๐ฉ๐ช
Philister11
2026-09-22 01:13:34
(29 minutes ago)
CrowdSec: crowdsecurity/http-probing (US/AS396982)
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-22 00:10:17
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.68.128.34 (34.128.68.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.68.128.34 (34.128.68.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 20:10:09.173431 2026] [security2:error] [pid 30195:tid 30195] [client 34.68.128.34:52454] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "airdeluxemusic.com"] [uri "/.env.bak"] [unique_id "arHHYWrYx1EtqQkqdWB11QAAAEo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
ciccio diddo
2026-09-21 23:22:32
(2 hours ago)
High Burst multiple 40X port:Tcp/80,443
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2026-09-21 23:05:48
(2 hours ago)
Scanning/Probing (14)
Brute-Force
Web App Attack
๐ฉ๐ช
ger-stg-sifi1
2026-09-21 22:54:11
(2 hours ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
๐ณ๐ฑ
svr
2026-09-21 19:56:19
(5 hours ago)
Abusive Automated Web Scanner
Web App Attack
Anonymous
2026-09-21 18:39:30
(7 hours ago)
Aggressive web scan
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-21 16:48:19
(8 hours ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-21 16:22:47
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.68.128.34 (34.128.68.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.68.128.34 (34.128.68.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 12:22:41.906558 2026] [security2:error] [pid 12716:tid 12716] [client 34.68.128.34:58234] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.sophcomp.com"] [uri "/deploy/.env"] [unique_id "arFZ0TYkDFZO38vwNSHe3gAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 15:26:09
(10 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.68.128.34 (34.128.68.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.68.128.34 (34.128.68.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 11:26:01.585676 2026] [security2:error] [pid 27069:tid 27069] [client 34.68.128.34:60132] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.albertawaterjet.com|F|2"] [data ".albertawaterjet.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.albertawaterjet.com"] [uri "/z9x8c7v6b5-debug-trigger-mail.albertawaterjet.com"] [unique_id "arFMib8cTyDTwr1p3hFcIgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 14:51:56
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.68.128.34 (34.128.68.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.68.128.34 (34.128.68.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 10:51:51.724854 2026] [security2:error] [pid 4432:tid 4432] [client 34.68.128.34:56446] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.alhill.com"] [uri "/@fs/proc/self/cwd/.env"] [unique_id "arFEh_PNcKBOseWQ8SrocwAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-21 14:27:40
(11 hours ago)
[ti-05al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-05al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.68.128.34 - - [21/Sep/2026:16:27:21 +0200] "GET /.svn/entries HTTP/2.0" 403 346 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 14:25:17
(11 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.68.128.34 (34.128.68.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.68.128.34 (34.128.68.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 10:25:12.974597 2026] [security2:error] [pid 23197:tid 23197] [client 34.68.128.34:33634] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.alexissteinrauf.com|F|2"] [data ".alexissteinrauf.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.alexissteinrauf.com"] [uri "/z9x8c7v6b5-debug-trigger-mail.alexissteinrauf.com"] [unique_id "arE-SC0UGKqGMYtdTNJonQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ฌ
Cloudkul Cloudkul
2026-09-21 14:00:53
(11 hours ago)
Attempted Brute Force on our application
Brute-Force
Web App Attack
๐ฎ๐น
VHosting
2026-09-21 13:55:05
(11 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack