πΊπΈ
TPI-Abuse
2026-08-29 06:57:43
(51 seconds ago)
(mod_security) mod_security (id:210492) triggered by 34.77.35.249 (249.35.77.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.77.35.249 (249.35.77.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 02:57:36.800718 2026] [security2:error] [pid 10325:tid 10325] [client 34.77.35.249:43032] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.peaksalesnw.com"] [uri "/@fs/root/.env"] [unique_id "apKC4NWt1T15xeFAaSRkBQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
masterguru
2026-08-29 06:51:29
(7 minutes ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.77.35.249 (BE/Belgium/249.35.77.34 ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.77.35.249 (BE/Belgium/249.35.77.34.bc.googleusercontent.com): 2 in the last 3600 secs (0-196)
show less
Hacking
πΊπΈ
TPI-Abuse
2026-08-29 06:25:45
(32 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.77.35.249 (249.35.77.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.77.35.249 (249.35.77.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 02:25:38.513174 2026] [security2:error] [pid 479:tid 479] [client 34.77.35.249:34614] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.loveoflearning.com"] [uri "/@fs/.env"] [unique_id "apJ7YgNID94cv5fqba-QtAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-29 05:43:20
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.77.35.249 (249.35.77.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.77.35.249 (249.35.77.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 01:43:16.400073 2026] [security2:error] [pid 3486:tid 3486] [client 34.77.35.249:59528] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.mathgen.com"] [uri "/@fs/.env"] [unique_id "apJxdGi1ysn8g61VCzHv8gAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΏπ¦
conure.sh
2026-08-29 05:26:39
(1 hour ago)
csagent: score 20.8: 404 noise floor x3, secrets grab x2; 1 domain(s) in 5s
Web App Attack
π«π·
Feelautom
2026-08-29 04:52:19
(2 hours ago)
[FeelAutom Auto-Ban] BotIdentityRotation: /@fs/etc/passwd?raw?? (Score: 220)
Hacking
π«π·
dynamix
2026-08-29 04:43:39
(2 hours ago)
Multiple WAF Violations
Web App Attack
π§πΎ
lns.bz
2026-08-29 04:40:50
(2 hours ago)
Too many 404 requests [BY]
Web App Attack
π³πΏ
Antinson
2026-08-29 04:31:59
(2 hours ago)
Scraping with a high error ratio and request rate
Bad Web Bot
π«π·
masterguru
2026-08-29 04:24:51
(2 hours ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.77.35.249 (BE/Belgium/249.35.77.34 ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.77.35.249 (BE/Belgium/249.35.77.34.bc.googleusercontent.com): 1 in the last 3600 secs (0-195)
show less
Hacking
πΊπΈ
TPI-Abuse
2026-08-29 04:10:46
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.77.35.249 (249.35.77.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.77.35.249 (249.35.77.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 00:10:42.471091 2026] [security2:error] [pid 23399:tid 23399] [client 34.77.35.249:6302] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.steinrauffamilylaw.com"] [uri "/@fs/src/.env"] [unique_id "apJbwjettwoeZyBMw3Z0gwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
Hary74656
2026-08-29 03:41:36
(3 hours ago)
Fail2Ban on schani.hostmi.at: jail=apache-modsecurity, failures=3. No raw log data included.
Web App Attack
πΊπΈ
kosada.com
2026-08-29 02:53:31
(4 hours ago)
Web bot: DDoS
DDoS Attack
Bad Web Bot
π©πͺ
FeG Deutschland
2026-08-29 02:19:39
(4 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 127
Exploited Host
Web App Attack
π¨π
zynex
2026-08-29 01:54:36
(5 hours ago)
URL Probing: /@fs/home/ubuntu/.env
Web App Attack