🇺🇸
TPI-Abuse
2026-09-13 10:00:29
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.80.139.124 (124.139.80.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.139.124 (124.139.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 06:00:16.323111 2026] [security2:error] [pid 28391:tid 28391] [client 34.80.139.124:51220] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "startordoro.com"] [uri "/@fs/.env"] [unique_id "aqZ0MDquxz44fems0J2hFwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 09:43:39
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.80.139.124 (124.139.80.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.139.124 (124.139.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 05:43:31.790616 2026] [security2:error] [pid 14897:tid 14897] [client 34.80.139.124:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sportsbookcommission.com"] [uri "/.env.development"] [unique_id "aqZwQwrOXxxpwKuJvg-9twAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-13 09:34:20
(2 hours ago)
Excessive multi-domain requests
Brute-Force
Anonymous
2026-09-13 09:26:39
(3 hours ago)
34.80.139.124 - - [13/Sep/2026:04:26:37 -0500] "GET /.env?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Ma ...
show more
34.80.139.124 - - [13/Sep/2026:04:26:37 -0500] "GET /.env?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1)" 34.80.139.124
34.80.139.124 - - [13/Sep/2026:04:26:37 -0500] "GET /.env?import&raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)" 34.80.139.124
34.80.139.124 - - [13/Sep/2026:04:26:38 -0500] "GET /.env.local?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1)" 34.80.139.124
34.80.139.124 - - [13/Sep/2026:04:26:38 -0500] "GET /.env?import&url&inline HTTP/1.1" 403 199 "-" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)" 34.80.139.124
34.80.139.124 - - [13/Sep/2026:04:26:38 -0500] "GET /.env.local?import&raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Google-
...
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 09:23:38
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.80.139.124 (124.139.80.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.80.139.124 (124.139.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 05:23:32.663280 2026] [security2:error] [pid 25260:tid 25260] [client 34.80.139.124:35448] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||souldata.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "souldata.com"] [uri "/z9x8c7v6b5-debug-trigger-souldata.com"] [unique_id "aqZrlAmfzgNMMp76OywSBQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 08:44:02
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.80.139.124 (124.139.80.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.80.139.124 (124.139.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 04:43:57.298985 2026] [security2:error] [pid 7739:tid 7739] [client 34.80.139.124:48774] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||slimlaw.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "slimlaw.com"] [uri "/z9x8c7v6b5-debug-trigger-slimlaw.com"] [unique_id "aqZiTerumYS0k688-aggSwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 08:27:01
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.80.139.124 (124.139.80.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.139.124 (124.139.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 04:26:56.321898 2026] [security2:error] [pid 4260:tid 4260] [client 34.80.139.124:52014] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sinko-intl.com"] [uri "/@fs/var/task/.env"] [unique_id "aqZeUJrSSPkw5GkKSiOATwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 07:46:32
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.80.139.124 (124.139.80.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.80.139.124 (124.139.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 03:46:25.493481 2026] [security2:error] [pid 31092:tid 31092] [client 34.80.139.124:58442] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||67ronin.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "67ronin.com"] [uri "/rclone.conf"] [unique_id "aqZU0WI1H-cPSBPI8R9HtAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 07:27:27
(5 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.80.139.124 (124.139.80.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.80.139.124 (124.139.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 03:27:24.275222 2026] [security2:error] [pid 32280:tid 32280] [client 34.80.139.124:34106] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||3-6trucking.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "3-6trucking.com"] [uri "/z9x8c7v6b5-debug-trigger-3-6trucking.com"] [unique_id "aqZQXFL4hD4QJ2J4_eHZ9AAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 07:11:59
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.80.139.124 (124.139.80.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.139.124 (124.139.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 03:11:53.544520 2026] [security2:error] [pid 17196:tid 17196] [client 34.80.139.124:60452] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "123clearmyticket.com"] [uri "/.git/HEAD"] [unique_id "aqZMuexwffv7PpYQa103jwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇳
evicky2002
2026-09-13 06:00:01
(6 hours ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
Anonymous
2026-09-13 02:30:12
(10 hours ago)
Bot / seems abusive / Apache connections: 24
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 02:24:27
(10 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.80.139.124 (124.139.80.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.80.139.124 (124.139.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 22:24:20.472672 2026] [security2:error] [pid 30809:tid 30809] [client 34.80.139.124:35188] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mirai-labo.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mirai-labo.com"] [uri "/z9x8c7v6b5-debug-trigger-mirai-labo.com"] [unique_id "aqYJVMvXuY6TS3rUTFyj7AAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-09-13 02:10:02
(10 hours ago)
crowdsecurity/http-cve-2021-41773
Brute-Force
Web App Attack
🇩🇪
EGP Abuse Dept
2026-09-13 02:05:35
(10 hours ago)
Scanning for web/db/file exploits on www.miotinto.nl
SQL Injection
Bad Web Bot
Web App Attack