🇺🇸
TPI-Abuse
2026-09-06 18:49:41
(48 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.78.225.249 (249.225.78.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.78.225.249 (249.225.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 14:49:34.215712 2026] [security2:error] [pid 23445:tid 23445] [client 34.78.225.249:42280] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "morninginc.com"] [uri "/.svn/entries"] [unique_id "ap21vnS6pM5EAxsSgtAwJwAAACo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Lino Project
2026-09-06 18:30:06
(1 hour ago)
34.78.225.249 - - [06/Sep/2026:20:30:04 +0200] "GET /.env.production?import&raw HTTP/1.1" 404 5611 " ...
show more
34.78.225.249 - - [06/Sep/2026:20:30:04 +0200] "GET /.env.production?import&raw HTTP/1.1" 404 5611 "-" "Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)"
34.78.225.249 - - [06/Sep/2026:20:30:04 +0200] "GET /.env.production?raw HTTP/1.1" 404 5611 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
Celtic
2026-09-06 17:25:54
(2 hours ago)
Blocked by Fail2Ban with Jail (plesk-modsecurity)
Brute-Force
SSH
Anonymous
2026-09-06 16:41:16
(2 hours ago)
Multiple web server 400 error codes from same source ip
Web App Attack
🇫🇮
pixiekat
2026-09-06 15:56:53
(3 hours ago)
[Sun Sep 06 16:56:47.604364 2026] [security2:error] [pid 879349:tid 879363] [remote 34.78.225.249:54 ...
show more
[Sun Sep 06 16:56:47.604364 2026] [security2:error] [pid 879349:tid 879363] [remote 34.78.225.249:54424] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/etc/apache2/modsecurity-crs/coreruleset/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.29.0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "katy.devilishseraph.net"] [uri "/"] [unique_id "ap2NP_SyZ4tUOxcvE1BEWgAAQgw"], referer: http://katy.devilishseraph.net/
[Sun Sep 06 16:56:50.770596 2026] [security2:error] [pid 879349:tid 879365] [remote 34.78.225.249:54424] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/etc/apache2/modsecurity-crs/coreruleset/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_C
...
show less
Web App Attack
🇺🇦
URAN Publishing Service
2026-09-06 15:22:15
(4 hours ago)
[06/Sep/2026:18:22:14 +0300] -- 34.78.225.249 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET / ...
show more
[06/Sep/2026:18:22:14 +0300] -- 34.78.225.249 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /assets/manifest.json HTTP/1.1
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 14:37:47
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.78.225.249 (249.225.78.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.78.225.249 (249.225.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 10:37:41.761572 2026] [security2:error] [pid 4915:tid 5027] [client 34.78.225.249:53084] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "moidawg.gg"] [uri "/userfiles"] [unique_id "ap16tSTcAg0Rw0v8Kj2PEwAAARc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Alboweb B.V.
2026-09-06 14:11:05
(5 hours ago)
Bad web bot activity detected by Fail2Ban in plesk-apache-badbot jail
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-06 14:02:13
(5 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.78.225.249 (249.225.78.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.78.225.249 (249.225.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 10:02:07.543978 2026] [security2:error] [pid 30684:tid 30684] [client 34.78.225.249:40898] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||modestosoftwater.com|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "modestosoftwater.com"] [uri "/ssl/server.key"] [unique_id "ap1yXy-bRxZ3YNAuJYZkfAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 11:57:36
(7 hours ago)
[ns41.kdns.gr] httpd-config-scan: sites=www.monastiria.gr; logs=/var/log/httpd/domains/monastiria.gr ...
show more
[ns41.kdns.gr] httpd-config-scan: sites=www.monastiria.gr; logs=/var/log/httpd/domains/monastiria.gr.log; samples=/@fs/src/.env?raw?? | /@fs/..%252f..%252f..%252f..%252f..%252froot/.env?raw?? | /@fs/../.env?raw??
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 10:42:14
(8 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.78.225.249 (249.225.78.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.78.225.249 (249.225.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 06:42:11.464154 2026] [security2:error] [pid 306:tid 306] [client 34.78.225.249:57052] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mofcolorado.com.mykelmilur.com|F|2"] [data ".com.mykelmilur.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mofcolorado.com.mykelmilur.com"] [uri "/z9x8c7v6b5-debug-trigger-mofcolorado.com.mykelmilur.com"] [unique_id "ap1Dg-TPPHOm3E1eh4GWcAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 10:17:33
(9 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-06 08:44:27
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.78.225.249 (249.225.78.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.78.225.249 (249.225.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 04:44:21.287375 2026] [security2:error] [pid 10766:tid 10900] [client 34.78.225.249:51956] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "moderncabinetcorp.com"] [uri "/static//home/user/.env"] [unique_id "ap0n5Ux-o8Ys5f7FgphT-gAAAUc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-06 08:02:13
(11 hours ago)
Multiple WAF Violations
Web App Attack
🇳🇱
Savvii
2026-09-06 07:43:43
(11 hours ago)
20 attempts against mh-misbehave-ban on moon
Brute-Force
Bad Web Bot
Web App Attack