πΏπ¦
conure.sh
2026-09-21 12:13:43
(11 hours ago)
csagent: score 24.4: 404 noise floor x18, secrets grab x2; 1 domain(s) in 1s
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 05:48:09
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.81.126.3 (3.126.81.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.126.3 (3.126.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 01:48:04.338148 2026] [security2:error] [pid 23271:tid 23271] [client 34.81.126.3:47824] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.development-dynamics.com"] [uri "/.env.stage"] [unique_id "arDFFO9AWsgsM_weKGpLhAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 04:58:22
(19 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.81.126.3 (3.126.81.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.81.126.3 (3.126.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 00:58:15.968131 2026] [security2:error] [pid 17359:tid 17359] [client 34.81.126.3:34998] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.futureproductionsonline.com|F|2"] [data ".futureproductionsonline.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.futureproductionsonline.com"] [uri "/z9x8c7v6b5-debug-trigger-www.futureproductionsonline.com"] [unique_id "arC5Z4n-T77QT6mqSmsVRAAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π²πΎ
Rizzy
2026-09-21 04:06:44
(20 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 03:10:31
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.81.126.3 (3.126.81.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.126.3 (3.126.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 23:10:25.120670 2026] [security2:error] [pid 27237:tid 27237] [client 34.81.126.3:52606] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.ficklepassionproductions.com"] [uri "/@fs/../.env"] [unique_id "arCgIe9jC_r760JVNYYLDQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 02:15:19
(21 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.81.126.3 (3.126.81.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.81.126.3 (3.126.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 22:15:11.959849 2026] [security2:error] [pid 3500:tid 3500] [client 34.81.126.3:35650] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.gowithevergreen.com|F|2"] [data ".gowithevergreen.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.gowithevergreen.com"] [uri "/z9x8c7v6b5-debug-trigger-www.gowithevergreen.com"] [unique_id "arCTL-TiN8EhmKV-TGMOHgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
LRob
2026-09-21 01:12:36
(22 hours ago)
Declared crawler ignoring robots.txt and the refusals it is given | ua: Mozilla/5.0 AppleWebKit/537. ...
show more
Declared crawler ignoring robots.txt and the refusals it is given | ua: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot) (+4 more) | path: /.aws/config (+14 more) | 2026-09-21 01:12 UTC
show less
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-09-21 00:59:48
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.81.126.3 (3.126.81.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.126.3 (3.126.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 20:59:41.498102 2026] [security2:error] [pid 883:tid 883] [client 34.81.126.3:37126] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.fashionmenswear.com"] [uri "/model/.env"] [unique_id "arCBfbwwGcKwfSr8y4igAQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 00:25:00
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.81.126.3 (3.126.81.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.126.3 (3.126.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 20:24:55.598551 2026] [security2:error] [pid 32154:tid 32154] [client 34.81.126.3:47780] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.growtowork.com"] [uri "/.env.production"] [unique_id "arB5V31503rhsW5yGV4M7AAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 00:09:10
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.81.126.3 (3.126.81.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.126.3 (3.126.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 20:09:03.397793 2026] [security2:error] [pid 1141:tid 1141] [client 34.81.126.3:60744] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "elenius.com"] [uri "/.git/HEAD"] [unique_id "arB1n1WJgMWssRpvp0aY9AAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-20 23:43:31
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.81.126.3 (3.126.81.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.126.3 (3.126.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 19:43:26.777601 2026] [security2:error] [pid 19531:tid 19531] [client 34.81.126.3:60006] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.homerbiz.com"] [uri "/.env.example"] [unique_id "arBvnti5wfDyFZtQbTqAcQAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-20 23:24:23
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.81.126.3 (3.126.81.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.126.3 (3.126.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 19:24:17.655070 2026] [security2:error] [pid 321:tid 321] [client 34.81.126.3:46120] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.i-med.com"] [uri "/.env.local"] [unique_id "arBrIc1-WksGhOB5XzbywQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-20 22:47:48
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.81.126.3 (3.126.81.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.126.3 (3.126.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 18:47:45.706770 2026] [security2:error] [pid 15190:tid 15201] [client 34.81.126.3:37056] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.filterchoice.com"] [uri "/cmd/.env"] [unique_id "arBikfZwOhW-Odp13o1ZswAAAIg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-20 22:43:34
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
πΊπΈ
TPI-Abuse
2026-09-20 22:32:36
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.81.126.3 (3.126.81.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.126.3 (3.126.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 18:32:29.793338 2026] [security2:error] [pid 11090:tid 11090] [client 34.81.126.3:33604] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.healthydatasystems.com"] [uri "/.env"] [unique_id "arBe_doq8xtU42Qdrox9CAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack