πΊπΈ
julianalee.com
2026-09-22 18:00:00
(1 hour ago)
1/Sep/26 08:38:45 #5444085 CRITICAL 1 34.75.234.236 GET /api/console/api_server?sense_vers ...
show more
1/Sep/26 08:38:45 #5444085 CRITICAL 1 34.75.234.236 GET /api/console/api_server?sense_version=%40%40SENSE_VERSION&apis=../../../../../../proc/self/environ - Directory traversal #1 - [GET:apis = ../../../../../../proc/self/environ] - south-san-francisco-ca-homes-and-real-estate.com
21/Sep/26 07:02:41 #3281734 CRITICAL 520 34.75.234.236 GET /__vite_rsc_findSourceMapURL?filename=file:///app/.env&environmentName=rsc - Data URI scheme or PHP wrappers - [GET:filename = file:///app/.env] - sunnyvale-ca-real-estate-and-homes.com
21/Sep/26 07:02:41 #8823227 CRITICAL 520 34.75.234.236 GET /__vite_rsc_findSourceMapURL?filename=file:///root/.aws/credentials&environmentName=rsc - Data URI scheme or PHP wrappers - [GET:filename = file:///root/.aws/credentials] - sunnyvale-ca-real-estate-and-homes.com
show less
Hacking
π²π½
octageeks.com
2026-09-22 04:17:29
(15 hours ago)
Wordpress malicious attack:[octablocked]
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-22 01:36:41
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.75.234.236 (236.234.75.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.75.234.236 (236.234.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 21:36:33.358421 2026] [security2:error] [pid 23830:tid 23830] [client 34.75.234.236:56306] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.pointillistic.com"] [uri "/backend/.env"] [unique_id "arHboa1QCrMFpJ4zINXx7wAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΏπ¦
conure.sh
2026-09-22 00:46:21
(18 hours ago)
csagent: score 20.2: secrets grab x2, 404 noise floor x1; 1 domain(s) in 1s
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-22 00:20:31
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.75.234.236 (236.234.75.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.75.234.236 (236.234.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 20:20:27.271444 2026] [security2:error] [pid 10449:tid 10449] [client 34.75.234.236:59030] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.sixsensehealing.com"] [uri "/server/.env"] [unique_id "arHJyyIFKxw9j1P9AGJWiQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 22:52:24
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.75.234.236 (236.234.75.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.75.234.236 (236.234.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 18:52:20.067286 2026] [security2:error] [pid 19029:tid 19029] [client 34.75.234.236:37388] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.snowrideadventures.com"] [uri "/config/.env"] [unique_id "arG1JNOiTckSVnJW3Js5zQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π²πΎ
Rizzy
2026-09-21 21:50:17
(21 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 20:17:24
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.75.234.236 (236.234.75.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.75.234.236 (236.234.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 16:17:19.951365 2026] [security2:error] [pid 1730:tid 1730] [client 34.75.234.236:37206] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.seshafting.com"] [uri "/.env.local"] [unique_id "arGQz_W5Z9zrlaXN0rx-_gAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 19:18:58
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.75.234.236 (236.234.75.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.75.234.236 (236.234.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 15:18:50.959212 2026] [security2:error] [pid 7273:tid 7273] [client 34.75.234.236:56702] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.rimworld.com|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.rimworld.com"] [uri "/host.key"] [unique_id "arGDGjKDU9ezsd7s4GVRIwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
rsa
2026-09-21 17:54:00
(1 day ago)
GET /functionRouter/ HTTP/1.1
DDoS Attack
Exploited Host
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 17:35:23
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.75.234.236 (236.234.75.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.75.234.236 (236.234.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 13:35:19.552550 2026] [security2:error] [pid 23864:tid 23864] [client 34.75.234.236:59434] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.pelicancovecondo.com"] [uri "/.env_1"] [unique_id "arFq17CrOiIshkHvnDJuygAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-21 16:45:33
(1 day ago)
Blocked by ModSec and CSF
Port Scan
πΊπΈ
TPI-Abuse
2026-09-21 16:35:59
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.75.234.236 (236.234.75.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.75.234.236 (236.234.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 12:35:52.588464 2026] [security2:error] [pid 26794:tid 26794] [client 34.75.234.236:33942] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "texasfurnitureinc.com"] [uri "/.git/config"] [unique_id "arFc6DyhIrKIC35lYBKetgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 15:36:56
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.75.234.236 (236.234.75.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.75.234.236 (236.234.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 11:36:52.785884 2026] [security2:error] [pid 10918:tid 10918] [client 34.75.234.236:46280] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||serpentstudios.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "serpentstudios.com"] [uri "/z9x8c7v6b5-debug-trigger-serpentstudios.com"] [unique_id "arFPFCCmu8lhOMaX9jRAXgAAADc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 15:12:58
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.75.234.236 (236.234.75.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.75.234.236 (236.234.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 11:12:52.816744 2026] [security2:error] [pid 8954:tid 8954] [client 34.75.234.236:46834] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||southernreader.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "southernreader.com"] [uri "/z9x8c7v6b5-debug-trigger-southernreader.com"] [unique_id "arFJdMmO8L6Ho6QJzS57uwAAADs"]
show less
Brute-Force
Bad Web Bot
Web App Attack