🇫🇷
dynamix
2026-09-12 17:49:52
(33 minutes ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-09-12 17:12:49
(1 hour ago)
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: US, Attack patterns: Word ...
show more
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: US, Attack patterns: WordPress scanning, Backup file probing, Cloud secrets probing
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 05:53:22
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.24.6.60 (60.6.24.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.24.6.60 (60.6.24.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 01:53:16.201554 2026] [security2:error] [pid 21204:tid 21204] [client 34.24.6.60:49754] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.rayeliotschwartz.com"] [uri "/@fs/.env"] [unique_id "aqTozPcAtxwbkvoT1smbYQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
rsa
2026-09-11 20:23:00
(21 hours ago)
GET /public/plugins/text/../../../../../../../../proc/self/envi
DDoS Attack
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 17:51:12
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.24.6.60 (60.6.24.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.24.6.60 (60.6.24.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 13:51:06.971088 2026] [security2:error] [pid 1536:tid 1536] [client 34.24.6.60:37238] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "realjasonchance.com"] [uri "/.htpasswd"] [unique_id "aqQ_iuL3jo10P0vCDIR6hgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
IndigoRidge
2026-09-11 17:40:11
(1 day ago)
34.24.6.60 - - [11/Sep/2026:13:40:10 -0400] "GET /images../.env HTTP/1.1" 403 4995 "-" "Mozilla/5.0 ...
show more
34.24.6.60 - - [11/Sep/2026:13:40:10 -0400] "GET /images../.env HTTP/1.1" 403 4995 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)"
34.24.6.60 - - [11/Sep/2026:13:40:10 -0400] "GET /uploads../.env HTTP/1.1" 403 5790 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36"
34.24.6.60 - - [11/Sep/2026:13:40:10 -0400] "GET /assets../.env HTTP/1.1" 403 5790 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)"
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 17:29:24
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.24.6.60 (60.6.24.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210730) triggered by 34.24.6.60 (60.6.24.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 13:29:17.441942 2026] [security2:error] [pid 30261:tid 30261] [client 34.24.6.60:35050] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||realdesigninterior.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "realdesigninterior.com"] [uri "/rclone.conf"] [unique_id "aqQ6bXQilRe8z8RenL-eJAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-11 17:28:25
(1 day ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-09-11 17:12:09
(1 day ago)
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: US, Attack patterns: Word ...
show more
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: US, Attack patterns: WordPress scanning, Backup file probing, Cloud secrets probing
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-11 17:02:40
(1 day ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 16:47:33
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.24.6.60 (60.6.24.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210730) triggered by 34.24.6.60 (60.6.24.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 12:47:28.844911 2026] [security2:error] [pid 22932:tid 22932] [client 34.24.6.60:35318] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||rdsparts.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "rdsparts.com"] [uri "/z9x8c7v6b5-debug-trigger-rdsparts.com"] [unique_id "aqQwoLHSI4zxybKw13MFmQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-11 16:46:54
(1 day ago)
Excessive 404/403 errors
Brute-Force
🇮🇹
VHosting
2026-09-11 16:45:04
(1 day ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 16:29:31
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.24.6.60 (60.6.24.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210730) triggered by 34.24.6.60 (60.6.24.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 12:29:25.073430 2026] [security2:error] [pid 7093:tid 7093] [client 34.24.6.60:51696] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||rcjav.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "rcjav.com"] [uri "/rclone.conf"] [unique_id "aqQsZUvXtFNH4XsrriyBMwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-11 16:06:21
(1 day ago)
34.24.6.60 - - [11/Sep/2026:11:03:17 -0500] "GET /.env?import&url&inline HTTP/1.1" 301 291 "-" "Mozi ...
show more
34.24.6.60 - - [11/Sep/2026:11:03:17 -0500] "GET /.env?import&url&inline HTTP/1.1" 301 291 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)" 172.71.31.157
34.24.6.60 - - [11/Sep/2026:11:03:17 -0500] "GET /.env.local?import&raw HTTP/1.1" 301 286 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)" 172.69.71.15
34.24.6.60 - - [11/Sep/2026:11:03:18 -0500] "GET /.env.development?import&raw HTTP/1.1" 301 292 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)" 104.23.245.51
34.24.6.60 - - [11/Sep/2026:11:03:18 -0500] "GET /.env.production?import&raw HTTP/1.1" 301 291 "-" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)" 172.71.31.157
34.24.6.60 - - [11/Sep/2026:11:03:18 -0500] "GET /.env.development?raw HTTP/1.1" 301 281 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)" 172.71.22.166
34.24.6.60 - - [11/Sep/2026:11:03:18 -0500] "GET /.env.js HTTP/1.1" 301 268
...
show less
Brute-Force
Bad Web Bot
Web App Attack