๐ง๐ช
boxed-it
2026-06-15 11:42:38
(13 hours ago)
GET /.env (Tarpitted for 1d15h8m28s, wasted 8.06MB)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 04:50:27
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.175.141.169 (169.141.175.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.175.141.169 (169.141.175.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 00:50:23.919248 2026] [security2:error] [pid 12459:tid 12483] [client 34.175.141.169:44266] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/config/config.yml" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.mjkotob.com"] [uri "/config/config.yml"] [unique_id "ai-Ejw7lyAKz8I1WY49oOAAAARU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 03:47:04
(21 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.175.141.169 (169.141.175.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.175.141.169 (169.141.175.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 23:46:57.542161 2026] [security2:error] [pid 29517:tid 29542] [client 34.175.141.169:56572] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.gffm.aafm.us|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.gffm.aafm.us"] [uri "/.config/gcloud/credentials.db"] [unique_id "ai91sXIS9EALsNu_ffysTwAAAVM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-15 02:36:53
(22 hours ago)
Multiple web server 400 error codes from same source ip
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 01:36:00
(23 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.175.141.169 (169.141.175.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.175.141.169 (169.141.175.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 21:35:56.922055 2026] [security2:error] [pid 27965:tid 27965] [client 34.175.141.169:51706] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||blackoakprop.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "blackoakprop.com"] [uri "/.config/gcloud/credentials.db"] [unique_id "ai9W_IVhHI1h9SJNSJ25PwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-06-15 00:17:20
(1 day ago)
Scanning/Probing (61)
Request Overload (427)
Brute-Force
Web App Attack
๐ณ๐ด
Bots.go.to.hell
2026-06-15 00:09:13
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐ณ๐ฑ
Cloud86 B.V.
2026-06-14 23:39:07
(1 day ago)
categories: DDoS Attack
DDoS Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 06:19:51
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.175.141.169 (169.141.175.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.175.141.169 (169.141.175.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 02:19:47.116550 2026] [security2:error] [pid 2512:tid 2512] [client 34.175.141.169:45960] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.bigpapajames.jasbemarketing.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.bigpapajames.jasbemarketing.com"] [uri "/.config/gcloud/credentials.db"] [unique_id "ai5IAw4LLiE_R5WgELwKuAAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 03:38:53
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.175.141.169 (169.141.175.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.175.141.169 (169.141.175.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 23:38:49.276452 2026] [security2:error] [pid 32067:tid 32067] [client 34.175.141.169:53986] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/config/parameters.yml" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.handyrehab.zunosaki.com"] [uri "/config/parameters.yml"] [unique_id "ai4iSUuqCDJdBBLwLLH7uAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack