๐บ๐ธ
julianalee.com
2026-09-22 17:54:00
(1 day ago)
21/Sep/26 07:24:39 #4824829 CRITICAL 3 34.73.165.217 GET /__vite_rsc_findSourceMapURL?file ...
show more
21/Sep/26 07:24:39 #4824829 CRITICAL 3 34.73.165.217 GET /__vite_rsc_findSourceMapURL?filename=file:///proc/self/environ&environmentName=rsc - Local file inclusion - [GET:filename = file:///proc/self/environ] - www.milpitas-ca-homes-and-real-estate.com
21/Sep/26 07:24:39 #8516115 CRITICAL 520 34.73.165.217 GET /__vite_rsc_findSourceMapURL?filename=file:///root/.aws/credentials&environmentName=rsc - Data URI scheme or PHP wrappers - [GET:filename = file:///root/.aws/credentials] - www.milpitas-ca-homes-and-real-estate.com
21/Sep/26 07:24:39 #7314422 CRITICAL 520 34.73.165.217 GET /__vite_rsc_findSourceMapURL?filename=file:///app/.env&environmentName=rsc - Data URI scheme or PHP wrappers - [GET:filename = file:///app/.env] - www.milpitas-ca-homes-and-real-estate.com
show less
Hacking
๐ฒ๐ฝ
octageeks.com
2026-09-22 04:20:30
(2 days ago)
Wordpress malicious attack:[octablocked]
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 01:38:00
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.73.165.217 (217.165.73.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.73.165.217 (217.165.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 21:37:55.783548 2026] [security2:error] [pid 31608:tid 31608] [client 34.73.165.217:53622] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "seacorre.com"] [uri "/.env"] [unique_id "arHb898QNbWUp1lHJTSzPAAAADs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
thieuleu
2026-09-22 01:20:16
(2 days ago)
Unauthorized connection attempt blocked by firewall policy. Web application hardening active.
Brute-Force
Exploited Host
๐บ๐ธ
TPI-Abuse
2026-09-22 00:58:06
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.73.165.217 (217.165.73.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.73.165.217 (217.165.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 20:58:02.915024 2026] [security2:error] [pid 30633:tid 30746] [client 34.73.165.217:49932] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.nelsonyung.com|F|2"] [data ".nelsonyung.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.nelsonyung.com"] [uri "/z9x8c7v6b5-debug-trigger-mail.nelsonyung.com"] [unique_id "arHSmsbHdU-pqdnv8ZJHDgAAAQc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-09-22 00:43:41
(2 days ago)
csagent: score 21.5: 404 noise floor x6, secrets grab x2; 1 domain(s) in 1s
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 00:22:07
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.73.165.217 (217.165.73.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.73.165.217 (217.165.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 20:22:01.853511 2026] [security2:error] [pid 22845:tid 22845] [client 34.73.165.217:42496] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pioneercanadian.com"] [uri "/.env.local"] [unique_id "arHKKcFSCF2chUJAoCML0gAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 22:57:34
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.73.165.217 (217.165.73.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.73.165.217 (217.165.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 18:57:26.215603 2026] [security2:error] [pid 22176:tid 22176] [client 34.73.165.217:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.sportsbookcommission.com"] [uri "/.git/config"] [unique_id "arG2Vjxf8fRn_XK3AQIAvwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-09-21 22:24:07
(2 days ago)
[TueSep2200:24:03.1688582026][security2:error][pid4071033:tid4071118][client34.73.165.217:0]ModSecur ...
show more
[TueSep2200:24:03.1688582026][security2:error][pid4071033:tid4071118][client34.73.165.217:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Matchedphrase\"proc/self/\"atARGS:0.[file\"/etc/apache2/conf.d/modsec_rules/10_asl_rules.conf\"][line\"135\"][id\"344360\"][rev\"5\"][msg\"Atomicorp.comWAFRules:UnauthorizedOperatingSystemFileAccessAttempt\"][data\"MatchedData:proc/self/foundwithinARGS:0:{\\\\x22then\\\\x22:\\\\x22\$1:__proto__:then\\\\x22\,\\\\x22status\\\\x22:\\\\x22resolved_model\\\\x22\,\\\\x22reason\\\\x22:-1\,\\\\x22value\\\\x22:\\\\x22{/\\\\x22then/\\\\x22:/\\\\x22\$b1337/\\\\x22}\\\\x22\,\\\\x22_response\\\\x22:{\\\\x22_prefix\\\\x22:\\\\x22process.mainmodule.require\(\'child_process\'\).execsync\(\'env2\>/dev/null\|\|cat/proc/self/environ2\>/dev/null\'\)\;\\\\x22\,\\\\x22_formdata\\\\x22:{\\\\x22get\\\\x22:\\\\x22\$1:constructor:constructor\\\\x22}}}\"][severity\"CRITICAL\"][tag\"attack-lfi\"][hostname\"www.modularss.com\"][uri\"/\"][unique_id\"arGugxm1outrmfCwQb1CVgAAAJQ\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 21:29:53
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.73.165.217 (217.165.73.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.73.165.217 (217.165.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 17:29:48.255164 2026] [security2:error] [pid 692:tid 692] [client 34.73.165.217:52870] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.silsby.com"] [uri "/.git/config"] [unique_id "arGhzNPZgqs98DNr__OjOgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 20:43:18
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.73.165.217 (217.165.73.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.73.165.217 (217.165.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 16:43:14.144977 2026] [security2:error] [pid 25524:tid 25524] [client 34.73.165.217:59284] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.nealandmichaeledesign.com|F|2"] [data ".nealandmichaeledesign.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.nealandmichaeledesign.com"] [uri "/z9x8c7v6b5-debug-trigger-autodiscover.nealandmichaeledesign.com"] [unique_id "arGW4r7WLnvyimTCxzibdQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 19:28:47
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.73.165.217 (217.165.73.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.73.165.217 (217.165.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 15:28:41.751229 2026] [security2:error] [pid 16353:tid 16353] [client 34.73.165.217:34504] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.rallyegroup.com"] [uri "/api/v1/.env"] [unique_id "arGFaUd2jw4-YGe-o2nYqQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
oja
2026-09-21 18:29:32
(2 days ago)
Aggressive web scanner
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-21 18:21:22
(2 days ago)
20 attempts against mh_ha-misbehave-ban on ec102950
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 18:20:09
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.73.165.217 (217.165.73.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.73.165.217 (217.165.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 14:20:03.127075 2026] [security2:error] [pid 6616:tid 6616] [client 34.73.165.217:60718] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.prcomputersolutions.com"] [uri "/.git/HEAD"] [unique_id "arF1UzqI1HXLAqqFQl1TUwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack