๐บ๐ธ
TPI-Abuse
2026-09-14 01:00:13
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.41.250.143 (143.250.41.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.41.250.143 (143.250.41.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 21:00:08.471770 2026] [security2:error] [pid 15212:tid 15212] [client 34.41.250.143:45430] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.rodamundo.blog"] [uri "/.env"] [unique_id "aqdHGGIbHBBjtPh4SwCKYgAAAJM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-13 18:54:38
(5 days ago)
Aggressive web scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-13 15:59:45
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.41.250.143 (143.250.41.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.41.250.143 (143.250.41.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 11:59:39.645552 2026] [security2:error] [pid 17880:tid 17880] [client 34.41.250.143:43426] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.general.graphics"] [uri "/.env.js"] [unique_id "aqbIa57S35kdjmMz1q6fgwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-09-13 07:38:44
(5 days ago)
533 requests with url.path *.env
Brute-Force
Bad Web Bot
๐ช๐ธ
pipeline.es
2026-09-13 06:08:29
(6 days ago)
Web scanning / probing for vulnerable paths | URL: /api/4/config | Evidence: morgana.travel 34.41.25 ...
show more
Web scanning / probing for vulnerable paths | URL: /api/4/config | Evidence: morgana.travel 34.41.250.143 - - [13/Sep/2026:08:08:02 +0200] \"GET /api/4/config HTTP/1.1\" 404 210 \"-\" \"Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)\" GEOIP_COUNTRY_CODE=US | ASN: GOOGLE-CLOUD-PLATFORM | Country: US
show less
Port Scan
Web App Attack
๐ฌ๐ง
consul.to
2026-09-13 04:48:13
(6 days ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
kbeezie
2026-09-11 18:32:34
(1 week ago)
34.41.250.143 - - [11/Sep/2026:14:32:34 -0400] "GET /id_ed25519 HTTP/1.1" 429 162 "-" "CCBot/2.0 (ht ...
show more
34.41.250.143 - - [11/Sep/2026:14:32:34 -0400] "GET /id_ed25519 HTTP/1.1" 429 162 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)"
34.41.250.143 - - [11/Sep/2026:14:32:34 -0400] "GET /id_dsa HTTP/1.1" 429 162 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)"
34.41.250.143 - - [11/Sep/2026:14:32:34 -0400] "GET /server.key HTTP/1.1" 429 162 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ChatGPT-User/1.0; +https://openai.com/bot)"
34.41.250.143 - - [11/Sep/2026:14:32:34 -0400] "GET /key.pem HTTP/1.1" 429 162 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)"
34.41.250.143 - - [11/Sep/2026:14:32:34 -0400] "GET /privatekey.key HTTP/1.1" 429 162 "-" "Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)"
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
kosada.com
2026-09-11 18:31:19
(1 week ago)
Repeated exploit attempts, for example: /v1/graphql {x22queryx22:x22{ __schema { types { name fields ...
show more
Repeated exploit attempts, for example: /v1/graphql {x22queryx22:x22{ __schema { types { name fields { name args { name defaultValue } } } } }x22} (HTTP/1.1 port 443, user agent: "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36")
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-11 18:16:10
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 34.41.250.143 (143.250.41.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.41.250.143 (143.250.41.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 14:16:03.362173 2026] [security2:error] [pid 14181:tid 14181] [client 34.41.250.143:39644] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||sterlingandtime.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "sterlingandtime.com"] [uri "/z9x8c7v6b5-debug-trigger-sterlingandtime.com"] [unique_id "aqRFY1b9tvZcqH_N9up8DgAAAC4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-11 18:11:29
(1 week ago)
Banned by Fail2Ban on server
Web App Attack
Anonymous
2026-09-11 18:11:12
(1 week ago)
34.41.250.143 - - [11/Sep/2026:20:11:11 +0200] "GET / HTTP/1.1" 403 12583 "-" "Mozilla/5.0 (Windows ...
show more
34.41.250.143 - - [11/Sep/2026:20:11:11 +0200] "GET / HTTP/1.1" 403 12583 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36 Edg/151.0.0.0"
34.41.250.143 - - [11/Sep/2026:20:11:11 +0200] "GET /z9x8c7v6b5-debug-trigger-stepsinlight.com HTTP/1.1" 403 153 "-" "Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)"
34.41.250.143 - - [11/Sep/2026:20:11:11 +0200] "GET /@fs/home/ec2-user/.aws/credentials?raw?? HTTP/1.1" 403 12583 "-" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)"
34.41.250.143 - - [11/Sep/2026:20:11:11 +0200] "GET /@fs/home/ubuntu/.aws/credentials?raw?? HTTP/1.1" 403 153 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )"
34.41.250.143 - - [11/Sep/2026:20:11:11 +0200] "GET /@fs/var/task/.env?raw?? HTTP/1.1" 403 12583 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)"
34.41.250.143 - - [11/Sep/2026:20:11:11 +0200] "GET
...
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-11 17:56:05
(1 week ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-cve-2021-41773
Web App Attack
Hacking
๐ฉ๐ช
konseptit
2026-09-11 17:42:47
(1 week ago)
(mod_security) mod_security triggered on hostname [redacted] 34.41.250.143 (US/United States/143.250 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.41.250.143 (US/United States/143.250.41.34.bc.googleusercontent.com)
show less
SQL Injection
๐ฎ๐น
ciccio diddo
2026-09-11 17:33:33
(1 week ago)
High Burst multiple 40X port:Tcp/80,443
Brute-Force
Web App Attack
Anonymous
2026-09-11 17:30:03
(1 week ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection