๐บ๐ธ
TPI-Abuse
2026-09-21 23:57:54
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 34.74.166.4 (4.166.74.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.74.166.4 (4.166.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 19:57:47.668191 2026] [security2:error] [pid 23614:tid 23614] [client 34.74.166.4:57736] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||blackstarmgmt.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "blackstarmgmt.com"] [uri "/z9x8c7v6b5-debug-trigger-blackstarmgmt.com"] [unique_id "arHEe40uCe_a3lBc9-x1JQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
david.houstin
2026-09-21 22:28:18
(1 week ago)
34.74.166.4 - - [22/Sep/2026:00:28:14 +0200] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f% ...
show more
34.74.166.4 - - [22/Sep/2026:00:28:14 +0200] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fproc/self/environ HTTP/2.0" 404 264 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)"
34.74.166.4 - - [22/Sep/2026:00:28:14 +0200] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f.env HTTP/2.0" 404 264 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)"
34.74.166.4 - - [22/Sep/2026:00:28:14 +0200] "GET /uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f.env HTTP/2.0" 404 264 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)"
34.74.166.4 - - [22/Sep/2026:00:28:14 +0200] "GET /admin%2F.env HTTP/2.0" 404 264 "-" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)"
34.74.166.4 - - [22/Sep/2026:00:28:14 +0200] "GET /dashboard%2F.env HTTP/2.0" 404 264 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)"
34.74.166.4 - - [22/Sep/2026:00:28:14 +0200] "GET /api%2F.env HTTP/2.0" 404 264 "-" "Mozilla/5.0 (comp
...
show less
Web App Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-21 22:22:10
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 34.74.166.4 (4.166.74.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.74.166.4 (4.166.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 18:22:06.038146 2026] [security2:error] [pid 14397:tid 14397] [client 34.74.166.4:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||nyemdr.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "nyemdr.com"] [uri "/z9x8c7v6b5-debug-trigger-nyemdr.com"] [unique_id "arGuDsbmGAR4wIaCF6ByJgAAAC0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 19:37:59
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.74.166.4 (4.166.74.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.74.166.4 (4.166.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 15:37:50.953635 2026] [security2:error] [pid 22417:tid 22417] [client 34.74.166.4:41178] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.blanchebb.com"] [uri "/web/.env"] [unique_id "arGHjtbwSlguhtrxN45QgQAAADc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ฌ
Cloudkul Cloudkul
2026-09-21 18:12:42
(1 week ago)
Attempted Brute Force on our application
Brute-Force
Web App Attack
๐บ๐ธ
deskpass.com
2026-09-21 17:19:16
(1 week ago)
GET /login
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 16:23:37
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.74.166.4 (4.166.74.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.74.166.4 (4.166.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 12:23:30.574274 2026] [security2:error] [pid 7977:tid 7977] [client 34.74.166.4:42112] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.huntingforebears.com"] [uri "/css../.env"] [unique_id "arFaAgFSOUAnp63XG1ShqQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-09-21 15:40:08
(1 week ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
interbiznw.com
2026-09-21 15:21:46
(1 week ago)
fail2ban-ban
Hacking
Brute-Force
Exploited Host
Web App Attack
Anonymous
2026-09-21 15:14:04
(1 week ago)
IP matched detection query many 3xx errors.
Brute-Force
Anonymous
2026-09-21 15:07:03
(1 week ago)
Automated web scanner. Requested suspicious paths: /z9x8c7v6b5-debug-trigger-api.tigzig.com. UTC: 20 ...
show more
Automated web scanner. Requested suspicious paths: /z9x8c7v6b5-debug-trigger-api.tigzig.com. UTC: 2026-09-21 14:16:17.
show less
Web App Attack
Anonymous
2026-09-21 14:54:07
(1 week ago)
[ns3.backorder.gr] httpd-config-scan: sites=www.blazos.com; logs=/var/log/httpd/domains/blazos.com.l ...
show more
[ns3.backorder.gr] httpd-config-scan: sites=www.blazos.com; logs=/var/log/httpd/domains/blazos.com.log; samples=/.env | /.env.example | /.env.production
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 14:19:37
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 34.74.166.4 (4.166.74.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.74.166.4 (4.166.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 10:19:30.772677 2026] [security2:error] [pid 16592:tid 16592] [client 34.74.166.4:48930] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||blackjobsnetwork.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "blackjobsnetwork.com"] [uri "/z9x8c7v6b5-debug-trigger-blackjobsnetwork.com"] [unique_id "arE88qmTQs8_OIdYQYEwwwAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-21 14:15:48
(1 week ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐ซ๐ท
dusfor72
2026-09-21 13:57:13
(1 week ago)
stupid access attempts on non-existant files
...
Brute-Force
Web App Attack