🇺🇸
mnsf
2026-09-12 17:05:18
(1 hour ago)
Too many Status 40X (17)
Scanning/Probing (11)
Brute-Force
Web App Attack
🇧🇪
cmbplf
2026-09-12 09:09:47
(9 hours ago)
2.913 requests from abuseipdb.com blacklisted IP (10mos3w6d)
Brute-Force
Bad Web Bot
🇩🇪
maxpower
2026-09-12 09:06:16
(9 hours ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.20.136.167 (US/United States/167.136. ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.20.136.167 (US/United States/167.136.20.34.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.20.136.167 - - [12/Sep/2026:11:06:13 +0200] "GET /secrets.env HTTP/2.0" 200 4810 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)" "34.20.136.167" host=www.marialauracaselli.com
show less
Port Scan
Anonymous
2026-09-12 07:52:33
(11 hours ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
🇺🇸
TPI-Abuse
2026-09-12 07:46:00
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.20.136.167 (167.136.20.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.20.136.167 (167.136.20.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 03:45:53.579015 2026] [security2:error] [pid 11230:tid 11230] [client 34.20.136.167:44102] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.mantality.com"] [uri "/@fs/app/.env"] [unique_id "aqUDMY0AeMaFqQXi_ozf4AAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 00:56:28
(17 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.20.136.167 (167.136.20.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.20.136.167 (167.136.20.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 20:56:23.117262 2026] [security2:error] [pid 578:tid 578] [client 34.20.136.167:60066] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.manvsfoodlocations.com|F|2"] [data ".manvsfoodlocations.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.manvsfoodlocations.com"] [uri "/z9x8c7v6b5-debug-trigger-mail.manvsfoodlocations.com"] [unique_id "aqSjN04Ui4mk-zh9UT8YZQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
sdos.es
2026-09-12 00:53:59
(18 hours ago)
"Restricted File Access Attempt - Matched Data: .aws/credentials found within REQUEST_FILENAME: /@fs ...
show more
"Restricted File Access Attempt - Matched Data: .aws/credentials found within REQUEST_FILENAME: /@fs/root/.aws/credentials"
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 17:48:28
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.20.136.167 (167.136.20.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.20.136.167 (167.136.20.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 13:48:21.481522 2026] [security2:error] [pid 1657:tid 1657] [client 34.20.136.167:58402] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||marilynmather.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "marilynmather.com"] [uri "/z9x8c7v6b5-debug-trigger-marilynmather.com"] [unique_id "aqQ-5Yykr4ti1ckoPM_7HwAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-11 17:33:43
(1 day ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-11 17:30:46
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.20.136.167 (167.136.20.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.20.136.167 (167.136.20.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 13:30:40.633122 2026] [security2:error] [pid 7820:tid 7820] [client 34.20.136.167:44214] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mariakhalitov.com"] [uri "/static//.env"] [unique_id "aqQ6wIxLV4f4X5Fcb21wuQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-11 17:26:30
(1 day ago)
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encod ...
show more
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encoding/ /proxy/ /lock-token/ /content-range/ /if/ /x-http-method-override/ /x-http-method/ /x-method-override/ /x-middleware-subrequest/ /expect/" at TX:header_name_920450_x-middleware-subrequest. (920450-197)
show less
Bad Web Bot
🇵🇱
strefapi_com
2026-09-11 17:15:25
(1 day ago)
Brute-force, web
...
Hacking
Brute-Force
Web App Attack
🇺🇸
NerdyMcNerderson
2026-09-11 17:14:23
(1 day ago)
MarekCloud auto-ban: ENV leak probe: GET /@fs/.env
Bad Web Bot
Web App Attack
🇦🇺
paulshipley.com.au
2026-09-11 17:14:01
(1 day ago)
[Sat Sep 12 03:14:00.104479 2026] [security2:error] [pid 662442] [client 34.20.136.167:49826] [clien ...
show more
[Sat Sep 12 03:14:00.104479 2026] [security2:error] [pid 662442] [client 34.20.136.167:49826] [client 34.20.136.167] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "mareeshefford.com"] [uri "/z9x8c7v6b5-debug-trigger-mareeshefford.com"] [unique_id "aqQ22LFB_NnYM5O2rjWUJwAAAAM"]
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 17:12:12
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.20.136.167 (167.136.20.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.20.136.167 (167.136.20.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 13:12:06.840682 2026] [security2:error] [pid 26774:tid 26774] [client 34.20.136.167:59988] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mardensmith.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mardensmith.com"] [uri "/rclone.conf"] [unique_id "aqQ2Zot7b93DpPvNlXgG-gAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack