Anonymous
2026-09-11 19:11:27
(13 hours ago)
IP matched detection query many 3xx errors.
Brute-Force
🇺🇸
IndigoRidge
2026-09-11 18:53:25
(13 hours ago)
34.57.24.150 - - [11/Sep/2026:14:53:25 -0400] "GET /.aws/credentials HTTP/1.1" 404 5554 "-" "Mozilla ...
show more
34.57.24.150 - - [11/Sep/2026:14:53:25 -0400] "GET /.aws/credentials HTTP/1.1" 404 5554 "-" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)"
34.57.24.150 - - [11/Sep/2026:14:53:25 -0400] "GET /.git/config HTTP/1.1" 404 5554 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )"
34.57.24.150 - - [11/Sep/2026:14:53:25 -0400] "GET /backend/.env HTTP/1.1" 404 5554 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)"
...
show less
Web App Attack
🇫🇷
dynamix
2026-09-11 18:15:13
(14 hours ago)
Multiple WAF Violations
Web App Attack
🇩🇪
yvoictra
2026-09-11 17:52:19
(14 hours ago)
Bloqueado automáticamente por CrowdSec. Escenario: crowdsecurity/http-bad-user-agent
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 17:46:13
(14 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.57.24.150 (150.24.57.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.57.24.150 (150.24.57.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 13:46:07.412947 2026] [security2:error] [pid 7548:tid 7548] [client 34.57.24.150:58014] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||unwaved.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "unwaved.com"] [uri "/z9x8c7v6b5-debug-trigger-unwaved.com"] [unique_id "aqQ-X8NxDQ0v2c3JIZCNaAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 16:55:14
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.57.24.150 (150.24.57.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.57.24.150 (150.24.57.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 12:55:09.340910 2026] [security2:error] [pid 19242:tid 19242] [client 34.57.24.150:56244] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "univey.com"] [uri "/.env.backup"] [unique_id "aqQybTyRLWOUHnz9YCCJCQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 16:33:56
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.57.24.150 (150.24.57.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.57.24.150 (150.24.57.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 12:33:51.866130 2026] [security2:error] [pid 26546:tid 26546] [client 34.57.24.150:36836] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "unityhealthpharmaceutical.com"] [uri "/.env"] [unique_id "aqQtb730pxBa8iwMo43ZcgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 16:18:18
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.57.24.150 (150.24.57.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.57.24.150 (150.24.57.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 12:18:14.484199 2026] [security2:error] [pid 15832:tid 15832] [client 34.57.24.150:55340] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "unitedfuturistassociation.com"] [uri "/.env.js"] [unique_id "aqQpxqHUNTJqHvjCYjaNnwAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-09-11 16:00:05
(16 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 15:58:06
(16 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.57.24.150 (150.24.57.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.57.24.150 (150.24.57.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 11:58:00.588507 2026] [security2:error] [pid 26579:tid 26579] [client 34.57.24.150:59860] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||uniquelaos.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "uniquelaos.com"] [uri "/z9x8c7v6b5-debug-trigger-uniquelaos.com"] [unique_id "aqQlCOnwXI1INqTXLBzVVwAAAEI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
IndigoRidge
2026-09-11 15:57:37
(16 hours ago)
34.57.24.150 - - [11/Sep/2026:11:57:33 -0400] "GET /.git/config HTTP/1.1" 403 5693 "-" "Mozilla/5.0 ...
show more
34.57.24.150 - - [11/Sep/2026:11:57:33 -0400] "GET /.git/config HTTP/1.1" 403 5693 "-" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/)"
34.57.24.150 - - [11/Sep/2026:11:57:33 -0400] "GET /.aws/credentials HTTP/1.1" 404 34162 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)"
34.57.24.150 - - [11/Sep/2026:11:57:37 -0400] "GET /.env HTTP/1.1" 403 5693 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)"
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 15:39:44
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.57.24.150 (150.24.57.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.57.24.150 (150.24.57.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 11:39:36.346601 2026] [security2:error] [pid 13569:tid 13569] [client 34.57.24.150:59966] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "unilabkenya.com"] [uri "/config/.env"] [unique_id "aqQguKPWMx1d1mDKKSpotAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-11 15:38:04
(16 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack