🇺🇸
TPI-Abuse
2026-09-11 21:55:38
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.48.44.40 (40.44.48.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.48.44.40 (40.44.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 17:55:29.563458 2026] [security2:error] [pid 15894:tid 15894] [client 34.48.44.40:59266] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.thegoldentether.com|F|2"] [data ".thegoldentether.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.thegoldentether.com"] [uri "/z9x8c7v6b5-debug-trigger-mail.thegoldentether.com"] [unique_id "aqR40TUIZfZ-ClrbGNNeeQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 16:59:22
(7 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.48.44.40 (40.44.48.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.48.44.40 (40.44.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 12:59:18.958697 2026] [security2:error] [pid 9380:tid 9380] [client 34.48.44.40:33164] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||thekingofweed.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "thekingofweed.com"] [uri "/z9x8c7v6b5-debug-trigger-thekingofweed.com"] [unique_id "aqQzZjJaQI_VjO1arAGF2AAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
lavnet.net
2026-09-11 16:52:36
(7 hours ago)
34.48.44.40 - - [11/Sep/2026:16:52:35 +0000] "GET /@fs/home/ubuntu/.aws/credentials?raw?? HTTP/2.0" ...
show more
34.48.44.40 - - [11/Sep/2026:16:52:35 +0000] "GET /@fs/home/ubuntu/.aws/credentials?raw?? HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)"
34.48.44.40 - - [11/Sep/2026:16:52:35 +0000] "GET /public/plugins/alertlist/../../../../../../../../proc/self/environ HTTP/2.0" 400 1841 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)"
34.48.44.40 - - [11/Sep/2026:16:52:35 +0000] "GET /@fs/home/ec2-user/.aws/credentials?raw?? HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)"
34.48.44.40 - - [11/Sep/2026:16:52:35 +0000] "GET /z9x8c7v6b5-debug-trigger-thejunkymonkey.com HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)"
34.48.44.40 - - [11/Sep/2026:16:52:35 +0000] "GET /@fs/var/task/.env?raw?? HTTP/2.0" 404 1855 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot)"
34.48.44.40 - - [11/Sep/2026:16:52:35 +0000
...
show less
Brute-Force
🇺🇸
IndigoRidge
2026-09-11 16:50:31
(7 hours ago)
34.48.44.40 - - [11/Sep/2026:12:50:29 -0400] "GET /api/.env/public/.env HTTP/1.1" 404 4838 "https:// ...
show more
34.48.44.40 - - [11/Sep/2026:12:50:29 -0400] "GET /api/.env/public/.env HTTP/1.1" 404 4838 "https://thejourneyhomellc.com/api/.env/public/.env" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ChatGPT-User/1.0; +https://openai.com/bot)"
34.48.44.40 - - [11/Sep/2026:12:50:30 -0400] "GET /assets../.env HTTP/1.1" 404 4838 "https://thejourneyhomellc.com/assets../.env" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot)"
34.48.44.40 - - [11/Sep/2026:12:50:30 -0400] "GET /images../.env HTTP/1.1" 404 4838 "https://thejourneyhomellc.com/images../.env" "Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)"
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 16:35:14
(7 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.48.44.40 (40.44.48.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.48.44.40 (40.44.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 12:35:07.127167 2026] [security2:error] [pid 2217522:tid 2217535] [client 34.48.44.40:45246] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||theinfinitenow.com|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "theinfinitenow.com"] [uri "/server.key"] [unique_id "aqQtuy2ChxZfYxBtuDWONwAAAQo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-09-11 16:15:03
(7 hours ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 16:13:07
(7 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.48.44.40 (40.44.48.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.48.44.40 (40.44.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 12:13:01.559925 2026] [security2:error] [pid 17020:tid 17020] [client 34.48.44.40:55048] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||thehiddengemmalta.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "thehiddengemmalta.com"] [uri "/z9x8c7v6b5-debug-trigger-thehiddengemmalta.com"] [unique_id "aqQojWYX3ol-xgN2sQBNeQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-09-11 16:05:03
(8 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 15:56:20
(8 hours ago)
(mod_security) mod_security (id:210580) triggered by 34.48.44.40 (40.44.48.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210580) triggered by 34.48.44.40 (40.44.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 11:56:14.804014 2026] [security2:error] [pid 6517:tid 6517] [client 34.48.44.40:41996] ModSecurity: Access denied with code 403 (phase 2). Matched phrase ".ssh/id_rsa" at ARGS:filename. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||thegrousewoods.com|F|2"] [data "Matched Data: .ssh/id_rsa found within ARGS:filename: file:/root/.ssh/id_rsa"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "thegrousewoods.com"] [uri "/__vite_rsc_findSourceMapURL"] [unique_id "aqQknsmBdgYMAEfrt9EBnQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-11 15:54:44
(8 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
🇺🇸
IndigoRidge
2026-09-11 15:54:01
(8 hours ago)
[11/Sep/2026:11:54:00.700914 --0400] aqQkGLkLfVsz@dIfTyEj3wAAAAo 34.48.44.40 35278 205.233.18.17 708 ...
show more
[11/Sep/2026:11:54:00.700914 --0400] aqQkGLkLfVsz@dIfTyEj3wAAAAo 34.48.44.40 35278 205.233.18.17 7081
[11/Sep/2026:11:54:00.701299 --0400] aqQkGGR8mlCxuJmsGIcZEQAAAUo 34.48.44.40 35268 205.233.18.17 7081
[11/Sep/2026:11:54:00.702094 --0400] aqQkGGR8mlCxuJmsGIcZEgAAAU0 34.48.44.40 35302 205.233.18.17 7081
[11/Sep/2026:11:54:00.712432 --0400] aqQkGAxe56R8QsFtLOTBDAAAAQw 34.48.44.40 35316 205.233.18.17 7081
[11/Sep/2026:11:54:00.712798 --0400] aqQkGOtd0tGuqtb5kIc7GgAAAE0 34.48.44.40 35330 205.233.18.17 7081
...
show less
Hacking