πΊπΈ
TPI-Abuse
2026-08-29 06:33:10
(6 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.7.11.159 (159.11.7.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.7.11.159 (159.11.7.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 02:33:03.253141 2026] [security2:error] [pid 4296:tid 4296] [client 34.7.11.159:28238] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.howtosellmorepizza.com"] [uri "/@fs/root/.env"] [unique_id "apJ9H4zYTGPWaQQznNxdfwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-29 06:10:30
(29 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.7.11.159 (159.11.7.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.7.11.159 (159.11.7.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 02:10:24.904675 2026] [security2:error] [pid 334:tid 334] [client 34.7.11.159:1614] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.wild-goose.net"] [uri "/@fs/app/.env"] [unique_id "apJ30NDwbQEy4KMJXwUa5AAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-29 05:26:37
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.7.11.159 (159.11.7.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.7.11.159 (159.11.7.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 01:26:30.143003 2026] [security2:error] [pid 10894:tid 10894] [client 34.7.11.159:18738] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.melkanbassil.com"] [uri "/@fs/root/.env"] [unique_id "apJthgyfBEmoYgjaMpZCKgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Savvii
2026-08-29 05:14:41
(1 hour ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Site.eu
2026-08-29 04:50:03
(1 hour ago)
Excessive multi-domain requests
Brute-Force
πΊπΈ
TPI-Abuse
2026-08-29 04:28:01
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.7.11.159 (159.11.7.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.7.11.159 (159.11.7.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 00:27:55.448616 2026] [security2:error] [pid 32476:tid 32476] [client 34.7.11.159:26664] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.riocanoas.com"] [uri "/@fs/root/.env"] [unique_id "apJfy5tkbL0hKXdAlusHmQAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-29 03:46:41
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.7.11.159 (159.11.7.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.7.11.159 (159.11.7.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 23:46:36.482825 2026] [security2:error] [pid 31266:tid 31266] [client 34.7.11.159:14784] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.benshermanclassicalguitar.benshermanguitar.com"] [uri "/@fs/app/.env"] [unique_id "apJWHOujy0xFzFsW_KQPCgAAADg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
maxpower
2026-08-29 03:21:41
(3 hours ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.7.11.159 (159.11.7.34.bc.googleuserco ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.7.11.159 (159.11.7.34.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.7.11.159 - - [29/Aug/2026:05:21:39 +0200] "GET /@fs/home/ubuntu/.aws/credentials?raw?? HTTP/1.1" 200 11961 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; LinkedInBot/1.0; +http://www.linkedin.com" "-" host=emmeccipubblicita.it
show less
Port Scan
πΊπΈ
TPI-Abuse
2026-08-29 01:58:45
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.7.11.159 (159.11.7.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.7.11.159 (159.11.7.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 21:58:39.728874 2026] [security2:error] [pid 4499:tid 4499] [client 34.7.11.159:8666] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.rockwaychiropractic.com"] [uri "/@fs/app/.env"] [unique_id "apI8z1Fg3UWeNxDtmAk4wQAAADI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-29 01:38:34
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.7.11.159 (159.11.7.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.7.11.159 (159.11.7.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 21:38:29.086425 2026] [security2:error] [pid 106473:tid 106492] [client 34.7.11.159:48508] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "earthlink-internet.com"] [uri "/@fs/.env"] [unique_id "apI4FQT0nhezPdooEOmhDAAAAM8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
jormaster3k
2026-08-29 01:14:09
(5 hours ago)
Attack against Apache (too many 404s)
Web App Attack
π³π±
Alboweb B.V.
2026-08-29 01:11:04
(5 hours ago)
Bad web bot activity detected by Fail2Ban in plesk-apache-badbot jail
Bad Web Bot
Anonymous
2026-08-29 01:10:12
(5 hours ago)
Bot / seems abusive / Apache connections: 122
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-29 00:57:57
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.7.11.159 (159.11.7.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.7.11.159 (159.11.7.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 20:57:49.156940 2026] [security2:error] [pid 28986:tid 28986] [client 34.7.11.159:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "haywardcarpentry.com"] [uri "/@fs/src/.env"] [unique_id "apIujcTAHnafmxpTm113CwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-29 00:39:57
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.7.11.159 (159.11.7.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.7.11.159 (159.11.7.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 20:39:53.144768 2026] [security2:error] [pid 29605:tid 29605] [client 34.7.11.159:57020] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.jbernsteinpc.com"] [uri "/@fs/.env"] [unique_id "apIqWYnZc2WB2Z8I2ve_iwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack