๐ฎ๐ช
RoboSOC
2026-09-22 03:01:37
(1 day ago)
Spring Cloud SPEL Remote Code Execution Vulnerability, PTR: 151.150.80.34.bc.googleusercontent.com.
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-22 01:50:10
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.80.150.151 (151.150.80.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.150.151 (151.150.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 21:50:03.085341 2026] [security2:error] [pid 16588:tid 16588] [client 34.80.150.151:53298] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.drainpoultry.com"] [uri "/.git/config"] [unique_id "arHey5rckq34kwgnV7bGLAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 01:01:01
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.80.150.151 (151.150.80.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.80.150.151 (151.150.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 21:00:55.817167 2026] [security2:error] [pid 11185:tid 11185] [client 34.80.150.151:41502] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||dunnretired.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "dunnretired.com"] [uri "/z9x8c7v6b5-debug-trigger-dunnretired.com"] [unique_id "arHTR_C4P64-WyzcKJkK5wAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 00:41:45
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.80.150.151 (151.150.80.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.80.150.151 (151.150.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 20:41:40.606524 2026] [security2:error] [pid 23431:tid 23431] [client 34.80.150.151:50874] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.drumez.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.drumez.com"] [uri "/rclone.conf"] [unique_id "arHOxJ-TPeKrM4Kcc408FAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 23:57:48
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.80.150.151 (151.150.80.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.150.151 (151.150.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 19:57:43.865920 2026] [security2:error] [pid 18864:tid 18864] [client 34.80.150.151:60862] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.sendalawyerletter.com"] [uri "/.env.swp"] [unique_id "arHEd2n8O0imdgOatCimswAAAEA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 23:32:01
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.80.150.151 (151.150.80.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.150.151 (151.150.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 19:31:54.455608 2026] [security2:error] [pid 12612:tid 12612] [client 34.80.150.151:46510] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.drxcontent.com"] [uri "/.env.js"] [unique_id "arG-aklDKR_WrMNzQsIKNwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 22:46:40
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.80.150.151 (151.150.80.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.80.150.151 (151.150.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 18:46:36.287456 2026] [security2:error] [pid 21342:tid 21342] [client 34.80.150.151:41344] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||drhasanunal.chevronparkett.com|F|2"] [data ".chevronparkett.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "drhasanunal.chevronparkett.com"] [uri "/z9x8c7v6b5-debug-trigger-drhasanunal.chevronparkett.com"] [unique_id "arGzzA6IbHN64RNwdlY2YgAAACo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
interbiznw.com
2026-09-21 22:35:50
(1 day ago)
malicious-web-requests-vulnerability-scanning
Hacking
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 21:37:54
(1 day ago)
(mod_security) mod_security (id:243320) triggered by 34.80.150.151 (151.150.80.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:243320) triggered by 34.80.150.151 (151.150.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 17:37:48.211552 2026] [security2:error] [pid 11417:tid 11417] [client 34.80.150.151:59536] ModSecurity: Access denied with code 403 (phase 2). String match "/.profile" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6621"] [id "243320"] [rev "1"] [msg "COMODO WAF: Information disclosure vulnerability in Cloud Foundry PHP Buildpack (aka php-buildpack) before 4.3.18 and PHP Buildpack Cf-release before 242, as used in Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.6.38 and 1.7.x before 1.7.19 and other products (CVE-2016-6639)||drgweich.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "drgweich.com"] [uri "/.profile"] [unique_id "arGjrPhTOHNNBdnNfNIArAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
dtorrer
2026-09-21 20:04:37
(1 day ago)
General vulnerability scan.
Port Scan
๐บ๐ธ
TPI-Abuse
2026-09-21 19:31:11
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.80.150.151 (151.150.80.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.150.151 (151.150.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 15:31:06.158372 2026] [security2:error] [pid 31910:tid 31910] [client 34.80.150.151:35004] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "drstilesdds.com"] [uri "/.git/config"] [unique_id "arGF-syxZdKQFTVbS_BLdwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 18:56:38
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.80.150.151 (151.150.80.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.150.151 (151.150.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 14:56:34.629005 2026] [security2:error] [pid 22075:tid 22075] [client 34.80.150.151:51956] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.alexthepunk.com"] [uri "/.env.stage"] [unique_id "arF94v-A7jFhp4V5S7-sXgAAADc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
boxed-it
2026-09-21 18:12:59
(1 day ago)
GET /config/.env (Tarpitted for 50m55s, wasted 179.06kB)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 17:47:55
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.80.150.151 (151.150.80.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.150.151 (151.150.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 13:47:48.638210 2026] [security2:error] [pid 6975:tid 7171] [client 34.80.150.151:35584] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.evan-hotel.com"] [uri "/public/.env"] [unique_id "arFtxGXN0yRc26kAdtB9xwAAAlg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-21 17:08:55
(1 day ago)
34.80.150.151 - - [21/Sep/2026:19:08:48 +0200] "GET /api/env HTTP/2.0" 404 265
34.80.150.151 - - [21 ...
show more
34.80.150.151 - - [21/Sep/2026:19:08:48 +0200] "GET /api/env HTTP/2.0" 404 265
34.80.150.151 - - [21/Sep/2026:19:08:48 +0200] "GET /z9x8c7v6b5-debug-trigger-static.veracash.com HTTP/2.0" 404 265
34.80.150.151 - - [21/Sep/2026:19:08:48 +0200] "POST /graphql HTTP/2.0" 404 265
34.80.150.151 - - [21/Sep/2026:19:08:49 +0200] "GET /config.json HTTP/2.0" 404 288
34.80.150.151 - - [21/Sep/2026:19:08:49 +0200] "GET /wp-json HTTP/2.0" 404 265
34.80.150.151 - - [21/Sep/2026:19:08:49 +0200] "GET /env.js HTTP/2.0" 404 265
34.80.150.151 - - [21/Sep/2026:19:08:49 +0200] "GET /runtime-config.js HTTP/2.0" 404 265
34.80.150.151 - - [21/Sep/2026:19:08:49 +0200] "POST /api/graphql HTTP/2.0" 404 265
34.80.150.151 - - [21/Sep/2026:19:08:49 +0200] "GET /api/config HTTP/2.0" 404 265
34.80.150.151 - - [21/Sep/2026:19:08:49 +0200] "GET /firebase-config.json HTTP/2.0" 404 265
34.80.150.151 - - [21/Sep/2026:19:08:49 +0200] "GET /settings.json HTTP/2.0" 404 265
34.80.150.151 - - [21/Sep/2026:19:08:49 +0200] "GET /
...
show less
Web Spam
Web App Attack