๐ณ๐ฑ
Site.eu
2026-10-01 18:52:00
(2 days ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-10-01 18:19:34
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.185.185.218 (218.185.185.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.185.185.218 (218.185.185.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 14:19:30.334260 2026] [security2:error] [pid 18054:tid 18054] [client 34.185.185.218:55886] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.acquivest.net"] [uri "/@fs/src/.env"] [unique_id "ar6kMst-ECdNseZy4g1MqgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
masterguru
2026-10-01 17:57:13
(2 days ago)
BAD BOT - Detected and Blocked.. Matched phrase "claudebot" at REQUEST_HEADERS:user-agent. (1100000- ...
show more
BAD BOT - Detected and Blocked.. Matched phrase "claudebot" at REQUEST_HEADERS:user-agent. (1100000-122)
show less
Bad Web Bot
๐ซ๐ท
Catalin Negru
2026-10-01 17:18:42
(2 days ago)
Recidive ban by fail2ban on server.blackbit.ro
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-10-01 16:02:09
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.185.185.218 (218.185.185.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.185.185.218 (218.185.185.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 12:02:03.233635 2026] [security2:error] [pid 23610:tid 23682] [client 34.185.185.218:33018] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.104ventures.com|F|2"] [data ".104ventures.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.104ventures.com"] [uri "/z9x8c7v6b5-debug-trigger-www.104ventures.com"] [unique_id "ar6D--hP6B2qjKbQftfYlwAAAUw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-10-01 15:38:52
(2 days ago)
excessive HTTP 404 errors
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-01 15:31:23
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.185.185.218 (218.185.185.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.185.185.218 (218.185.185.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 11:31:16.822161 2026] [security2:error] [pid 20136:tid 20136] [client 34.185.185.218:46884] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.adamscott.us"] [uri "/.htpasswd"] [unique_id "ar58xG38UWIOIeVxO4QoogAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-10-01 15:01:20
(2 days ago)
[ThuOct0117:01:16.9679402026][security2:error][pid1106912:tid1106967][client34.185.185.218:0]ModSecu ...
show more
[ThuOct0117:01:16.9679402026][security2:error][pid1106912:tid1106967][client34.185.185.218:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"cpcalendars.admin-services.ch\"][uri\"/.htpasswd\"][unique_id\"ar51vEVm148tK410uXqYUwAAAEY\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 14:27:18
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.185.185.218 (218.185.185.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.185.185.218 (218.185.185.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 10:27:13.032117 2026] [security2:error] [pid 2788:tid 2788] [client 34.185.185.218:43710] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.1writeforthegrant.com"] [uri "/core/.env"] [unique_id "ar5twXc6GFKg175OsG-bdgAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 14:07:57
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.185.185.218 (218.185.185.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.185.185.218 (218.185.185.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 10:07:51.819691 2026] [security2:error] [pid 19031:tid 19031] [client 34.185.185.218:57148] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.13waggoners.com|F|2"] [data ".13waggoners.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.13waggoners.com"] [uri "/z9x8c7v6b5-debug-trigger-www.13waggoners.com"] [unique_id "ar5pN2CDj9m_MxoO4MSe9AAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-01 12:05:36
(2 days ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
๐ฟ๐ฆ
conure.sh
2026-10-01 11:55:10
(2 days ago)
csagent: score 18.2: 404 noise floor x33, secrets grab x1; 1 domain(s) in 1s
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 11:18:20
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.185.185.218 (218.185.185.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.185.185.218 (218.185.185.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 07:18:12.721602 2026] [security2:error] [pid 23194:tid 23194] [client 34.185.185.218:45224] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.1954topresent.com"] [uri "/api/.env/public/.env"] [unique_id "ar5BdEDH59_X1v2pnlXpoAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 10:22:51
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.185.185.218 (218.185.185.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.185.185.218 (218.185.185.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 06:22:47.426474 2026] [security2:error] [pid 10226:tid 10226] [client 34.185.185.218:55876] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "achari.com"] [uri "/__vite_rsc_findSourceMapURL"] [unique_id "ar40dxbVEY8OQja71Q7KwAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-10-01 10:04:02
(2 days ago)
[ThuOct0112:03:56.5749142026][security2:error][pid3481489:tid3481656][client34.185.185.218:0]ModSecu ...
show more
[ThuOct0112:03:56.5749142026][security2:error][pid3481489:tid3481656][client34.185.185.218:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"710\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"cpcalendars.aidconsultancy.ch\"][uri\"/config/env/aws_credentials.env\"][unique_id\"ar4wDCxK9sM05NbgV7rIYAAAAQc\"]
show less
Hacking
Web App Attack