๐ง๐ช
sid3windr
2026-09-23 02:50:23
(2 days ago)
GET //.env (Tarpitted for 1d15h8m26s, wasted 8.06MB)
Web App Attack
๐ซ๐ฎ
robotstxt
2026-09-22 01:01:36
(3 days ago)
34.78.76.255 - - [22/Sep/2026:01:00:42 +0000] "GET /.git/config HTTP/2.0" 403 33021 "-" rt="2.699" " ...
show more
34.78.76.255 - - [22/Sep/2026:01:00:42 +0000] "GET /.git/config HTTP/2.0" 403 33021 "-" rt="2.699" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)" "-" edge="34.78.76.255" h="directorio.componentescalzado.com" sn="directorio.componentescalzado.com" ru="/.git/config" u="/index.php" ucs="-" ua="unix:/var/run/php/ccalzadodir82.sock" us="404" uct="0.000" urt="2.699"
34.78.76.255 - - [22/Sep/2026:01:00:45 +0000] "GET /.aws/credentials HTTP/2.0" 403 33028 "-" rt="5.570" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)" "-" edge="34.78.76.255" h="directorio.componentescalzado.com" sn="directorio.componentescalzado.com" ru="/.aws/credentials" u="/index.php" ucs="-" ua="unix:/var/run/php/ccalzadodir82.sock" us="404" uct="0.000" urt="5.571"
34.78.76.255 - - [22/Sep/2026:01:00:45 +0000] "GET /.git/HEAD HTTP/2.0" 403 33024 "-" rt="3.190" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)" "-" edge="34.78.76.255" h="directorio.componentescalzado.com" sn="d
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 00:59:42
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.78.76.255 (255.76.78.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.78.76.255 (255.76.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 20:59:37.140780 2026] [security2:error] [pid 23358:tid 23358] [client 34.78.76.255:43244] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dinogirl.com"] [uri "/.env.live"] [unique_id "arHS-YKsLIRF_eMlsjKsbAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 23:27:50
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.78.76.255 (255.76.78.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.78.76.255 (255.76.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 19:27:45.961564 2026] [security2:error] [pid 27403:tid 27403] [client 34.78.76.255:54666] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.digi-estudio.com"] [uri "/.env.local"] [unique_id "arG9cbyyhS2DEHvGI4o6VwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 19:41:06
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.78.76.255 (255.76.78.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.78.76.255 (255.76.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 15:41:01.349200 2026] [security2:error] [pid 2257:tid 2257] [client 34.78.76.255:53404] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.diegogamazo.com"] [uri "/.env.backup"] [unique_id "arGITeTFygdWOM7FsU7PDwAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
maxpower
2026-09-21 14:48:34
(4 days ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.78.76.255 (BE/Belgium/255.76.78.34.bc ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.78.76.255 (BE/Belgium/255.76.78.34.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.78.76.255 - - [21/Sep/2026:16:48:28 +0200] "GET /.ssh/id_rsa HTTP/2.0" 200 12060 "-" "Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)" "-" host=www.mediaqualitylab.com
show less
Port Scan
๐ฎ๐น
VHosting
2026-09-21 14:15:04
(4 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 14:04:10
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.78.76.255 (255.76.78.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.78.76.255 (255.76.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 10:04:05.339065 2026] [security2:error] [pid 26139:tid 26139] [client 34.78.76.255:54054] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.directoryofdiamonds.com"] [uri "/appearance/../../.env"] [unique_id "arE5VXM-fx1rphOKWTNY-gAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2026-09-21 13:48:00
(4 days ago)
block ruleset WAF detection and high score on abuseIPDB 149EB1B42C242111FADBBC2EF8F90219570691E1
Bad Web Bot
Anonymous
2026-09-21 13:47:00
(4 days ago)
XSS Attempt
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-21 13:46:18
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 34.78.76.255 (255.76.78.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.78.76.255 (255.76.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 09:46:11.518300 2026] [security2:error] [pid 9773:tid 9795] [client 34.78.76.255:35426] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||digital4z.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "digital4z.com"] [uri "/z9x8c7v6b5-debug-trigger-digital4z.com"] [unique_id "arE1I-QTzkLohTzNUjoWrAAAAM8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
paissangroup
2026-09-21 13:35:06
(4 days ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-09-21 13:34:36
(4 days ago)
34.78.76.255 - - [21/Sep/2026:21:34:35 +0800] "GET /.env_sample HTTP/1.1" 200 19012 "-" "Mozilla/5.0 ...
show more
34.78.76.255 - - [21/Sep/2026:21:34:35 +0800] "GET /.env_sample HTTP/1.1" 200 19012 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot"
...
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
maxxsense
2026-09-21 13:23:55
(4 days ago)
(mod_security) mod_security triggered on hostname [redacted] 34.78.76.255 (BE/Belgium/255.76.78.34.b ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.78.76.255 (BE/Belgium/255.76.78.34.bc.googleusercontent.com)
show less
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-09-21 13:08:31
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.78.76.255 (255.76.78.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.78.76.255 (255.76.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 09:08:27.839446 2026] [security2:error] [pid 28259:tid 28259] [client 34.78.76.255:54080] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.my-spec.com"] [uri "/wp-config.php.bak"] [unique_id "arEsS5NsiTdU-bPsvp2SsQAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack