🇺🇸
TPI-Abuse
2026-09-06 23:19:17
(53 minutes ago)
(mod_security) mod_security (id:949110) triggered by 34.78.152.66 (66.152.78.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:949110) triggered by 34.78.152.66 (66.152.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 19:19:12.082583 2026] [security2:error] [pid 10873:tid 10873] [client 34.78.152.66:54142] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "crazycontrols.com"] [uri "/rclone.conf"] [unique_id "ap308L5F66UW3AVhmdx_zwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 22:17:48
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.78.152.66 (66.152.78.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.78.152.66 (66.152.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 18:17:43.950019 2026] [security2:error] [pid 24780:tid 24780] [client 34.78.152.66:46464] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.fastr-wellington.com"] [uri "/%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env"] [unique_id "ap3mh5WsITbqSlvSWWbvTwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Séfora Srl
2026-09-06 21:22:20
(2 hours ago)
crowdsecurity/http-bad-user-agent detected by CrowdSec
Bad Web Bot
🇩🇪
big-cloud.nl
2026-09-06 20:46:06
(3 hours ago)
Try to access /css../.env
Web App Attack
🇧🇪
cmbplf
2026-09-06 20:45:27
(3 hours ago)
161 requests with url.path *.ssh/*
Brute-Force
Bad Web Bot
🇩🇪
neckaralb-admin.de
2026-09-06 19:48:34
(4 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇫🇷
dynamix
2026-09-06 19:44:19
(4 hours ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 19:43:17
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.78.152.66 (66.152.78.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.78.152.66 (66.152.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 15:43:09.337871 2026] [security2:error] [pid 5805:tid 5805] [client 34.78.152.66:39612] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aaronbeg.com"] [uri "/@fs/../.env"] [unique_id "ap3CTWjRio8UUReYFt44vgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 18:42:52
(5 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.78.152.66 (66.152.78.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.78.152.66 (66.152.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 14:42:49.401322 2026] [security2:error] [pid 28143:tid 28143] [client 34.78.152.66:46146] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.candlesandwoodcrafts.com|F|2"] [data ".candlesandwoodcrafts.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.candlesandwoodcrafts.com"] [uri "/z9x8c7v6b5-debug-trigger-www.candlesandwoodcrafts.com"] [unique_id "ap20KRUGJ0i1PWDgf2nH9AAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
debestelapp
2026-09-06 18:30:11
(5 hours ago)
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 18:03:43
(6 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.78.152.66 (66.152.78.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.78.152.66 (66.152.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 14:03:39.079524 2026] [security2:error] [pid 10474:tid 10474] [client 34.78.152.66:43026] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.fitzcosound.com|F|2"] [data ".fitzcosound.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.fitzcosound.com"] [uri "/z9x8c7v6b5-debug-trigger-www.fitzcosound.com"] [unique_id "ap2q-5KsT1paODFQTJctzwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇭
zynex
2026-09-06 17:38:43
(6 hours ago)
URL Probing: /@fs/..%252f..%252f..%252f..%252f..%252froot/.env
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 16:58:33
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.78.152.66 (66.152.78.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.78.152.66 (66.152.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 12:58:26.692067 2026] [security2:error] [pid 20226:tid 20226] [client 34.78.152.66:39056] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "frameandsavehydepark.com"] [uri "/_nuxt/../.env"] [unique_id "ap2bsn8HcvebEsfgKCz6QAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
ConsulHosting
2026-09-06 16:54:41
(7 hours ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 16:40:57
(7 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.78.152.66 (66.152.78.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.78.152.66 (66.152.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 12:40:53.584034 2026] [security2:error] [pid 17922:tid 17922] [client 34.78.152.66:39490] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||aares2026.net|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "aares2026.net"] [uri "/server.key"] [unique_id "ap2XlcBvsh-0BaqphxdtqQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack