๐บ๐ธ
TPI-Abuse
2026-09-21 19:42:03
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.177.99.251 (251.99.177.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.177.99.251 (251.99.177.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 15:41:56.170385 2026] [security2:error] [pid 19760:tid 19760] [client 34.177.99.251:55578] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.jsw4.net"] [uri "/services/.env"] [unique_id "arGIhBi3c7xXP-368NcVCgAAAEA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
pscriptos
2026-09-21 19:28:04
(1 hour ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-21 18:27:41
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.177.99.251 (251.99.177.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.177.99.251 (251.99.177.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 14:27:33.295590 2026] [security2:error] [pid 26810:tid 26810] [client 34.177.99.251:38424] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.texaslawman.net"] [uri "/build/.env"] [unique_id "arF3FaMBf5_O7xijmZ5CyQAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 16:53:01
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.177.99.251 (251.99.177.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.177.99.251 (251.99.177.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 12:52:54.424247 2026] [security2:error] [pid 27377:tid 27377] [client 34.177.99.251:46608] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.thehallway.net"] [uri "/.git/config"] [unique_id "arFg5jd-v-7jdomG1rMZwgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-21 16:47:09
(4 hours ago)
34.177.99.251 - - [22/Sep/2026:00:47:08 +0800] "GET /.github/workflows/deploy.yml HTTP/1.1" 404 2964 ...
show more
34.177.99.251 - - [22/Sep/2026:00:47:08 +0800] "GET /.github/workflows/deploy.yml HTTP/1.1" 404 296486 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)"
...
show less
Bad Web Bot
Web App Attack
๐ต๐ฑ
sefinek.net
2026-09-21 16:25:38
(4 hours ago)
Triggered Cloudflare WAF (firewallCustom) from SG.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoi ...
show more
Triggered Cloudflare WAF (firewallCustom) from SG.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoint: /v1/graphql | UA: Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/) โข Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-21 15:35:39
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.177.99.251 (251.99.177.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.177.99.251 (251.99.177.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 11:35:32.774461 2026] [security2:error] [pid 22293:tid 22293] [client 34.177.99.251:50732] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.schoolsliaisoncommunity.net"] [uri "/@fs/app/.env"] [unique_id "arFOxM-_onqCoM5JMFKE4gAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 15:10:38
(5 hours ago)
(mod_security) mod_security (id:210580) triggered by 34.177.99.251 (251.99.177.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210580) triggered by 34.177.99.251 (251.99.177.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 11:10:33.605756 2026] [security2:error] [pid 10910:tid 10910] [client 34.177.99.251:40694] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at ARGS:path. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||www.wickedworks.net|F|2"] [data "Matched Data: proc/self/environ found within ARGS:path: ../../../../proc/self/environ"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "www.wickedworks.net"] [uri "/userfiles"] [unique_id "arFI6Q6ECJtc0o7Wa453DQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-21 15:08:47
(5 hours ago)
http scanning for .env files
...
Hacking
Web App Attack
๐ฉ๐ช
pscriptos
2026-09-21 14:56:08
(6 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/appsec-vpatch
Web App Attack
๐ฉ๐ช
Bedios GmbH
2026-09-21 14:35:28
(6 hours ago)
Keyfile theft attempt
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-21 14:32:38
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.177.99.251 (251.99.177.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.177.99.251 (251.99.177.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 10:32:33.770112 2026] [security2:error] [pid 3528:tid 3528] [client 34.177.99.251:46876] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.artglass-jerusalem.net"] [uri "/__vite_rsc_findSourceMapURL"] [unique_id "arFAAd6A2exXhk2SkOgauQAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
updown.io
2026-09-21 14:21:58
(6 hours ago)
{"level":"info","ts":1790000512.8221116,"logger":"http.log.access.log1","msg":"handled request","req ...
show more
{"level":"info","ts":1790000512.8221116,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.177.99.251","remote_port":"43202","client_ip":"34.177.99.251","proto":"HTTP/2.0","method":"GET","host":"status.solovyov.net","uri":"/firebase-config.json","headers":{"Accept-Encoding":["gzip"],"X-Middleware-Subrequest":["src/middleware:nowaf:src/middleware:src/middleware:src/middleware:src/middleware:middleware:middleware:nowaf:middleware:middleware:middleware:pages/_middleware"],"X-Nextjs-Data":["1"],"User-Agent":["Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)"],"Accept":["*/*"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"h2","server_name":"status.solovyov.net","ech":false}},"bytes_read":0,"user_id":"","duration":0.000994948,"size":0,"status":429,"resp_headers":{"Server":["Caddy"],"Alt-Svc":["h3=\":443\"; ma=2592000"],"Retry-After":["1"]}}
{"level":"info","ts":1790000512.8385403,"logger":"http.log.access.log1","msg":"h
...
show less
DDoS Attack
Web App Attack
๐ณ๐ฑ
i-turnradio.nl
2026-09-21 14:14:41
(6 hours ago)
2026-09-21 @ 16:14:32 (CET) ~ Blocked for trying to access: /api
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 14:14:03
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.177.99.251 (251.99.177.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.177.99.251 (251.99.177.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 10:13:59.691372 2026] [security2:error] [pid 32326:tid 32326] [client 34.177.99.251:57130] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "weathercarib.net"] [uri "/.env.js"] [unique_id "arE7p0bTETGSKdCDoa7GLQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack