๐บ๐ธ
TPI-Abuse
2026-06-15 17:26:59
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 34.176.239.81 (81.239.176.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.176.239.81 (81.239.176.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 13:26:54.638765 2026] [security2:error] [pid 31511:tid 31511] [client 34.176.239.81:51336] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||valuerec.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "valuerec.com"] [uri "/.config/gcloud/credentials.db"] [unique_id "ajA13u9As0JQKp1G-N-wpgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-06-15 13:15:44
(3 months ago)
20 attempts against mh_ha-misbehave-ban on pf221104
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
Proton7214
2026-06-15 12:18:41
(3 months ago)
GGS honeypot: Scanner hit honeypot `/trace` โ GET /trace
Web App Attack
๐ซ๐ท
Octopuce
2026-06-15 09:48:21
(3 months ago)
Aggressive web search of vulnerable pages: /services/.env.local /server/.env.local /admin/.env /serv ...
show more
Aggressive web search of vulnerable pages: /services/.env.local /server/.env.local /admin/.env /services/.env /service/.env ...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 06:08:50
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 34.176.239.81 (81.239.176.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.176.239.81 (81.239.176.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 02:03:19.875433 2026] [security2:error] [pid 7284:tid 7284] [client 34.176.239.81:57156] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "elsejewelry.fabulouswire.net"] [uri "/.env.test"] [unique_id "ai-Vp6M9DnYiAbN3AOnhGAAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-06-15 05:18:42
(3 months ago)
Excessive multi-domain requests
Brute-Force
๐ธ๐ฌ
securejdprop
2026-06-15 05:01:04
(3 months ago)
This IP was detected by CrowdSec triggering crowdsecurity/suricata-major-severity(๐พ - ๐ Many TCP/SYN ...
show more
This IP was detected by CrowdSec triggering crowdsecurity/suricata-major-severity(๐พ - ๐ Many TCP/SYN - Possible Masscan Network Service Discovery ๐ฅท - T1046). Ip 34.176.239.81 performed 'crowdsecurity/suricata-major-severity' (1 events over 0s) at 2026-06-15 05:01:03.139909529 +0000 UTC
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 05:00:47
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 34.176.239.81 (81.239.176.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.176.239.81 (81.239.176.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 01:00:43.886815 2026] [security2:error] [pid 11319:tid 11319] [client 34.176.239.81:44924] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "expresstires.us"] [uri "/.env.txt"] [unique_id "ai-G-4rNeV_CjDcUaVERXwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-06-15 04:07:02
(3 months ago)
Scanning/Probing (111)
Request Overload (116)
Brute-Force
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2026-06-15 03:23:51
(3 months ago)
(modsecurity) srv102 ModSecurity 34.176.239.81 (81.239.176.34.bc.googleusercontent.com): 10 in the l ...
show more
(modsecurity) srv102 ModSecurity 34.176.239.81 (81.239.176.34.bc.googleusercontent.com): 10 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 03:13:50
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 34.176.239.81 (81.239.176.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.176.239.81 (81.239.176.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 23:13:45.310211 2026] [security2:error] [pid 27743:tid 27743] [client 34.176.239.81:35638] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "norkyn.austli.com"] [uri "/.env.example"] [unique_id "ai9t6SRCHAaIKbvxMbOyOAAAACo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
nekopavel
2026-06-15 02:12:26
(3 months ago)
34.176.239.81 - - [15/Jun/2026:04:12:22 +0200]"GET /.env.backup HTTP/1.1" 404 530"-" uwu.so "Mozilla ...
show more
34.176.239.81 - - [15/Jun/2026:04:12:22 +0200]"GET /.env.backup HTTP/1.1" 404 530"-" uwu.so "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_13_6) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/12.1 Safari/605.1.15""0.017" "0.000""Santiago" "CL"
34.176.239.81 - - [15/Jun/2026:04:12:22 +0200]"GET /.env.old HTTP/1.1" 404 530"-" uwu.so "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_5) AppleWebKit/600.8.9 (KHTML, like Gecko) Maxthon/4.5.2""0.016" "0.000""Santiago" "CL"
34.176.239.81 - - [15/Jun/2026:04:12:22 +0200]"GET /.env.production HTTP/1.1" 404 530"-" uwu.so "BlackBerry9700/5.0.0.351 Profile/MIDP-2.1 Configuration/CLDC-1.1 VendorID/123""0.016" "0.001""Santiago" "CL"
...
show less
Hacking
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-06-15 01:50:02
(3 months ago)
trying wp-login.php/xmlrpc.php 150 times in 1 minutes
Brute-Force
Web App Attack
Anonymous
2026-06-14 19:17:48
(3 months ago)
[ssd1.kdns.gr] httpd-suspicious-path: sites=global; logs=/var/log/httpd/access_log; samples=/backend ...
show more
[ssd1.kdns.gr] httpd-suspicious-path: sites=global; logs=/var/log/httpd/access_log; samples=/backend/.env.backup | /.env.dev | /backend/.env.staging
show less
Hacking
Web App Attack
๐ณ๐ฑ
Savvii
2026-06-14 14:16:10
(3 months ago)
63 attempts against mh-misbehave-ban on cedar
Brute-Force
Bad Web Bot
Web App Attack