๐ฉ๐ช
creoline GmbH
2026-09-24 13:54:46
(9 hours ago)
[WAF] Multiple suspicious HTTP requests has been blocked
Bad Web Bot
Web App Attack
Anonymous
2026-09-24 13:24:31
(10 hours ago)
Aggressive web scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 12:06:24
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.7.214.52 (52.214.7.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.7.214.52 (52.214.7.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 08:06:18.912464 2026] [security2:error] [pid 28180:tid 28180] [client 34.7.214.52:35442] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.diegolaje.com"] [uri "/.env.development"] [unique_id "arUSOnb8L4Z3PFcroLATuQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-09-24 11:55:19
(11 hours ago)
128 requests with url.path */@fs/*
Brute-Force
Bad Web Bot
๐บ๐ธ
Takesh
2026-09-24 10:13:10
(13 hours ago)
Numbase auto-report: abuseipdb_known_bad_score_76
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-24 08:56:52
(14 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.7.214.52 (52.214.7.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.7.214.52 (52.214.7.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 04:56:48.084397 2026] [security2:error] [pid 25397:tid 25397] [client 34.7.214.52:40984] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||directnic.ladybehindthecurtain.com|F|2"] [data ".ladybehindthecurtain.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "directnic.ladybehindthecurtain.com"] [uri "/z9x8c7v6b5-debug-trigger-directnic.ladybehindthecurtain.com"] [unique_id "arTl0ESsm8HabnZpHELmwwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
robotstxt
2026-09-24 08:56:26
(14 hours ago)
34.7.214.52 - - [24/Sep/2026:08:55:49 +0000] "GET /.env.save HTTP/2.0" 403 33029 "-" rt="5.391" "Moz ...
show more
34.7.214.52 - - [24/Sep/2026:08:55:49 +0000] "GET /.env.save HTTP/2.0" 403 33029 "-" rt="5.391" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)" "-" edge="34.7.214.52" h="directorio.componentescalzado.com" sn="directorio.componentescalzado.com" ru="/.env.save" u="/index.php" ucs="-" ua="unix:/var/run/php/ccalzadodir82.sock" us="404" uct="0.000" urt="5.391"
34.7.214.52 - - [24/Sep/2026:08:55:50 +0000] "GET /.env.prod HTTP/2.0" 403 33028 "-" rt="5.647" "Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)" "-" edge="34.7.214.52" h="directorio.componentescalzado.com" sn="directorio.componentescalzado.com" ru="/.env.prod" u="/index.php" ucs="-" ua="unix:/var/run/php/ccalzadodir82.sock" us="404" uct="0.000" urt="5.646"
34.7.214.52 - - [24/Sep/2026:08:55:52 +0000] "GET /api/.env HTTP/2.0" 403 33028 "-" rt="4.898" "Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)" "-" edge="34.7.214.52" h="directorio.componentescalzado.com" sn="directorio.componentescalzado.c
...
show less
Web App Attack
Anonymous
2026-09-23 18:38:01
(1 day ago)
34.7.214.52 - - [23/Sep/2026:13:37:57 -0500] "GET /.env?import&raw HTTP/1.1" 403 199 "-" "Mozilla/5. ...
show more
34.7.214.52 - - [23/Sep/2026:13:37:57 -0500] "GET /.env?import&raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )" 172.69.194.70
34.7.214.52 - - [23/Sep/2026:13:37:57 -0500] "GET /.env?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)" 172.69.194.70
34.7.214.52 - - [23/Sep/2026:13:37:58 -0500] "GET /.env.production?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)" 172.69.194.70
34.7.214.52 - - [23/Sep/2026:13:37:58 -0500] "GET /.env.local?import&raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)" 172.69.194.70
34.7.214.52 - - [23/Sep/2026:13:37:58 -0500] "GET /.env?import&url&inline HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)" 172.69.194.70
34.7.214.52 - - [23/Sep/2026:13:37:58 -0500] "GET /.env.local?raw HTT
...
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-23 18:26:44
(1 day ago)
34.7.214.52 - - [24/Sep/2026:02:26:43 +0800] "GET /webpack-stats.json HTTP/1.1" 404 39532 "https://w ...
show more
34.7.214.52 - - [24/Sep/2026:02:26:43 +0800] "GET /webpack-stats.json HTTP/1.1" 404 39532 "https://www.nonsensemakers.com/webpack-stats.json" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 Edg/153.0.0.0"
34.7.214.52 - - [24/Sep/2026:02:26:43 +0800] "GET /manifest.json HTTP/1.1" 404 39532 "https://www.nonsensemakers.com/manifest.json" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 Edg/153.0.0.0"
34.7.214.52 - - [24/Sep/2026:02:26:43 +0800] "GET /static/manifest.json HTTP/1.1" 404 39532 "https://www.nonsensemakers.com/static/manifest.json" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 Edg/153.0.0.0"
34.7.214.52 - - [24/Sep/2026:02:26:43 +0800] "GET /menfnjka5pupzv29z45x HTTP/1.1" 404 39532 "https://www.nonsensemakers.com/menfnjka5pupzv29z45x" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://w
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 18:25:08
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.7.214.52 (52.214.7.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.7.214.52 (52.214.7.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 14:25:03.753915 2026] [security2:error] [pid 22825:tid 22825] [client 34.7.214.52:55444] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.my-spec.com|F|2"] [data ".my-spec.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.my-spec.com"] [uri "/z9x8c7v6b5-debug-trigger-www.my-spec.com"] [unique_id "arQZf8SioQLAUMT0VeJNvQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 16:57:59
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.7.214.52 (52.214.7.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.7.214.52 (52.214.7.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 12:57:55.098979 2026] [security2:error] [pid 4222:tid 4286] [client 34.7.214.52:52620] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.digital4z.com|F|2"] [data ".digital4z.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.digital4z.com"] [uri "/z9x8c7v6b5-debug-trigger-www.digital4z.com"] [unique_id "arQFEwbAi7Yjiq-MRwbwKQAAAcc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-23 15:56:38
(1 day ago)
Excessive multi-domain requests
Brute-Force
๐ฉ๐ช
todix
2026-09-23 15:42:01
(1 day ago)
Web App Attack Exploid from 34.7.214.52
Web App Attack
๐ซ๐ท
Octopuce
2026-09-23 15:26:59
(1 day ago)
Aggressive web search of vulnerable pages: /docker-compose.yml /application.yml /config/database.yml ...
show more
Aggressive web search of vulnerable pages: /docker-compose.yml /application.yml /config/database.yml /openapi.json /admin/ ...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 15:19:18
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.7.214.52 (52.214.7.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.7.214.52 (52.214.7.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 11:19:14.560378 2026] [security2:error] [pid 21182:tid 21182] [client 34.7.214.52:57202] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||digifonics.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "digifonics.com"] [uri "/z9x8c7v6b5-debug-trigger-digifonics.com"] [unique_id "arPt8kwopaFsc6B9Tv-sSAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack