๐บ๐ธ
factor1
2026-09-22 01:46:53
(3 days ago)
CrowdSec at saturn Reports Abuse
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 01:28:57
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.70.117.226 (226.117.70.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.70.117.226 (226.117.70.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 21:28:53.777453 2026] [security2:error] [pid 19787:tid 19787] [client 34.70.117.226:43304] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.anchorroots.com"] [uri "/.git/config"] [unique_id "arHZ1ZuxgsuIe6FsHRD_tQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 00:39:50
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.70.117.226 (226.117.70.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.70.117.226 (226.117.70.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 20:39:42.894584 2026] [security2:error] [pid 21105:tid 21105] [client 34.70.117.226:60500] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.4dbm.com"] [uri "/.env.old"] [unique_id "arHOTpNbPBwcyWqiOeEBaAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 23:35:29
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.70.117.226 (226.117.70.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.70.117.226 (226.117.70.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 19:35:21.755569 2026] [security2:error] [pid 7205:tid 7205] [client 34.70.117.226:58990] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.1writeforthegrant.com"] [uri "/.env"] [unique_id "arG_OamGn2n4gWmRo9m_4gAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
maxpower
2026-09-21 23:16:12
(3 days ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.70.117.226 (US/United States/226.117. ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.70.117.226 (US/United States/226.117.70.34.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.70.117.226 - - [22/Sep/2026:01:16:10 +0200] "GET /.aws/credentials HTTP/2.0" 200 12168 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot)" "-" host=aureasrl.com
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-09-21 23:13:43
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 34.70.117.226 (226.117.70.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.70.117.226 (226.117.70.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 19:13:39.781830 2026] [security2:error] [pid 13823:tid 13823] [client 34.70.117.226:46058] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.alanbeckwith.com|F|2"] [data ".alanbeckwith.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.alanbeckwith.com"] [uri "/z9x8c7v6b5-debug-trigger-autodiscover.alanbeckwith.com"] [unique_id "arG6I5zxgrMxrHNKMz_k6QAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
TheDjRider
2026-09-21 22:50:40
(3 days ago)
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban tri ...
show more
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban triggered. Detection time (UTC): 2026-09-21T22:50:37.65977413Z. Context: http_status=404
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 22:44:00
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.70.117.226 (226.117.70.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.70.117.226 (226.117.70.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 18:43:52.043351 2026] [security2:error] [pid 13834:tid 13834] [client 34.70.117.226:32992] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.alhashim.com"] [uri "/frontend/.env"] [unique_id "arGzKFHTbdvZCCTeMA9bdgAAAEQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 22:20:44
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.70.117.226 (226.117.70.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.70.117.226 (226.117.70.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 18:20:39.571647 2026] [security2:error] [pid 23801:tid 23801] [client 34.70.117.226:41910] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.astariamedia.com"] [uri "/.env.example"] [unique_id "arGttxarezC4auTfueKqLwAAAE4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 21:26:16
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.70.117.226 (226.117.70.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.70.117.226 (226.117.70.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 17:26:10.950146 2026] [security2:error] [pid 32353:tid 32353] [client 34.70.117.226:58778] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.americanureport.com"] [uri "/.git/HEAD"] [unique_id "arGg8j3HxdRVMOkV1UDG1gAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 20:19:16
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 34.70.117.226 (226.117.70.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.70.117.226 (226.117.70.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 16:19:10.859793 2026] [security2:error] [pid 5242:tid 5242] [client 34.70.117.226:43546] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.3-6trucking.com|F|2"] [data ".3-6trucking.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.3-6trucking.com"] [uri "/z9x8c7v6b5-debug-trigger-mail.3-6trucking.com"] [unique_id "arGRPnpCgSN2qzcGrBxqZgAAAEk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 19:54:37
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 34.70.117.226 (226.117.70.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.70.117.226 (226.117.70.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 15:54:32.772052 2026] [security2:error] [pid 12000:tid 12000] [client 34.70.117.226:35194] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.advantageinvestigation.com|F|2"] [data ".advantageinvestigation.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.advantageinvestigation.com"] [uri "/z9x8c7v6b5-debug-trigger-autodiscover.advantageinvestigation.com"] [unique_id "arGLePmdNCLci-7z9IggDAAAAH8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 19:29:21
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.70.117.226 (226.117.70.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.70.117.226 (226.117.70.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 15:29:15.430027 2026] [security2:error] [pid 26824:tid 26824] [client 34.70.117.226:36488] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.apfarrell.com"] [uri "/.env.backup"] [unique_id "arGFizEAPkwBbHSV9YyxqQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 17:41:00
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.70.117.226 (226.117.70.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.70.117.226 (226.117.70.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 13:40:53.316895 2026] [security2:error] [pid 30106:tid 30106] [client 34.70.117.226:54726] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.abirdnamedfart.com"] [uri "/.git/HEAD"] [unique_id "arFsJag6ZnvsaENjfKVv7QAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 16:47:25
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.70.117.226 (226.117.70.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.70.117.226 (226.117.70.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 12:47:18.835186 2026] [security2:error] [pid 21505:tid 21505] [client 34.70.117.226:47088] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.acmyles.com"] [uri "/.env.local"] [unique_id "arFflnXo5YnrInA034xZ2gAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack