๐บ๐ธ
TPI-Abuse
2026-09-01 12:31:38
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.56.128.84 (84.128.56.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.56.128.84 (84.128.56.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 08:31:32.034675 2026] [security2:error] [pid 14635:tid 14635] [client 34.56.128.84:53050] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cgcontinental.com.grupoporvenir.com"] [uri "/.env.production"] [unique_id "apbFpBS7orI6i-fzvQviPgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
factor1
2026-09-01 10:56:28
(4 hours ago)
CrowdSec at apollo Reports Abuse
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 10:46:23
(4 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.56.128.84 (84.128.56.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:949110) triggered by 34.56.128.84 (84.128.56.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 06:46:19.153533 2026] [security2:error] [pid 13581:tid 13581] [client 34.56.128.84:54556] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "panabait.com"] [uri "/.env.save"] [unique_id "apas-3jpvnEtmJ57s1AXhQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Aetherweb Ark
2026-09-01 10:46:00
(4 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.56.128.84 (US/United States/84.128.56.34.bc. ...
show more
(mod_security) mod_security (id:949110) triggered by 34.56.128.84 (US/United States/84.128.56.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
๐ซ๐ท
masterguru
2026-09-01 09:39:21
(6 hours ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.56.128.84 (US/United States/84.128 ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.56.128.84 (US/United States/84.128.56.34.bc.googleusercontent.com): 1 in the last 3600 secs (0-195)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-01 09:31:29
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.56.128.84 (84.128.56.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.56.128.84 (84.128.56.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 05:31:23.231416 2026] [security2:error] [pid 20083:tid 20196] [client 34.56.128.84:57850] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "smtp2.absurdotron.com"] [uri "/.env.dev"] [unique_id "apaba3rBwjt5T889PpFs5QAAAIo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ญ๐บ
Csaba Gรกspรกr
2026-09-01 08:49:00
(6 hours ago)
Spring.Boot.Actuator.Unauthorized.Access
Hacking
๐ฉ๐ช
raph
2026-09-01 07:46:55
(7 hours ago)
[Wordpress] crawler /wp-admin/*, /wp-content/*, etc.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 07:19:21
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.56.128.84 (84.128.56.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.56.128.84 (84.128.56.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 03:19:15.787089 2026] [security2:error] [pid 27685:tid 27685] [client 34.56.128.84:55864] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mirai-labo.com"] [uri "/.env.prod"] [unique_id "apZ8c-Ql5FsVPpS0ODfKBgAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 06:03:30
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.56.128.84 (84.128.56.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.56.128.84 (84.128.56.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 02:03:23.682014 2026] [security2:error] [pid 23025:tid 23025] [client 34.56.128.84:54684] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cooteconsultinggroup.com"] [uri "/.env"] [unique_id "apZqq87tVGB5jcya75_wtgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-01 04:48:42
(10 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-01 04:10:03
(11 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 03:45:53
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.56.128.84 (84.128.56.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.56.128.84 (84.128.56.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 23:45:49.051679 2026] [security2:error] [pid 1400:tid 1400] [client 34.56.128.84:34704] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "alecmcatee.robertmcatee.com"] [uri "/.env.local"] [unique_id "apZKbclh0OgNgLfrlEk62QAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 03:07:00
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.56.128.84 (84.128.56.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.56.128.84 (84.128.56.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 23:06:53.285724 2026] [security2:error] [pid 9701:tid 9806] [client 34.56.128.84:46874] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pflagabq.org"] [uri "/.env.backup"] [unique_id "apZBTTeTJ-AG_xCOHsf1lAAAAhE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
MyGlobalFlowers
2026-09-01 03:00:41
(12 hours ago)
Multiple WAF Violations
Web App Attack