๐บ๐ธ
TPI-Abuse
2026-10-01 14:51:31
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.159.197.195 (195.197.159.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.159.197.195 (195.197.159.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 10:51:27.846225 2026] [security2:error] [pid 30168:tid 30168] [client 34.159.197.195:58756] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.brupharm.net"] [uri "/.env.production"] [unique_id "ar5zb8U0QTs2pvwlDKtNSgAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-01 14:30:07
(20 hours ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-10-01 14:08:55
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.159.197.195 (195.197.159.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.159.197.195 (195.197.159.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 10:08:51.739660 2026] [security2:error] [pid 27503:tid 27503] [client 34.159.197.195:50596] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.retiredengineers.net"] [uri "/static../.env"] [unique_id "ar5pc1ATDIa53O50sMBk8wAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 13:49:45
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.159.197.195 (195.197.159.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.159.197.195 (195.197.159.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 09:49:41.463566 2026] [security2:error] [pid 29475:tid 29475] [client 34.159.197.195:38344] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.bencramer.net"] [uri "/wp-config.php.bak"] [unique_id "ar5k9TCL9c3hv_RJfLsAiwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-01 13:40:54
(20 hours ago)
IP matched detection query 50 and more bad rqs apache.
Hacking
Bad Web Bot
Brute-Force
Web App Attack
๐ฉ๐ช
updown.io
2026-10-01 13:34:25
(21 hours ago)
{"level":"info","ts":1790861664.9420764,"logger":"http.log.access.log1","msg":"handled request","req ...
show more
{"level":"info","ts":1790861664.9420764,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.159.197.195","remote_port":"33740","client_ip":"34.159.197.195","proto":"HTTP/2.0","method":"GET","host":"status.patpro.net","uri":"/manifest.json","headers":{"Sec-Fetch-User":["?1"],"Accept-Encoding":["gzip, deflate, br, zstd"],"Sec-Fetch-Mode":["navigate"],"User-Agent":["Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36 Edg/152.0.0.0"],"Accept-Language":["en-US,en;q=0.9"],"Priority":["u=0, i"],"Upgrade-Insecure-Requests":["1"],"Sec-Ch-Ua-Platform":["\"Windows\""],"Sec-Ch-Ua-Mobile":["?0"],"Sec-Fetch-Dest":["document"],"X-Nextjs-Data":["1"],"Sec-Ch-Ua":["\"Chromium\";v=\"152\", \"Not?A_Brand\";v=\"24\", \"Microsoft Edge\";v=\"152\""],"X-Middleware-Subrequest":["src/middleware:nowaf:src/middleware:src/middleware:src/middleware:src/middleware:middleware:middleware:nowaf:middleware:middleware:middleware:pa
...
show less
DDoS Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 13:31:06
(21 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.159.197.195 (195.197.159.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.159.197.195 (195.197.159.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 09:30:58.743899 2026] [security2:error] [pid 30850:tid 30850] [client 34.159.197.195:37244] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||tracytappan.net|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "tracytappan.net"] [uri "/rclone.conf"] [unique_id "ar5gkqTcAFE7-ihYd5ll_wAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-01 13:20:59
(21 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 13:15:08
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.159.197.195 (195.197.159.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.159.197.195 (195.197.159.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 09:15:03.304293 2026] [security2:error] [pid 20111:tid 20111] [client 34.159.197.195:43232] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/Web.config" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.beckerbrokerage.net"] [uri "/web.config"] [unique_id "ar5c15mIUGMyRSassWvI6gAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-01 13:07:51
(21 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
Anonymous
2026-10-01 12:59:18
(21 hours ago)
Bad bot
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-01 12:58:26
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.159.197.195 (195.197.159.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.159.197.195 (195.197.159.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 08:58:22.294777 2026] [security2:error] [pid 26520:tid 26520] [client 34.159.197.195:44718] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dbanetwork.net"] [uri "/.htpasswd"] [unique_id "ar5Y7rs1VeNOvdt_rjD4BwAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-01 12:50:45
(21 hours ago)
[backup01al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. E ...
show more
[backup01al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.159.197.195 - - [01/Oct/2026:14:50:38 +0200] "GET /.env.staging HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)"
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2026-10-01 12:38:10
(21 hours ago)
Bad bot ignoring robot.txt
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-01 12:35:50
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.159.197.195 (195.197.159.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.159.197.195 (195.197.159.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 08:35:45.445447 2026] [security2:error] [pid 31746:tid 31746] [client 34.159.197.195:37020] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.bodeur.net"] [uri "/.htpasswd"] [unique_id "ar5ToY7b7S4WqHnRbUkJ1wAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack