🇺🇸
TPI-Abuse
2026-09-15 14:13:32
(4 minutes ago)
(mod_security) mod_security (id:210350) triggered by 34.42.39.59 (59.39.42.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210350) triggered by 34.42.39.59 (59.39.42.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 10:13:28.236213 2026] [security2:error] [pid 4702:tid 4793] [client 34.42.39.59:63136] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.surdick.com.faimreps.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.surdick.com.faimreps.com"] [uri "/application_default_credentials.json"] [unique_id "aqlSiJShTdG5MG5ZksfySAAAAQc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-15 13:29:36
(48 minutes ago)
(mod_security) mod_security (id:210350) triggered by 34.42.39.59 (59.39.42.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210350) triggered by 34.42.39.59 (59.39.42.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 09:29:28.240653 2026] [security2:error] [pid 29957:tid 29957] [client 34.42.39.59:46696] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||topografiazgs.com.disenowebprofesional.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "topografiazgs.com.disenowebprofesional.com"] [uri "/application_default_credentials.json"] [unique_id "aqlIOArxjaH1e2hXaaWEOwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-15 12:35:15
(1 hour ago)
(mod_security) mod_security (id:210350) triggered by 34.42.39.59 (59.39.42.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210350) triggered by 34.42.39.59 (59.39.42.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 08:35:07.150449 2026] [security2:error] [pid 22981:tid 22981] [client 34.42.39.59:51350] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||mail.northfortworthalliance.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "mail.northfortworthalliance.com"] [uri "/application_default_credentials.json"] [unique_id "aqk7exmqvUudN0lB9KcZ9wAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-15 12:32:27
(1 hour ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /application_default_credentials.json | 2026-09-15 12:32 UTC
show less
Hacking
Web App Attack
🇫🇷
lindi
2026-09-15 11:40:15
(2 hours ago)
Probing for resource vulnerabilities
...
Web Spam
Brute-Force
Bad Web Bot
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-15 11:37:51
(2 hours ago)
(mod_security) mod_security (id:210350) triggered by 34.42.39.59 (59.39.42.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210350) triggered by 34.42.39.59 (59.39.42.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 07:37:44.829195 2026] [security2:error] [pid 28218:tid 28218] [client 34.42.39.59:17166] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||groupof12.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "groupof12.com"] [uri "/application_default_credentials.json"] [unique_id "aqkuCM-NjF3GA-Sm51_bagAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-15 10:52:10
(3 hours ago)
(mod_security) mod_security (id:210350) triggered by 34.42.39.59 (59.39.42.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210350) triggered by 34.42.39.59 (59.39.42.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 06:52:04.026502 2026] [security2:error] [pid 18343:tid 18343] [client 34.42.39.59:14780] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||ulrike-petri.de|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "ulrike-petri.de"] [uri "/application_default_credentials.json"] [unique_id "aqkjVEBkym92PJjNtZp8twAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Skyrider
2026-09-15 09:25:10
(4 hours ago)
Nginx: HTTP 4xx probe/scan attempts. Automated fail2ban report.
Bad Web Bot
Web App Attack
🇳🇿
Antinson
2026-09-15 06:27:01
(7 hours ago)
Scraping with a high error ratio and request rate
Bad Web Bot
Anonymous
2026-09-15 05:56:01
(8 hours ago)
Bot / scanning and/or hacking attempts: GET /.env.local HTTP/1.1, GET /~/.aws/credentials HTTP/1.1, ...
show more
Bot / scanning and/or hacking attempts: GET /.env.local HTTP/1.1, GET /~/.aws/credentials HTTP/1.1, GET /.env.dev HTTP/1.1, GET /.env.staging HTTP/1.1, GET /.aws/credentials HTTP/1.1, GET /.env.production HTTP/1.1, GET /docker-compose.yaml HTTP/1.1
show less
Hacking
Web App Attack
🇩🇪
paissangroup
2026-09-15 05:14:39
(9 hours ago)
Multiple WAF Violations
Web App Attack
🇦🇹
Starburst SysOp Team
2026-09-15 04:54:31
(9 hours ago)
Restricted File Access Attempt. Matched phrase "credentials.json" at REQUEST_FILENAME. (930130-vie6- ...
show more
Restricted File Access Attempt. Matched phrase "credentials.json" at REQUEST_FILENAME. (930130-vie6-1)
show less
Hacking
Web App Attack
🇩🇪
Admins@FBN
2026-09-15 03:41:29
(10 hours ago)
FW-PortScan: Traffic Blocked srcport=49588 dstport=443
Port Scan
Anonymous
2026-09-15 02:15:09
(12 hours ago)
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: US, Attack patterns: Clou ...
show more
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: US, Attack patterns: Cloud secrets probing
show less
Bad Web Bot
Web App Attack
🇫🇷
Zundapper
2026-09-15 01:35:50
(12 hours ago)
34.42.39.59 - - [15/Sep/2026:03:35:42 +0200] "GET /application_default_credentials.json HTTP/1.1" 40 ...
show more
34.42.39.59 - - [15/Sep/2026:03:35:42 +0200] "GET /application_default_credentials.json HTTP/1.1" 404 178 "https://www.illustrami.com/application_default_credentials.json" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.0.0 Safari/537.36"
34.42.39.59 - - [15/Sep/2026:03:35:43 +0200] "GET /client_secret.json HTTP/1.1" 404 178 "https://www.illustrami.com/client_secret.json" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.0.0 Safari/537.36"
34.42.39.59 - - [15/Sep/2026:03:35:48 +0200] "GET /client_secret_web.json HTTP/1.1" 404 178 "https://www.illustrami.com/client_secret_web.json" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.0.0 Safari/537.36"
34.42.39.59 - - [15/Sep/2026:03:35:49 +0200] "GET /client_secret_installed.json HTTP/1.1" 404 178 "https://www.illustrami.com/client_secret_installed.json" "Mozilla/5.0 (Macintosh; Intel M
...
show less
Web App Attack
Port Scan