๐บ๐ธ
TPI-Abuse
2026-10-09 15:46:55
(1 minute ago)
(mod_security) mod_security (id:210580) triggered by 34.6.207.174 (174.207.6.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210580) triggered by 34.6.207.174 (174.207.6.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 11:46:49.584884 2026] [security2:error] [pid 23762:tid 23762] [client 34.6.207.174:40426] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at ARGS:file. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||hydrogenplus.net|F|2"] [data "Matched Data: proc/self/environ found within ARGS:file: /proc/self/environ"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "hydrogenplus.net"] [uri "/api/system/fileView"] [unique_id "askMaYPWuKsnCuabFhweKQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
pcpiefke
2026-10-09 15:21:54
(26 minutes ago)
(mod_security) mod_security triggered on hostname [redacted] 34.6.207.174 (174.207.6.34.bc.googleuse ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.6.207.174 (174.207.6.34.bc.googleusercontent.com)
show less
SQL Injection
๐ฉ๐ช
paissangroup
2026-10-09 15:04:30
(43 minutes ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
interbiznw.com
2026-10-09 14:49:35
(58 minutes ago)
malicious-web-requests-vulnerability-scanning
Hacking
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 14:38:22
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.6.207.174 (174.207.6.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.6.207.174 (174.207.6.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 10:38:15.835032 2026] [security2:error] [pid 31752:tid 31752] [client 34.6.207.174:54652] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hisfavorite.net"] [uri "/.env.prod"] [unique_id "asj8VzzcfDvuwqXGNzHwKAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-09 14:27:52
(1 hour ago)
[ti-12al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 34. ...
show more
[ti-12al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 34.6.207.174 - - \[09/Oct/2026:16:27:31 +0200\] "GET /%2e%2e/.env HTTP/2.0" 400 332 "-" "Mozilla/5.0 \(compatible\; xAI-Grok/1.0\; +https://x.ai/\)"
...
show less
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-10-09 14:24:42
(1 hour ago)
BAD BOT - Detected and Blocked.. Matched phrase "baidu" at REQUEST_HEADERS:User-Agent. (1100000-196)
Bad Web Bot
๐ฌ๐ง
consul.to
2026-10-09 14:22:30
(1 hour ago)
Web attack/malicious scanning detected
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-10-09 14:20:18
(1 hour ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 14:17:12
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.6.207.174 (174.207.6.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.6.207.174 (174.207.6.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 10:17:08.984836 2026] [security2:error] [pid 7250:tid 7250] [client 34.6.207.174:48480] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "heavenonearthonline.net"] [uri "/static../.env"] [unique_id "asj3ZCOAjv4uxytw1kgAlgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
yitzhaq
2026-10-09 14:11:07
(1 hour ago)
34.6.207.174 - - [09/Oct/2026:16:11:03 +0200] "GET /settings.js HTTP/2.0" 403 290 "-" "Mozilla/5.0 A ...
show more
34.6.207.174 - - [09/Oct/2026:16:11:03 +0200] "GET /settings.js HTTP/2.0" 403 290 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)"
34.6.207.174 - - [09/Oct/2026:16:11:03 +0200] "GET /configuration.js HTTP/2.0" 403 290 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email])"
34.6.207.174 - - [09/Oct/2026:16:11:03 +0200] "GET /swagger.json HTTP/2.0" 404 644 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)"
34.6.207.174 - - [09/Oct/2026:16:11:03 +0200] "GET /environment.js HTTP/2.0" 404 644 "-" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)"
34.6.207.174 - - [09/Oct/2026:16:11:03 +0200] "GET /api/health HTTP/2.0" 404 644 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot"
34.6.207.174 - - [09/Oct/2026:16:11:03 +0200] "GET /constants.js HTTP/2.0" 403 290 "-" "Mozilla/5.0 AppleWebK
show less
Bad Web Bot
Anonymous
2026-10-09 14:00:07
(1 hour ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection
๐ซ๐ท
masterguru
2026-10-09 13:58:52
(1 hour ago)
BAD BOT - Detected and Blocked.. Matched phrase "baidu" at REQUEST_HEADERS:User-Agent. (1100000-193)
Bad Web Bot
๐บ๐ธ
magnetosphere-tarpit
2026-10-09 13:57:08
(1 hour ago)
Automated web scanner: repeatedly probed for .env, .git, wp-admin and PHP webshell paths that do not ...
show more
Automated web scanner: repeatedly probed for .env, .git, wp-admin and PHP webshell paths that do not exist on this host. Tarpitted, then banned: 10 requests within 24h0m0s
show less
Port Scan
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 13:51:30
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.6.207.174 (174.207.6.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.6.207.174 (174.207.6.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 09:51:25.852793 2026] [security2:error] [pid 24699:tid 24699] [client 34.6.207.174:33806] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "haarr.net"] [uri "/.htpasswd"] [unique_id "asjxXReNyXE7JI-FggB4cgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack