🇺🇸
TPI-Abuse
2026-09-19 10:02:57
(13 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.75.115.200 (200.115.75.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.75.115.200 (200.115.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 06:02:52.155000 2026] [security2:error] [pid 32628:tid 32628] [client 34.75.115.200:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.psychoclast.com"] [uri "/.git/config"] [unique_id "aq5dzNuPnY-vNS0c8L3x0gAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-19 09:44:49
(31 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.75.115.200 (200.115.75.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.75.115.200 (200.115.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 05:44:43.623785 2026] [security2:error] [pid 4042:tid 4042] [client 34.75.115.200:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.pixacast.com"] [uri "/@fs/app/.env"] [unique_id "aq5Ziy5ZIP4rJMFGQZwRpAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇿🇦
conure.sh
2026-09-19 09:21:02
(55 minutes ago)
csagent: score 20.2: secrets grab x2, 404 noise floor x1; 1 domain(s) in 2s
Web App Attack
🇮🇹
VHosting
2026-09-19 08:50:03
(1 hour ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇲🇾
Rizzy
2026-09-19 08:19:05
(1 hour ago)
Multiple WAF Violations
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-19 08:18:15
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.75.115.200 (200.115.75.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.75.115.200 (200.115.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 04:18:07.454488 2026] [security2:error] [pid 24408:tid 24440] [client 34.75.115.200:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.mindgardens.com"] [uri "/@fs/src/.env"] [unique_id "aq5FP68i-0wx7Nlv1EQ4zgAAAUE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-19 03:59:30
(6 hours ago)
Aggressive web scan
Web App Attack
🇬🇧
oja
2026-09-18 22:41:18
(11 hours ago)
Aggressive web scanner
Web App Attack
🇺🇸
TPI-Abuse
2026-09-18 22:40:54
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.75.115.200 (200.115.75.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.75.115.200 (200.115.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 18:40:47.936801 2026] [security2:error] [pid 28498:tid 28498] [client 34.75.115.200:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "blog.nyemdr.com"] [uri "/@fs/app/.env"] [unique_id "aq297_CXwgfaRj8FCe4MsgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
CoreTech srl
2026-09-18 05:58:40
(1 day ago)
[DC: IP:151.1.252.27] ntopng alert: blacklisted_client_contact,ndpi_tcp_issues,ndpi_probing_attempt
Hacking
🇲🇽
octageeks.com
2026-09-18 04:08:37
(1 day ago)
Wordpress malicious attack:[octablocked]
Web App Attack
🇪🇸
robotstxt
2026-09-18 00:22:19
(1 day ago)
34.75.115.200 - - [18/Sep/2026:00:22:14 +0000] "GET /key.pem HTTP/2.0" 403 13410 "-" "Mozilla/5.0 (c ...
show more
34.75.115.200 - - [18/Sep/2026:00:22:14 +0000] "GET /key.pem HTTP/2.0" 403 13410 "-" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" "-" edge="34.75.115.200"
34.75.115.200 - - [18/Sep/2026:00:22:14 +0000] "GET /z9x8c7v6b5-debug-trigger-campus.economipedia.com HTTP/2.0" 403 13420 "-" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)" "-" edge="34.75.115.200"
34.75.115.200 - - [18/Sep/2026:00:22:15 +0000] "GET /privatekey.key HTTP/2.0" 403 13420 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" "-" edge="34.75.115.200"
34.75.115.200 - - [18/Sep/2026:00:22:15 +0000] "GET /dist/manifest.json HTTP/2.0" 403 12919 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36" "-" edge="34.75.115.200"
34.75.115.200 - - [18/Sep/2026:00:22:15 +0000] "GET /webpack-stats.json HTTP/2.0" 403 12900 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.
...
show less
Web App Attack
🇫🇷
SpaceHost-Server
2026-09-17 22:21:33
(1 day ago)
Brute-Force
Web App Attack
Anonymous
2026-09-17 22:15:27
(1 day ago)
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: US, Attack patterns: Word ...
show more
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: US, Attack patterns: WordPress scanning, Backup file probing, Cloud secrets probing
show less
Bad Web Bot
Web App Attack
🇩🇪
macrob
2026-09-17 17:29:43
(1 day ago)
2026/09/17 17:29:41 [error] 3435314#3435314: *8914742 access forbidden by rule, client: 34.75.115.20 ...
show more
2026/09/17 17:29:41 [error] 3435314#3435314: *8914742 access forbidden by rule, client: 34.75.115.200, server: fn.binixo.es, request: "GET /.bashrc HTTP/2.0", host: "app.fastcredit.net.ua"
2026/09/17 17:29:41 [error] 3435314#3435314: *8914747 access forbidden by rule, client: 34.75.115.200, server: fn.binixo.es, request: "GET /dist/.vite/manifest.json HTTP/2.0", host: "app.fastcredit.net.ua"
2026/09/17 17:29:41 [error] 3435314#3435314: *8914751 access forbidden by rule, client: 34.75.115.200, server: fn.binixo.es, request: "GET /.vite/manifest.json HTTP/2.0", host: "app.fastcredit.net.ua"
...
show less
Web App Attack