๐บ๐ธ
TPI-Abuse
2026-10-09 09:27:27
(10 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.47.35.142 (142.35.47.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.47.35.142 (142.35.47.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 05:27:20.959433 2026] [security2:error] [pid 22846:tid 22846] [client 34.47.35.142:47744] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||account.robtown.com|F|2"] [data ".robtown.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "account.robtown.com"] [uri "/z9x8c7v6b5-debug-trigger-account.robtown.com"] [unique_id "asizePtlOZKH_81UEyfXWAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-09 09:07:02
(10 hours ago)
Automated web scanner. Requested suspicious paths: /.vite/manifest.json. UTC: 2026-10-09 08:26:18.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 08:22:24
(11 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.47.35.142 (142.35.47.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.47.35.142 (142.35.47.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 04:22:18.277522 2026] [security2:error] [pid 25322:tid 25322] [client 34.47.35.142:50598] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||systemcapacityoptimization.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "systemcapacityoptimization.com"] [uri "/z9x8c7v6b5-debug-trigger-systemcapacityoptimization.com"] [unique_id "asikOufOgP0bx1R1bE3emgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
EGP Abuse Dept
2026-10-09 08:15:32
(11 hours ago)
Scanning for web/db/file exploits on sjaloomzorg.nl
SQL Injection
Bad Web Bot
Web App Attack
Anonymous
2026-10-09 08:08:34
(11 hours ago)
Blocked by fail2ban on a public web server.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 07:13:05
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.47.35.142 (142.35.47.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.47.35.142 (142.35.47.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 03:13:01.390474 2026] [security2:error] [pid 11611:tid 11611] [client 34.47.35.142:41836] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "millergrain.com"] [uri "/assets../.env"] [unique_id "asiT_XGySrdU7omUo65iKAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Lino Project
2026-10-09 07:00:44
(12 hours ago)
34.47.35.142 - - [09/Oct/2026:09:00:42 +0200] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f ...
show more
34.47.35.142 - - [09/Oct/2026:09:00:42 +0200] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f.env HTTP/2.0" 404 224 "-" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/)"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Petros Stefanakis
2026-10-09 06:46:38
(13 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.47.35.142 (CA/Canada/142.35.47.34.bc ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.47.35.142 (CA/Canada/142.35.47.34.bc.googleusercontent.com)
show less
SQL Injection
๐ฉ๐ช
altenglaner
2026-10-09 06:45:22
(13 hours ago)
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show more
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
Hacking
Web App Attack
Anonymous
2026-10-09 06:40:43
(13 hours ago)
Fail2Ban apache-noscript
Bad Web Bot
๐ฌ๐ง
consul.to
2026-10-09 06:38:15
(13 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 06:20:20
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.47.35.142 (142.35.47.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.47.35.142 (142.35.47.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 02:20:15.966158 2026] [security2:error] [pid 10621:tid 10621] [client 34.47.35.142:38306] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "miles2go.net"] [uri "/media../.env"] [unique_id "asiHn9kbMW3e86KBJ8Z7yAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
srebrakowski.com
2026-10-09 05:32:57
(14 hours ago)
crowdsec/waf-detected-exploits
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-10-09 05:20:23
(14 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.47.35.142 (142.35.47.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.47.35.142 (142.35.47.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 01:20:17.414862 2026] [security2:error] [pid 32200:tid 32200] [client 34.47.35.142:47028] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mikewakimphotos.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mikewakimphotos.com"] [uri "/z9x8c7v6b5-debug-trigger-mikewakimphotos.com"] [unique_id "ash5kTkNRhb7961soB7CPAAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
openstrike.co.uk
2026-10-09 05:15:41
(14 hours ago)
147 attacks on config grabbing URLs (type 2), VC URLs, directory traversals, PHP URLs, env grabbing ...
show more
147 attacks on config grabbing URLs (type 2), VC URLs, directory traversals, PHP URLs, env grabbing URLs, shell probes, password/key grabbing URLs, env grabbing URLs (type 2):
GET /secrets.yml HTTP/1.1
GET /.git/HEAD HTTP/1.1
GET /..%2f..%2f.env HTTP/1.1
POST /index.php?-d+allow_url_include%3don+-d+auto_prepend_file%3dphp://input HTTP/1.1
GET /.env.js HTTP/1.1
POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1
GET /.git-credentials HTTP/1.1
GET /userfiles/x?path=../../../../proc/self/environ HTTP/1.1
show less
Hacking
Web App Attack