๐บ๐ธ
julianalee.com
2026-09-22 17:55:00
(3 days ago)
21/Sep/26 08:17:25 #3080151 CRITICAL 520 34.73.236.224 GET /__vite_rsc_findSourceMapURL?file ...
show more
21/Sep/26 08:17:25 #3080151 CRITICAL 520 34.73.236.224 GET /__vite_rsc_findSourceMapURL?filename=file:///root/.ssh/id_rsa&environmentName=rsc - Data URI scheme or PHP wrappers - [GET:filename = file:///root/.ssh/id_rsa] - mail.sunnyvale-homes-for-sale-and-real-estate.com
21/Sep/26 08:17:25 #6643170 CRITICAL 520 34.73.236.224 GET /__vite_rsc_findSourceMapURL?filename=file:///root/.aws/credentials&environmentName=rsc - Data URI scheme or PHP wrappers - [GET:filename = file:///root/.aws/credentials] - mail.sunnyvale-homes-for-sale-and-real-estate.com
21/Sep/26 08:17:26 #7592649 CRITICAL 520 34.73.236.224 GET /__vite_rsc_findSourceMapURL?filename=file:///app/.env&environmentName=rsc - Data URI scheme or PHP wrappers - [GET:filename = file:///app/.env] - mail.sunnyvale-homes-for-sale-and-real-estate.com
show less
Hacking
๐ฟ๐ฆ
conure.sh
2026-09-22 12:04:54
(3 days ago)
csagent: score 21.1: 404 noise floor x5, secrets grab x2; 1 domain(s) in 11s
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-22 01:50:23
(3 days ago)
Excessive 404/403 errors
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-22 00:39:04
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.73.236.224 (224.236.73.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.73.236.224 (224.236.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 20:39:00.187914 2026] [security2:error] [pid 662:tid 662] [client 34.73.236.224:46690] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.utahproaudio.com"] [uri "/.env.bak"] [unique_id "arHOJM6Zn3q0hj7KXC2rVAAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 00:08:55
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.73.236.224 (224.236.73.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.73.236.224 (224.236.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 20:08:50.037728 2026] [security2:error] [pid 1802:tid 1802] [client 34.73.236.224:45960] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.tenmenband.com"] [uri "/frontend/.env"] [unique_id "arHHEvLYARZ31qeBxDHbmwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
CoreTech srl
2026-09-21 23:28:57
(3 days ago)
cloudlinux2 fail2ban: 2026-09-22 01:25:31,444 fail2ban.actions [1598]: NOTICE [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-22 01:25:31,444 fail2ban.actions [1598]: NOTICE [plesk-modsecurity] Unban 45.138.12.43cloudlinux2 fail2ban: 2026-09-22 01:26:00,093 fail2ban.actions [1598]: NOTICE [plesk-modsecurity] Unban 34.101.79.138cloudlinux2 fail2ban: 2026-09-22 01:26:45,099 fail2ban.filter [1598]: INFO [plesk-modsecurity] Found 34.73.236.224 - 2026-09-22 01:26:45cloudlinux2 fail2ban: 2026-09-22 01:26:45,259 fail2ban.filter [1598]: INFO [plesk-modsecurity] Found 34.73.236.224 - 2026-09-22 01:26:45cloudlinux2 fail2ban: 2026-09-22 01:26:45,361 fail2ban.actions [1598]: NOTICE [plesk-modsecurity] Ban 34.73.236.224cloudlinux2 fail2ban: 2026-09-22 01:26:44,848 fail2ban.filter [1598]: INFO [plesk-modsecurity] Found 34.73.236.224 - 2026-09-22 01:26:44cloudlinux2 fail2ban: 2026-09-22 01:26:44,962 fail2ban.filter [1598]: INFO [plesk-modsecurity] Found 34.73.236.224 - 2026-09-22 01:26:44cloudlinux2 fail2ban: 2026-09-22 01:26:45,364 fail2ban.filter
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-21 21:54:54
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.73.236.224 (224.236.73.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.73.236.224 (224.236.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 17:54:49.460829 2026] [security2:error] [pid 9790:tid 9790] [client 34.73.236.224:34288] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.technesa.com"] [uri "/.git/HEAD"] [unique_id "arGnqdTLtrP3Zb2dmwcuxQAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 21:15:43
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.73.236.224 (224.236.73.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.73.236.224 (224.236.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 17:15:37.896532 2026] [security2:error] [pid 21540:tid 21540] [client 34.73.236.224:57974] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.stricklinphotography.com"] [uri "/.env"] [unique_id "arGeeVYMpkx_8g6qBUQPFgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 19:30:56
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 34.73.236.224 (224.236.73.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.73.236.224 (224.236.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 15:30:51.474966 2026] [security2:error] [pid 26814:tid 26814] [client 34.73.236.224:45646] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||stkm.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "stkm.com"] [uri "/z9x8c7v6b5-debug-trigger-stkm.com"] [unique_id "arGF67TK6X4J9nbPOFfHdgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 18:46:46
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.73.236.224 (224.236.73.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.73.236.224 (224.236.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 14:46:39.187349 2026] [security2:error] [pid 568414:tid 568414] [client 34.73.236.224:54090] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.zenithxen.com"] [uri "/.git/config"] [unique_id "arF7j06erjCR2yUokC-HQwAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 17:44:19
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.73.236.224 (224.236.73.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.73.236.224 (224.236.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 13:44:11.466380 2026] [security2:error] [pid 29840:tid 29840] [client 34.73.236.224:39832] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.tech-servusa.com"] [uri "/.git/HEAD"] [unique_id "arFs6y8lRwQA65Zn1FER2wAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 16:46:06
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 34.73.236.224 (224.236.73.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.73.236.224 (224.236.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 12:45:56.401045 2026] [security2:error] [pid 4766:tid 4766] [client 34.73.236.224:51144] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.taschstudios.com|F|2"] [data ".taschstudios.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.taschstudios.com"] [uri "/z9x8c7v6b5-debug-trigger-autodiscover.taschstudios.com"] [unique_id "arFfRDkAfqThxm8tGQj8ewAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 15:32:26
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.73.236.224 (224.236.73.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.73.236.224 (224.236.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 11:32:21.946667 2026] [security2:error] [pid 10831:tid 10831] [client 34.73.236.224:39730] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.thepianosmith.com"] [uri "/%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env"] [unique_id "arFOBYUJCXS1gCrZR-BoTQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Mundo Bueno
2026-09-21 15:29:02
(4 days ago)
[ISILIA Protection v2.3] Tentative d'accรจs: /public/.env [RATE LIMITED - 1800s quarantine] | Pays: U ...
show more
[ISILIA Protection v2.3] Tentative d'accรจs: /public/.env [RATE LIMITED - 1800s quarantine] | Pays: US | UA: Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 15:15:59
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 34.73.236.224 (224.236.73.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.73.236.224 (224.236.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 11:15:53.424377 2026] [security2:error] [pid 24269:tid 24269] [client 34.73.236.224:54906] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.swampoodlegrounds.com|F|2"] [data ".swampoodlegrounds.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.swampoodlegrounds.com"] [uri "/z9x8c7v6b5-debug-trigger-mail.swampoodlegrounds.com"] [unique_id "arFKKR5nHABlGG6kMylo-gAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack