๐ฟ๐ฆ
conure.sh
2026-09-16 12:07:37
(15 hours ago)
csagent: score 22.5: 404 noise floor x10, secrets grab x2; 1 domain(s) in 1s
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 05:04:30
(22 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.55.53.13 (13.53.55.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.55.53.13 (13.53.55.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 01:04:22.521370 2026] [security2:error] [pid 15866:tid 15866] [client 34.55.53.13:48138] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||williamgilcher.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "williamgilcher.com"] [uri "/z9x8c7v6b5-debug-trigger-williamgilcher.com"] [unique_id "aqojVn4DWzTJkU57f_HjuQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 04:38:56
(23 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.55.53.13 (13.53.55.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.55.53.13 (13.53.55.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 00:38:53.131350 2026] [security2:error] [pid 26481:tid 26481] [client 34.55.53.13:50054] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||sunshinenv.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "sunshinenv.com"] [uri "/z9x8c7v6b5-debug-trigger-sunshinenv.com"] [unique_id "aqodXdbu1CmqOO3_PJ2P1gAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-09-16 04:30:03
(23 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ฉ๐ช
FD-IX
2026-09-16 04:25:40
(23 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
Anonymous
2026-09-16 04:10:02
(23 hours ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-09-16 03:53:24
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.55.53.13 (13.53.55.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.55.53.13 (13.53.55.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 23:53:18.790845 2026] [security2:error] [pid 2004643:tid 2004643] [client 34.55.53.13:38140] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mrcd.org|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mrcd.org"] [uri "/rclone.conf"] [unique_id "aqoSrkQhDlGbhF-rbrN4jgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-16 03:25:20
(1 day ago)
2026/09/16 03:25:17 [error] 1993365#1993365: *290 [client 34.55.53.13] ModSecurity: Access denied wi ...
show more
2026/09/16 03:25:17 [error] 1993365#1993365: *290 [client 34.55.53.13] ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Ge' with parameter `5' against variable `TX:BLOCKING_INBOUND_ANOMALY_SCORE' (Value: `15' ) [file "/usr/local/owasp-modsecurity-crs-4.11.0/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "222"] [id "949110"] [rev ""] [msg "Inbound Anomaly Score Exceeded (Total Score: 15)"] [data ""] [severity "0"] [ver "OWASP_CRS/4.29.0"] [maturity "0"] [accuracy "0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "ingeltechgh.com"] [uri "/api/uploads/../../.env"] [unique_id "178952911740.960771"] [ref ""], client: 34.55.53.13, server: ingeltechgh.com, request: "GET /api/uploads/%2e%2e%2f%2e%2e%2f.env HTTP/2.0", host: "ingeltechgh.com"
2026/09/16 03:25:18 [error] 1993365#1993365: *290 [client 34.55.53.13] ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Ge' with parameter `5' against variable `TX:BLOCKING_INBOUND_ANOMALY_SCORE' (Value: `
...
show less
Brute-Force
๐ฌ๐ง
Aetherweb Ark
2026-09-16 03:17:18
(1 day ago)
(mod_security) mod_security (id:949110) triggered by 34.55.53.13 (US/United States/13.53.55.34.bc.go ...
show more
(mod_security) mod_security (id:949110) triggered by 34.55.53.13 (US/United States/13.53.55.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 03:15:58
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.55.53.13 (13.53.55.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.55.53.13 (13.53.55.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 23:15:54.704333 2026] [security2:error] [pid 31235:tid 31235] [client 34.55.53.13:53174] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hongkonger.org"] [uri "/%2e%2e/%2e%2e/%2e%2e/%2e%2e/.env"] [unique_id "aqoJ6l2692-CetV-fm-wFwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-16 03:02:02
(1 day ago)
[ti-12al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 34. ...
show more
[ti-12al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 34.55.53.13 - - \[16/Sep/2026:05:01:44 +0200\] "GET /.github/.env HTTP/2.0" 404 1863 "-" "Mozilla/5.0 AppleWebKit/537.36 \(KHTML, like Gecko\; compatible\; Claude-User/1.0\; [email protected] \)"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
interbiznw.com
2026-09-16 02:38:08
(1 day ago)
malicious-web-requests-vulnerability-scanning
Hacking
Brute-Force
Exploited Host
Web App Attack
Anonymous
2026-09-16 02:19:58
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted] 34.55.53.13 (US/United States/13.53.55. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.55.53.13 (US/United States/13.53.55.34.bc.googleusercontent.com)
show less
SQL Injection
Anonymous
2026-09-16 01:48:02
(1 day ago)
Bot / scanning and/or hacking attempts: GET /.well-known/jwks.json HTTP/2.0, GET /admin/.env HTTP/2. ...
show more
Bot / scanning and/or hacking attempts: GET /.well-known/jwks.json HTTP/2.0, GET /admin/.env HTTP/2.0, GET /service_account.json HTTP/2.0, GET /userfiles?path=../../../../proc/self/environ HTTP/2.0, GET /secrets.json HTTP/2.0, GET /.env.example HTTP/2.0, GET /Dockerfile HTTP/2.0, GET /secrets.yml HTTP/2.0, GET /.env.bak HTTP/2.0, GET /key.json HTTP/2.0, GET /userfiles?path=../../../.env HTTP/2.0, GET /api/.env HTTP/2.0, GET /.env.local HTTP/2.0, GET /userfiles?path=../../../../.env HTTP/2.0, GET /credentials.json HTTP/2.0, GET /service-account.json HTTP/2.0, GET /firebase-adminsdk.json HTTP/2.0, GET /.env.old HTTP/2.0, GET /wp-config.php.old HTTP/2.0, GET /userfiles/x?path=../../.env HTTP/2.0, GET /serviceAccountKey.json HTTP/2.0, GET /firebase-service-account.json HTTP/2.0, GET /config/.env HTTP/2.0, GET /.env.backup HTTP/2.0
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 01:31:04
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.55.53.13 (13.53.55.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.55.53.13 (13.53.55.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 21:30:57.298668 2026] [security2:error] [pid 24155:tid 24155] [client 34.55.53.13:42072] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||hodges-web.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "hodges-web.com"] [uri "/rclone.conf"] [unique_id "aqnxUejzqXTbQFEo2yzNNgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack