๐บ๐ธ
TPI-Abuse
2026-09-08 05:04:40
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.65.142.17 (17.142.65.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.142.17 (17.142.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 01:04:33.998141 2026] [security2:error] [pid 16640:tid 16640] [client 34.65.142.17:60064] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.photospecialties.net"] [uri "/.env.production"] [unique_id "ap-XYd3WyurXf14yGcN96gAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-08 03:44:30
(2 weeks ago)
Web attack/malicious scanning detected
Web App Attack
๐ฎ๐ช
AutosOnShow
2026-09-07 22:54:05
(2 weeks ago)
blocked for webapp attack | path requested: / | seen at 2026-09-07 22:53:25.598 |
Web App Attack
๐ฌ๐ง
essinghigh
2026-09-07 21:28:16
(2 weeks ago)
IPS Detection: 34.65.142.17 -> DPT: 80
Port Scan
๐ญ๐บ
kollanyit
2026-09-07 12:31:34
(2 weeks ago)
34.65.142.17 - - [07/Sep/2026:12:31:31 +0000] "GET /.aider.env HTTP/1.1" 404 179 "-" "Mozilla/5.0 (X ...
show more
34.65.142.17 - - [07/Sep/2026:12:31:31 +0000] "GET /.aider.env HTTP/1.1" 404 179 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36" "-"
...
show less
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-09-06 22:19:50
(2 weeks ago)
Brute-Force
Web App Attack
๐บ๐ธ
Major Hostility
2026-09-06 17:59:01
(2 weeks ago)
"GET /backup.tar HTTP/1.1" 404
"GET /db.sql HTTP/1.1" 404
"GET /backup.zip HTTP/1.1" 404
"GET /backu ...
show more
"GET /backup.tar HTTP/1.1" 404
"GET /db.sql HTTP/1.1" 404
"GET /backup.zip HTTP/1.1" 404
"GET /backup.tar.gz HTTP/1.1" 404
"GET /backup.sql HTTP/1.1" 404
"GET /dump.sql HTTP/1.1" 404
"GET /database.sql HTTP/1.1" 404
"GET /backup.tgz HTTP/1.1" 404
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-06 03:49:29
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.65.142.17 (17.142.65.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.142.17 (17.142.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:49:23.891826 2026] [security2:error] [pid 24528:tid 24528] [client 34.65.142.17:53730] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.dc406.net"] [uri "/wp-config.php.swp"] [unique_id "apziwwh9q9IPeE66xfB5EQAAAFk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-06 02:57:09
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.65.142.17 (17.142.65.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.142.17 (17.142.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:57:02.196137 2026] [security2:error] [pid 12436:tid 12436] [client 34.65.142.17:48398] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.dunningtons.com"] [uri "/.env.bak"] [unique_id "apzWfpIiVVDC47d-9EKlBwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-06 02:05:13
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 34.65.142.17 (17.142.65.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.65.142.17 (17.142.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:05:07.034890 2026] [security2:error] [pid 26983:tid 26983] [client 34.65.142.17:57778] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||imagesbyaubrey.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "imagesbyaubrey.com"] [uri "/db.sql"] [unique_id "apzKU0aUQJsnuiBgTIIy8QAAAHY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FD-IX
2026-09-06 01:46:00
(2 weeks ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-06 01:35:05
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.65.142.17 (17.142.65.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.142.17 (17.142.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:34:57.984826 2026] [security2:error] [pid 11357:tid 11357] [client 34.65.142.17:35480] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mrccertification.com"] [uri "/.env.bak"] [unique_id "apzDQe9letBXOidvPBMK2QAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-09-06 01:20:18
(2 weeks ago)
Try to access /.env
Web App Attack
Anonymous
2026-09-06 00:51:04
(2 weeks ago)
Bot / scanning and/or hacking attempts: GET /wp-config.php~ HTTP/1.1, GET /actuator/configprops HTTP ...
show more
Bot / scanning and/or hacking attempts: GET /wp-config.php~ HTTP/1.1, GET /actuator/configprops HTTP/1.1, GET /actuator/env HTTP/1.1, GET /.env.backup HTTP/1.1, GET /wp-config.php.swp HTTP/1.1, GET /.env.dev HTTP/1.1, GET /.env.bak HTTP/1.1, GET /.env.prod HTTP/1.1, GET /env HTTP/1.1, GET /_ignition/health-check HTTP/1.1, GET /.env.local HTTP/1.1, GET /wp-config.php.bak HTTP/1.1, GET /crusader-404-probe HTTP/1.1, GET /.env.save HTTP/1.1, GET /.env.production HTTP/1.1
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-05 23:55:01
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.65.142.17 (17.142.65.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.142.17 (17.142.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:54:55.605504 2026] [security2:error] [pid 19230:tid 19230] [client 34.65.142.17:56688] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.jvcsat.com"] [uri "/.env.production"] [unique_id "apyrzwhg9r-xQcX37GHiWwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack