🇺🇸
TPI-Abuse
2026-09-12 04:18:52
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.22.144.248 (248.144.22.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.22.144.248 (248.144.22.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 00:18:44.478605 2026] [security2:error] [pid 32222:tid 32222] [client 34.22.144.248:59018] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.noviasaltovacio.com"] [uri "/.git/config"] [unique_id "aqTSpLnCO9cOU5chSnfvLQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
rubixstudios
2026-09-12 04:11:02
(7 hours ago)
Excessive HTTP requests consistent with automated attack behaviour detected by Imunify360
DDoS Attack
Brute-Force
Web App Attack
Anonymous
2026-09-12 00:54:44
(10 hours ago)
34.22.144.248 - - [12/Sep/2026:08:54:43 +0800] "GET /manifest.json HTTP/1.1" 404 196 "-" "Mozilla/5. ...
show more
34.22.144.248 - - [12/Sep/2026:08:54:43 +0800] "GET /manifest.json HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36"
34.22.144.248 - - [12/Sep/2026:08:54:43 +0800] "GET /z9x8c7v6b5-debug-trigger-hk.nowbaogumovies.com HTTP/1.1" 404 196 "-" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)"
34.22.144.248 - - [12/Sep/2026:08:54:43 +0800] "GET /z9x8c7v6b5-debug-trigger-hk.nowbaogumovies.com HTTP/1.1" 404 196 "-" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)"
34.22.144.248 - - [12/Sep/2026:08:54:43 +0800] "GET /.aws/credentials HTTP/1.1" 404 196 "-" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)"
34.22.144.248 - - [12/Sep/2026:08:54:43 +0800] "GET /.aws/config HTTP/1.1" 404 196 "-" "Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)"
34.22.144.248 - - [12/Sep/2026:08:54:43 +0800] "GET /.aws/credentials HTTP/1.1" 404 196 "-" "Mozilla/5.0 (com
...
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 17:55:22
(17 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.22.144.248 (248.144.22.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.22.144.248 (248.144.22.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 13:55:17.663752 2026] [security2:error] [pid 4080:tid 4080] [client 34.22.144.248:34204] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||npcsouthernclassic.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "npcsouthernclassic.com"] [uri "/z9x8c7v6b5-debug-trigger-npcsouthernclassic.com"] [unique_id "aqRAhZv0jN2CBqaE0GQkCAAAAC0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-11 17:51:53
(17 hours ago)
Excessive 404/403 errors
Brute-Force
Anonymous
2026-09-11 17:43:45
(17 hours ago)
34.22.144.248 - - [12/Sep/2026:01:43:44 +0800] "GET /assets/manifest.json HTTP/1.1" 404 196 "-" "Moz ...
show more
34.22.144.248 - - [12/Sep/2026:01:43:44 +0800] "GET /assets/manifest.json HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Mobile Safari/537.36"
34.22.144.248 - - [12/Sep/2026:01:43:44 +0800] "GET /host.key HTTP/1.1" 404 196 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)"
34.22.144.248 - - [12/Sep/2026:01:43:44 +0800] "GET /rclone.conf HTTP/1.1" 404 196 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.3; +https://openai.com/gptbot)"
34.22.144.248 - - [12/Sep/2026:01:43:44 +0800] "GET /manifest.json HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Mobile Safari/537.36"
34.22.144.248 - - [12/Sep/2026:01:43:44 +0800] "GET /private-key HTTP/1.1" 404 196 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
34.22.144.248 - - [12/Sep/2026:0
...
show less
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-09-11 17:30:04
(18 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇨🇿
ddw
2026-09-11 17:19:09
(18 hours ago)
Multiple ModSecurity detections - Rules: 920440(URL file extension is restricted by policy), 920450( ...
show more
Multiple ModSecurity detections - Rules: 920440(URL file extension is restricted by policy), 920450(HTTP header is restricted by policy (/x-middleware-subrequest/)), 920450(HTTP header is restricted by policy (/x-middleware-subrequest/)), 930130(Restricted File Access Attempt)
show less
Web App Attack
🇫🇷
dynamix
2026-09-11 16:54:58
(18 hours ago)
Multiple WAF Violations
Web App Attack
🇺🇸
interbiznw.com
2026-09-11 16:54:38
(18 hours ago)
fail2ban-ban
Hacking
Brute-Force
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 16:42:58
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.22.144.248 (248.144.22.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.22.144.248 (248.144.22.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 12:42:53.482127 2026] [security2:error] [pid 18538:tid 18538] [client 34.22.144.248:49908] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "notepromd.com"] [uri "/%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env"] [unique_id "aqQvjY8SbqoXV1Ft_MQIzgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-11 16:28:36
(19 hours ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-196)
Hacking
Web App Attack
🇩🇪
konseptit
2026-09-11 16:23:39
(19 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.22.144.248 (BE/Belgium/248.144.22.34 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.22.144.248 (BE/Belgium/248.144.22.34.bc.googleusercontent.com)
show less
SQL Injection
🇳🇴
jad-abuse
2026-09-11 16:15:02
(19 hours ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe, credential_file, dotfile_probe, ssh_keys, path_traversal, aws_creds, source_backup, config_backup. Observed by 1 sensor(s); 180 hits.
show less
Web App Attack
🇺🇸
mnsf
2026-09-11 16:06:11
(19 hours ago)
Too many Status 40X (12)
Brute-Force
Web App Attack