🇸🇪
vaia.cloud
2026-09-08 03:30:02
(47 minutes ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 03:23:38
(53 minutes ago)
(mod_security) mod_security (id:243420) triggered by 34.79.170.118 (118.170.79.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:243420) triggered by 34.79.170.118 (118.170.79.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 23:23:32.720951 2026] [security2:error] [pid 13182:tid 13182] [client 34.79.170.118:43584] ModSecurity: Access denied with code 403 (phase 3). Match of "validateByteRange 0-31" against "ARGS:raw??" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6640"] [id "243420"] [rev "4"] [msg "COMODO WAF: Information disclosure vulnerability in Eclipse Jetty before 9.2.9.v20150224 (CVE-2015-2080)||hi-niemczuras.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "hi-niemczuras.net"] [uri "/.env"] [unique_id "ap9_tDz_SNBJKx4LA4J9eAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 02:58:36
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.79.170.118 (118.170.79.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.79.170.118 (118.170.79.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 22:58:30.215730 2026] [security2:error] [pid 4444:tid 4444] [client 34.79.170.118:29626] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.customhumanrobots.com"] [uri "/@fs/root/.env"] [unique_id "ap951j4b2FDqDpX9XPNxzAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
maxpower
2026-09-08 02:47:45
(1 hour ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.79.170.118 (BE/Belgium/118.170.79.34. ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.79.170.118 (BE/Belgium/118.170.79.34.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.79.170.118 - - [08/Sep/2026:04:47:44 +0200] "GET /@fs/root/.aws/credentials?raw?? HTTP/1.1" 200 12196 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_6_1) AppleWebKit/537.36 (KHTML, like Gecko; compatible; GrokBot/1.0; +https://x.ai/grokbot) Chrome/131.0.2555.25 Safari/537.36 Edg/131.0.2555.25" "-" host=mlocale.com
show less
Port Scan
🇺🇸
TPI-Abuse
2026-09-08 02:38:00
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.79.170.118 (118.170.79.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.79.170.118 (118.170.79.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 22:37:53.985945 2026] [security2:error] [pid 30512:tid 30512] [client 34.79.170.118:34078] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.ingberinteriors.com"] [uri "/@fs/src/.env"] [unique_id "ap91AWDaaU0BPeK5Yf5mnwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 02:20:32
(1 hour ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇫🇷
COMAITE
2026-09-08 01:32:39
(2 hours ago)
Common web attack from 34.79.170.118.
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 01:29:52
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.79.170.118 (118.170.79.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.79.170.118 (118.170.79.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 21:29:47.964432 2026] [security2:error] [pid 10423:tid 10423] [client 34.79.170.118:32808] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.rcto.us"] [uri "/@fs/root/.env"] [unique_id "ap9lC8xnxhX7UypsUQna9gAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 01:12:38
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.79.170.118 (118.170.79.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.79.170.118 (118.170.79.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 21:12:34.362202 2026] [security2:error] [pid 23126:tid 23126] [client 34.79.170.118:39978] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.spiritofacorn.com"] [uri "/@fs/.env"] [unique_id "ap9hAgw6kWUmHlJDQEHMbQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FD-IX
2026-09-08 00:35:50
(3 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇨🇭
backslash
2026-09-08 00:12:00
(4 hours ago)
block ruleset bad bot: misc bad content F608233CC4C86EE814CE8DDDA9C4A0D3C79882F6
Bad Web Bot
Anonymous
2026-09-08 00:05:12
(4 hours ago)
Aggressive web scan
Web App Attack
🇳🇱
ConsulHosting
2026-09-07 23:56:47
(4 hours ago)
Automatically blocked due to distributed attack
Hacking
🇮🇹
VHosting
2026-09-07 23:50:03
(4 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 23:48:51
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.79.170.118 (118.170.79.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.79.170.118 (118.170.79.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 19:48:43.153723 2026] [security2:error] [pid 32338:tid 32338] [client 34.79.170.118:23718] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.web-sitebuilder.com"] [uri "/@fs/app/.env"] [unique_id "ap9NWyY7PsVRSaJqzWDkYAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack