🇺🇸
TPI-Abuse
2026-09-07 20:41:01
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.181.144.110 (110.144.181.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.181.144.110 (110.144.181.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 16:40:54.409263 2026] [security2:error] [pid 32286:tid 32286] [client 34.181.144.110:34782] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.advantageinvestigation.com"] [uri "/@fs/app/.env"] [unique_id "ap8hVuwjiJik_sz3pWeJwwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Savvii
2026-09-07 20:15:54
(3 hours ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FeG Deutschland
2026-09-07 20:01:13
(3 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 12
Exploited Host
Web App Attack
🇫🇷
Octopuce
2026-09-07 19:36:21
(3 hours ago)
Aggressive web search of vulnerable pages: /.docker/.env /uploads../.env /img../.env /images../.env ...
show more
Aggressive web search of vulnerable pages: /.docker/.env /uploads../.env /img../.env /images../.env /_nuxt/../.env ...
show less
Web App Attack
🇧🇪
cmbplf
2026-09-07 18:58:38
(4 hours ago)
569 requests with url.path *.azure/*
142 requests with url.path */auth.json
Brute-Force
Bad Web Bot
🇫🇷
dynamix
2026-09-07 18:49:53
(4 hours ago)
Multiple WAF Violations
Web App Attack
🇩🇪
maxpower
2026-09-07 18:46:47
(4 hours ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.181.144.110 (US/United States/110.144 ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.181.144.110 (US/United States/110.144.181.34.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.181.144.110 - - [07/Sep/2026:20:46:46 +0200] "GET /@fs/root/.aws/credentials?raw?? HTTP/1.1" 200 11924 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.4663.181 Safari/537.36; compatible; Claude-User/1.0; +https://www.anthropic.com/claude-user" "-" host=mail.samitecnopetrol.it
show less
Port Scan
🇩🇪
s@ch@
2026-09-07 18:30:02
(4 hours ago)
Jail: plesk-modsecurity | Web application attack (Plesk ModSecurity)
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 18:13:20
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.181.144.110 (110.144.181.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.181.144.110 (110.144.181.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 14:13:15.373376 2026] [security2:error] [pid 861067:tid 861074] [client 34.181.144.110:34642] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "eagletons.com"] [uri "/@fs/../.env"] [unique_id "ap7-u_auu5gs53CK6bwU2AAAAIU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-07 18:10:16
(5 hours ago)
Excessive 404/403 errors
Brute-Force
🇮🇹
VHosting
2026-09-07 18:05:03
(5 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇺🇸
Charlesiv
2026-09-07 18:01:26
(5 hours ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Pro ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/1.1 (GET method)
Endpoint: /__debug__/
Timestamp: 2026-09-07T17:39:30Z
Ray ID: a3777e42a8dd386e
UA: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Bytespider; +https://zhanzhang.toutiao.com/)
show less
Bad Web Bot
🇩🇪
Bedios GmbH
2026-09-07 17:47:16
(5 hours ago)
Login credentials theft attempt
Hacking
🇺🇸
TPI-Abuse
2026-09-07 17:23:57
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.181.144.110 (110.144.181.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.181.144.110 (110.144.181.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 13:23:49.683737 2026] [security2:error] [pid 27432:tid 27432] [client 34.181.144.110:41856] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.natursac.com"] [uri "/@fs/root/.env"] [unique_id "ap7zJQT8tz7M6chGs1psbgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 16:51:47
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.181.144.110 (110.144.181.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.181.144.110 (110.144.181.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 12:51:43.708668 2026] [security2:error] [pid 12813:tid 12813] [client 34.181.144.110:49676] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.929.us"] [uri "/@fs/.env"] [unique_id "ap7rnySF1IaM6yCv2qVKOAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack