๐บ๐ธ
TPI-Abuse
2026-09-21 06:20:58
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.80.121.201 (201.121.80.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.121.201 (201.121.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 02:20:54.735125 2026] [security2:error] [pid 29524:tid 29524] [client 34.80.121.201:48498] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "airei.com"] [uri "/admin/.env"] [unique_id "arDMxmOlBl3RvQhMUarFHwAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 04:15:56
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.80.121.201 (201.121.80.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.121.201 (201.121.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 00:15:49.952285 2026] [security2:error] [pid 9396:tid 9396] [client 34.80.121.201:47400] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.artspacecleveland.com"] [uri "/src/.env"] [unique_id "arCvdWmz7PoS03L7-VoQFgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 03:07:36
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.80.121.201 (201.121.80.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.121.201 (201.121.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 23:07:34.073350 2026] [security2:error] [pid 19775:tid 19775] [client 34.80.121.201:35602] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.aliamus.com"] [uri "/appearance/../../.env"] [unique_id "arCfdn5jMi1du4koe1_pkwAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
albionfreemarket.com
2026-09-21 02:56:36
(1 day ago)
34.80.121.201 - - [21/Sep/2026:02:56:35 +0000] "POST /graphql HTTP/2.0" 403 555 "https://albionfreem ...
show more
34.80.121.201 - - [21/Sep/2026:02:56:35 +0000] "POST /graphql HTTP/2.0" 403 555 "https://albionfreemarket.com" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36" 0.000 "-" "TW"
34.80.121.201 - - [21/Sep/2026:02:56:35 +0000] "POST /api/graphql HTTP/2.0" 403 555 "https://albionfreemarket.com" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36" 0.000 "-" "TW"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 02:47:19
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.80.121.201 (201.121.80.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.80.121.201 (201.121.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 22:47:15.908411 2026] [security2:error] [pid 21757:tid 21757] [client 34.80.121.201:50012] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.4starpromotions.com|F|2"] [data ".4starpromotions.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.4starpromotions.com"] [uri "/z9x8c7v6b5-debug-trigger-www.4starpromotions.com"] [unique_id "arCaswrZiuan24Qh7OYc6AAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 01:35:12
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.80.121.201 (201.121.80.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.80.121.201 (201.121.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 21:35:06.977019 2026] [security2:error] [pid 11924:tid 11924] [client 34.80.121.201:47962] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.atlanticcitypartybuses.com|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.atlanticcitypartybuses.com"] [uri "/ssl/localhost.key"] [unique_id "arCJyigRww-psAdRat5z2gAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
Carl
2026-09-21 01:33:10
(1 day ago)
Aggressive web scan
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 00:33:01
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.80.121.201 (201.121.80.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.121.201 (201.121.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 20:32:56.616158 2026] [security2:error] [pid 24826:tid 24826] [client 34.80.121.201:45174] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.179vfs.com"] [uri "/.env.production"] [unique_id "arB7OC0u1ehl-3TKPoZqIQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 00:02:34
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.80.121.201 (201.121.80.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.121.201 (201.121.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 20:02:28.604641 2026] [security2:error] [pid 8432:tid 8432] [client 34.80.121.201:49068] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.abilityimprinting.com"] [uri "/.env.example"] [unique_id "arB0FHCu0MkDrW0XW57CDwAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
Mediashaker
2026-09-21 00:00:08
(1 day ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 34.80.121.201 (TW/Ta ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 34.80.121.201 (TW/Taiwan/201.121.80.34.bc.googleusercontent.com)
show less
Bad Web Bot
๐ฉ๐ช
SCHAPPY
2026-09-20 23:21:28
(1 day ago)
Malicious activity from IP detected: crowdsecurity/http-sensitive-files.
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-20 22:51:14
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.80.121.201 (201.121.80.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.121.201 (201.121.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 18:51:06.953621 2026] [security2:error] [pid 28382:tid 28382] [client 34.80.121.201:40146] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.3beeze.com"] [uri "/app/.env"] [unique_id "arBjWiZVVlbusUzRd5UruwAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Stara
2026-09-20 22:22:42
(1 day ago)
ModSecurity detected web attack - .env/config probing or SQLi/Code injection (Rule 949110)
Brute-Force
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 21:43:51
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.80.121.201 (201.121.80.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.80.121.201 (201.121.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 17:43:48.004081 2026] [security2:error] [pid 5143:tid 5143] [client 34.80.121.201:58348] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||10bestsongs.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "10bestsongs.com"] [uri "/z9x8c7v6b5-debug-trigger-10bestsongs.com"] [unique_id "arBTlEuvzpgtz8rhEMWLowAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 21:09:22
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.80.121.201 (201.121.80.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.80.121.201 (201.121.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 17:09:16.901735 2026] [security2:error] [pid 5301:tid 5301] [client 34.80.121.201:59976] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||intranet.arroceraomoa.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "intranet.arroceraomoa.com"] [uri "/rclone.conf"] [unique_id "arBLfOBWbr3FbWLpC-630QAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack