.158.8.107:57590] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "search.feaverslane.com"] [uri "/.env"] [unique_id "aoCl5A3QTr0zNabxOD1WcwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
i-turnradio.nl
2026-08-15 17:20:37
(1 week ago)
2026-08-15 @ 19:20:36 (CET) ~ Blocked for trying to access: /.github/.env
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-15 17:04:59
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 34.158.8.107 (107.8.158.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.158.8.107 (107.8.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 15 13:04:52.092816 2026] [security2:error] [pid 21698:tid 21698] [client 34.158.8.107:46416] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||partner.markgiffin.com|F|2"] [data ".markgiffin.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "partner.markgiffin.com"] [uri "/z9x8c7v6b5-debug-trigger-partner.markgiffin.com"] [unique_id "aoCcNJ1F1ukboXWOwckOrgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-15 16:25:05
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 34.158.8.107 (107.8.158.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.158.8.107 (107.8.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 15 12:24:58.049372 2026] [security2:error] [pid 813068:tid 813068] [client 34.158.8.107:54356] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||new.davisllp.com|F|2"] [data ".davisllp.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "new.davisllp.com"] [uri "/z9x8c7v6b5-debug-trigger-new.davisllp.com"] [unique_id "aoCS2tcH9H-Bfw7sUDwE0wAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
gws-hostmaster
2026-08-15 16:24:49
(1 week ago)
ModSecurity OWASP CRS (Anomaly Score: 10): Restricted File Access Attempt;URL file extension is rest ...
show more
ModSecurity OWASP CRS (Anomaly Score: 10): Restricted File Access Attempt;URL file extension is restricted by policy;
show less
Web App Attack