๐ฉ๐ช
Sรฉfora Srl
2026-09-19 16:00:25
(21 hours ago)
Failed attempt detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 12:03:07
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.80.34.63 (63.34.80.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.34.63 (63.34.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 08:03:02.753823 2026] [security2:error] [pid 9618:tid 9618] [client 34.80.34.63:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.sportsbookcommission.com"] [uri "/@fs/../.env"] [unique_id "aq559lBC710USCkNJJxKdgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-09-19 11:42:36
(1 day ago)
csagent: score 21.2: 404 noise floor x5, secrets grab x2; 1 domain(s) in 3s
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 11:35:25
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.80.34.63 (63.34.80.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.34.63 (63.34.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 07:35:21.701454 2026] [security2:error] [pid 30273:tid 30273] [client 34.80.34.63:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.poweribo.com"] [uri "/admin/.env"] [unique_id "aq5zebvNZc6g3L7n9mKKgwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 11:06:00
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.80.34.63 (63.34.80.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.34.63 (63.34.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 07:05:57.180621 2026] [security2:error] [pid 16536:tid 16536] [client 34.80.34.63:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.mail-pmg.com"] [uri "/config/.env"] [unique_id "aq5slQccF8mt0GRThuf34gAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 10:34:26
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.80.34.63 (63.34.80.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.34.63 (63.34.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 06:34:19.614497 2026] [security2:error] [pid 21467:tid 21569] [client 34.80.34.63:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.grandmasgentlesteps.com"] [uri "/admin/.env"] [unique_id "aq5lK87l9A6-uR9FnRnJ3AAAAkQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-09-19 09:35:03
(1 day ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 09:26:30
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.80.34.63 (63.34.80.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.34.63 (63.34.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 05:26:25.573345 2026] [security2:error] [pid 16643:tid 16643] [client 34.80.34.63:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.barryherbach.com"] [uri "/@fs/app/.env"] [unique_id "aq5VQYORygY3sWepOP_AWAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-18 19:29:19
(1 day ago)
Aggressive web scan
Web App Attack
๐ฆ๐ช
CG
2026-09-18 18:02:34
(1 day ago)
Web application attack, Automated scan
Web App Attack
Hacking
SQL Injection
๐ฉ๐ช
www.Examensfragen.de
2026-09-18 17:03:11
(1 day ago)
Web Spam
Bad Web Bot
Anonymous
2026-09-18 16:07:03
(1 day ago)
Automated web scanner. Requested suspicious paths: /reset-password | /login | /console | /__/firebas ...
show more
Automated web scanner. Requested suspicious paths: /reset-password | /login | /console | /__/firebase/init.json | /.gitlab-ci.yml. UTC: 2026-09-18 15:17:50.
show less
Web App Attack
๐ช๐ธ
robotstxt
2026-09-18 15:22:31
(1 day ago)
34.80.34.63 - - [18/Sep/2026:15:22:16 +0000] "-" 400 193 "-" "-" "-" edge="34.80.34.63"
34.80.34.63 ...
show more
34.80.34.63 - - [18/Sep/2026:15:22:16 +0000] "-" 400 193 "-" "-" "-" edge="34.80.34.63"
34.80.34.63 - - [18/Sep/2026:15:22:17 +0000] "-" 400 193 "-" "-" "-" edge="34.80.34.63"
34.80.34.63 - - [18/Sep/2026:15:22:18 +0000] "-" 400 193 "-" "-" "-" edge="34.80.34.63"
34.80.34.63 - - [18/Sep/2026:15:22:18 +0000] "-" 400 193 "-" "-" "-" edge="34.80.34.63"
34.80.34.63 - - [18/Sep/2026:15:22:18 +0000] "-" 400 193 "-" "-" "-" edge="34.80.34.63"
...
show less
Web Spam
Web App Attack
๐จ๐ฆ
Anytech
2026-09-18 14:58:56
(1 day ago)
Blocked by ConnMonitor
Web App Attack
๐บ๐ธ
earnquest
2026-09-18 14:48:38
(1 day ago)
Vulnerability scanning detected on EarnQuest Server | Trigger path: /.env.local | Total attempts: 5 ...
show more
Vulnerability scanning detected on EarnQuest Server | Trigger path: /.env.local | Total attempts: 5 | Sample paths: /lib/.env, /backend/.env, /.git/head, /.env.local | User-Agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexit... | Blocked by automated scanner detection middleware
show less
Web App Attack
Port Scan