🇺🇸
TPI-Abuse
2026-09-11 02:47:01
(30 minutes ago)
(mod_security) mod_security (id:210730) triggered by 34.182.229.85 (85.229.182.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.182.229.85 (85.229.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 22:46:55.394839 2026] [security2:error] [pid 12798:tid 12798] [client 34.182.229.85:38170] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kln.ne.jp|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kln.ne.jp"] [uri "/rclone.conf"] [unique_id "aqNrn88IuLLmoC03KOTy2QAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇾
lns.bz
2026-09-11 02:12:40
(1 hour ago)
Too many 404 requests [BY]
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 01:53:42
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 34.182.229.85 (85.229.182.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.182.229.85 (85.229.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 21:53:35.588281 2026] [security2:error] [pid 1434:tid 1434] [client 34.182.229.85:52592] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ictsl.net|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ictsl.net"] [uri "/ssl/server.key"] [unique_id "aqNfH5Eaz1H4ek82HXCMzQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
paissangroup
2026-09-11 01:44:10
(1 hour ago)
Multiple WAF Violations
Web App Attack
🇺🇸
H24
2026-09-11 01:42:55
(1 hour ago)
/@fs/var/task/.env /static//app/.env /.//.env /media../.env /files../.env /images../.env /static//.e ...
show more
/@fs/var/task/.env /static//app/.env /.//.env /media../.env /files../.env /images../.env /static//.env /@fs/home/ubuntu/.aws/credentials /api/.env/public/.env /@fs/root/.aws/credentials
show less
Web App Attack
🇳🇱
debestelapp
2026-09-11 01:35:14
(1 hour ago)
Web App Attack
🇺🇸
mnsf
2026-09-11 01:05:30
(2 hours ago)
Scanning/Probing (15)
Brute-Force
Web App Attack
🇸🇪
vaia.cloud
2026-09-11 00:40:03
(2 hours ago)
crowdsecurity/http-cve-2021-41773
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 00:29:07
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.182.229.85 (85.229.182.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.182.229.85 (85.229.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 20:29:00.084408 2026] [security2:error] [pid 11803:tid 11803] [client 34.182.229.85:60354] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||flavornet.org|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "flavornet.org"] [uri "/rclone.conf"] [unique_id "aqNLTAVxFSfX8qapqK8qxwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
MusicLibrary
2026-09-11 00:24:19
(2 hours ago)
Attempted access to sensitive configuration files (.env, .git, etc.)
Bad Web Bot
Web App Attack
🇪🇸
elcruzado.es
2026-09-10 23:53:19
(3 hours ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 34.182.229.85 (US/Un ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 34.182.229.85 (US/United States/85.229.182.34.bc.googleusercontent.com)
show less
Bad Web Bot
🇪🇸
el-brujo
2026-09-10 23:51:28
(3 hours ago)
34.182.229.85 - - [11/Sep/2026:01:51:28 +0200] "GET /privatekey.key HTTP/2.0" 404 15911 "-" "Mozilla ...
show more
34.182.229.85 - - [11/Sep/2026:01:51:28 +0200] "GET /privatekey.key HTTP/2.0" 404 15911 "-" "Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)"
34.182.229.85 - - [11/Sep/2026:01:51:28 +0200] "GET /key.pem HTTP/2.0" 404 15911 "-" "Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)"
34.182.229.85 - - [11/Sep/2026:01:51:28 +0200] "GET /server.key HTTP/2.0" 404 15911 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)"
34.182.229.85 - - [11/Sep/2026:01:51:28 +0200] "GET /rclone.conf HTTP/2.0" 404 15911 "-" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)"
...
show less
Web App Attack
Hacking
🇫🇮
Shaik Sai Meera
2026-09-10 23:50:09
(3 hours ago)
IM360 WAF: Hidden file access
Brute-Force
🇩🇪
netclix.gr
2026-09-10 23:38:58
(3 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.182.229.85 (US/United States/85.229. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.182.229.85 (US/United States/85.229.182.34.bc.googleusercontent.com): (CF_ENABLE)
show less
SQL Injection
🇫🇷
Baking333
2026-09-10 23:38:15
(3 hours ago)
[redacted] 34.182.229.85 - - [11/Sep/2026:00:38:14 +0100] "GET /.aws/config HTTP/1.1" 302 6743 0/494 ...
show more
[redacted] 34.182.229.85 - - [11/Sep/2026:00:38:14 +0100] "GET /.aws/config HTTP/1.1" 302 6743 0/49444 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://[redacted]/perplexitybot)" [redacted] 34.182.229.85 - - [11/Sep/2026:00:38:14 +0100] "GET /.aws/credentials HTTP/1.1" 302 6743 0/49444 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://[redacted]/)"
show less
Bad Web Bot
Web App Attack