Anonymous
2026-09-22 01:12:48
(2 hours ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
๐ณ๐ฑ
Site.eu
2026-09-22 00:51:21
(3 hours ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-22 00:43:30
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.81.156.49 (49.156.81.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.156.49 (49.156.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 20:43:25.295882 2026] [security2:error] [pid 14961:tid 14961] [client 34.81.156.49:49856] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.gun-laws-by-state.com"] [uri "/server/.env"] [unique_id "arHPLWIjh6mXuPFHR8WaxwAAADU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
bazter.pro
2026-09-21 23:59:42
(3 hours ago)
Fail2Ban: apache-ratelimit - 20 failures
Port Scan
Bad Web Bot
Web App Attack
๐ฉ๐ช
itsolon
2026-09-21 23:28:22
(4 hours ago)
[22/Sep/2026:01:28:20 +0200] 179003330027.255966 34.81.156.49 54606 217.154.7.177 443
[22/Sep/2026:0 ...
show more
[22/Sep/2026:01:28:20 +0200] 179003330027.255966 34.81.156.49 54606 217.154.7.177 443
[22/Sep/2026:01:28:20 +0200] 179003330024.422801 34.81.156.49 54606 217.154.7.177 443
[22/Sep/2026:01:28:20 +0200] 179003330011.540535 34.81.156.49 54606 217.154.7.177 443
[22/Sep/2026:01:28:21 +0200] 179003330131.899010 34.81.156.49 54606 217.154.7.177 443
[22/Sep/2026:01:28:21 +0200] 179003330137.320206 34.81.156.49 54606 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
๐ซ๐ท
GoodOldTOS
2026-09-21 20:33:41
(7 hours ago)
Highly suspect IP
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 19:14:30
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.81.156.49 (49.156.81.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.156.49 (49.156.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 15:14:22.950817 2026] [security2:error] [pid 602253:tid 602253] [client 34.81.156.49:34008] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.gwenwaltersartrep.com"] [uri "/.env.js"] [unique_id "arGCDmdAzOSe3Xz7g_tJyAAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Sling
2026-09-21 17:44:49
(10 hours ago)
Automated detection: IP accessed 8 sensitive endpoints within 30s on panel.slingexe.com. Paths: /.en ...
show more
Automated detection: IP accessed 8 sensitive endpoints within 30s on panel.slingexe.com. Paths: /.env.production, /.env.local, /pages/index.astro.mjs.map, /secrets.yml, /pages/api/index.astro.mjs.map, /.npmrc, /.env.stage, /info.php. UA: Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/).
show less
Web App Attack
Bad Web Bot
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-21 16:37:10
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.81.156.49 (49.156.81.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.156.49 (49.156.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 12:37:02.737784 2026] [security2:error] [pid 4280:tid 4280] [client 34.81.156.49:42044] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.modeltdr.com"] [uri "/.env.example"] [unique_id "arFdLv2p1zohiYVBpMhlngAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Sling
2026-09-21 15:37:31
(12 hours ago)
Automated detection: IP accessed 8 sensitive endpoints within 30s on airflow.slingexe.com. Paths: /. ...
show more
Automated detection: IP accessed 8 sensitive endpoints within 30s on airflow.slingexe.com. Paths: /.env.production, /application.properties, /.env.local, /.gitlab-ci.yml, /secrets.json, /.npmrc, /.aws/credentials, /config.json. UA: Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/).
show less
Web App Attack
Bad Web Bot
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-21 15:36:17
(12 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.81.156.49 (49.156.81.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.81.156.49 (49.156.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 11:36:11.057649 2026] [security2:error] [pid 6973:tid 7213] [client 34.81.156.49:34820] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.neotienda.com|F|2"] [data ".neotienda.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.neotienda.com"] [uri "/z9x8c7v6b5-debug-trigger-mail.neotienda.com"] [unique_id "arFO6-nGAoDSm12nz2RmGQAAAYw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-21 15:33:43
(12 hours ago)
XSS Attempt
Hacking
Anonymous
2026-09-21 15:30:06
(12 hours ago)
CrowdSec decision: crowdsecurity/http-admin-interface-probing (origin: crowdsec)
Web App Attack
Anonymous
2026-09-21 15:29:49
(12 hours ago)
Aggressive web scan
Web App Attack
๐บ๐ธ
robotstxt
2026-09-21 15:23:53
(12 hours ago)
34.81.156.49 - - [21/Sep/2026:15:23:12 +0000] "GET /shop/.env HTTP/2.0" 403 25101 "https://www.growl ...
show more
34.81.156.49 - - [21/Sep/2026:15:23:12 +0000] "GET /shop/.env HTTP/2.0" 403 25101 "https://www.growlantis.com/shop/.env" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" "-" edge="34.81.156.49"
34.81.156.49 - - [21/Sep/2026:15:23:12 +0000] "GET /panel/.env HTTP/2.0" 403 25101 "https://www.growlantis.com/panel/.env" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)" "-" edge="34.81.156.49"
34.81.156.49 - - [21/Sep/2026:15:23:12 +0000] "GET /dashboard/.env HTTP/2.0" 403 25107 "https://www.growlantis.com/dashboard/.env" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)" "-" edge="34.81.156.49"
34.81.156.49 - - [21/Sep/2026:15:23:12 +0000] "GET /store/.env HTTP/2.0" 403 25107 "https://www.growlantis.com/store/.env" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)" "-" edge="34.81.156.49"
34.81.156.49 - - [21/Sep/2026:15:23:13 +0000] "GET /static/.env HTTP/
...
show less
Web App Attack