๐บ๐ธ
TPI-Abuse
2026-09-22 15:48:38
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.21.187.211 (211.187.21.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.21.187.211 (211.187.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 11:48:31.987184 2026] [security2:error] [pid 5917:tid 5917] [client 34.21.187.211:50178] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "deargrampy.net"] [uri "/.env"] [unique_id "arKjT0zUeENWF3NmUIP7dAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-22 15:39:40
(1 hour ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
pixiekat
2026-09-22 15:33:23
(1 hour ago)
Banned by fail2ban (apache-modsecurity, 3 hits) [msg "Inbound Anomaly Score Exceeded (Total Score: 5 ...
show more
Banned by fail2ban (apache-modsecurity, 3 hits) [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [msg "Next.js Server Action probe blocked (no Next.js apps on this server)"]
show less
Web App Attack
Anonymous
2026-09-22 15:20:06
(2 hours ago)
| [Dangerous/Singapore] Aggressive IP 34.21.187.211 (~30 hits). Type: DoS Defender- Web server 400 e ...
show more
| [Dangerous/Singapore] Aggressive IP 34.21.187.211 (~30 hits). Type: DoS Defender- Web server 400 error code
show less
Web App Attack
Hacking
SQL Injection
๐ช๐ธ
robotstxt
2026-09-22 14:49:04
(2 hours ago)
34.21.187.211 - - [22/Sep/2026:14:48:11 +0000] "GET /wp-content/cache/autoptimize/js/autoptimize_2e5 ...
show more
34.21.187.211 - - [22/Sep/2026:14:48:11 +0000] "GET /wp-content/cache/autoptimize/js/autoptimize_2e5954a14bf7a8996a876a5327610b48.js HTTP/2.0" 403 165 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "-" edge="34.21.187.211"
34.21.187.211 - - [22/Sep/2026:14:48:11 +0000] "GET /wp-includes/js/dist/hooks.min.js?ver=f0f188028580e8dc1255 HTTP/2.0" 403 13106 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "-" edge="34.21.187.211"
34.21.187.211 - - [22/Sep/2026:14:48:11 +0000] "GET /wp-includes/js/dist/i18n.min.js?ver=1dfe7db3940c23ea9216 HTTP/2.0" 403 13106 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "-" edge="34.21.187.211"
34.21.187.211 - - [22/Sep/2026:14:48:11 +0000] "GET /?8b5ae9=16e37b7710.js& HTTP/2.0" 403 2 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 14:37:23
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.21.187.211 (211.187.21.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.21.187.211 (211.187.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 10:37:16.756487 2026] [security2:error] [pid 26869:tid 26869] [client 34.21.187.211:41382] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "eboredom.net"] [uri "/.htpasswd"] [unique_id "arKSnJ9WqTM8j0EGRr_qiAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-22 14:33:13
(2 hours ago)
34.21.187.211 - - [22/Sep/2026:22:33:12 +0800] "GET /webpack-stats.json HTTP/1.1" 404 196 "-" "Mozil ...
show more
34.21.187.211 - - [22/Sep/2026:22:33:12 +0800] "GET /webpack-stats.json HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 Edg/153.0.0.0"
34.21.187.211 - - [22/Sep/2026:22:33:12 +0800] "GET /asset-manifest.json HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 Edg/153.0.0.0"
34.21.187.211 - - [22/Sep/2026:22:33:12 +0800] "GET /assets/manifest.json HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 Edg/153.0.0.0"
34.21.187.211 - - [22/Sep/2026:22:33:12 +0800] "GET /static/manifest.json HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 Edg/153.0.0.0"
34.21.187.211 - - [22/Sep/2026:22:33:12 +0800] "GET /manifest.json HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Wind
...
show less
Bad Web Bot
Web App Attack
๐ช๐ธ
el-brujo
2026-09-22 14:18:51
(3 hours ago)
34.21.187.211 - - [22/Sep/2026:16:18:49 +0200] "GET /98cm2gv0uhiy8kpjjw8d HTTP/2.0" 404 15828 "-" "M ...
show more
34.21.187.211 - - [22/Sep/2026:16:18:49 +0200] "GET /98cm2gv0uhiy8kpjjw8d HTTP/2.0" 404 15828 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )"
34.21.187.211 - - [22/Sep/2026:16:18:50 +0200] "GET /dist/.vite/manifest.json HTTP/2.0" 404 15828 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 Edg/153.0.0.0"
34.21.187.211 - - [22/Sep/2026:16:18:50 +0200] "GET /dist/manifest.json HTTP/2.0" 404 15828 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 Edg/153.0.0.0"
34.21.187.211 - - [22/Sep/2026:16:18:50 +0200] "GET /z9x8c7v6b5-debug-trigger-elhacker.net HTTP/2.0" 404 15828 "-" "Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)"
...
show less
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-22 14:16:10
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.21.187.211 (211.187.21.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.21.187.211 (211.187.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 10:16:07.212626 2026] [security2:error] [pid 13719:tid 13845] [client 34.21.187.211:47562] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ellicottville.net"] [uri "/app/.env"] [unique_id "arKNpycExj3DI8hY61HqDQAAAlU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
findlab
2026-09-22 14:00:02
(3 hours ago)
Backdrop CMS module - malicious activity detected
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 13:52:05
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.21.187.211 (211.187.21.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.21.187.211 (211.187.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 09:51:58.315433 2026] [security2:error] [pid 8255:tid 8255] [client 34.21.187.211:34974] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "essav.net"] [uri "/.env.production"] [unique_id "arKH_h57Vg2QSHjEaroNXQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
bescared
2026-09-22 13:29:00
(3 hours ago)
WAF (2) - Malicious activity detected: URL probing.
Bad Web Bot
Web App Attack
Hacking
๐ณ๐ฑ
debestelapp
2026-09-22 13:20:11
(4 hours ago)
Web App Attack
๐ฟ๐ฆ
vanderhost
2026-09-22 13:04:54
(4 hours ago)
[Laravel HoneypotPlus] Automated report - Honeypot access detected on path: /config/gcp-credentials. ...
show more
[Laravel HoneypotPlus] Automated report - Honeypot access detected on path: /config/gcp-credentials.json via rule: /config
show less
Web App Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-22 13:00:29
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.21.187.211 (211.187.21.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.21.187.211 (211.187.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 09:00:26.076510 2026] [security2:error] [pid 711242:tid 711242] [client 34.21.187.211:33328] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fixitz.net"] [uri "/.env.old"] [unique_id "arJ76m4GDiPmYo2JJTh57QAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack