๐บ๐ธ
TPI-Abuse
2026-10-03 07:44:32
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.81.214.219 (219.214.81.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.214.219 (219.214.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 03 03:44:28.637096 2026] [security2:error] [pid 21252:tid 21252] [client 34.81.214.219:48584] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.jonesypop.com"] [uri "/static../.env"] [unique_id "asCyXMRuWjvAyu-7tl_djwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-03 07:28:16
(2 days ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
๐ฉ๐ช
stinpriza
2026-10-03 07:27:23
(2 days ago)
common Web Exploits being scanned
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-03 07:25:42
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.81.214.219 (219.214.81.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.214.219 (219.214.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 03 03:25:34.207223 2026] [security2:error] [pid 18054:tid 18054] [client 34.81.214.219:36932] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "m.handyrehab.com"] [uri "/media../.env"] [unique_id "asCt7u8LIoXMmct0zKOpfgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-03 07:02:52
(2 days ago)
[ti-22al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-22al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.81.214.219 - - [03/Oct/2026:09:02:50 +0200] "GET /static//.env HTTP/2.0" 403 369 "-" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)"
...
show less
Bad Web Bot
Web App Attack
๐ง๐ช
taivas.nl
2026-10-03 04:33:11
(2 days ago)
Many_bad_calls
Web App Attack
๐ณ๐ฑ
BlueWire Hosting
2026-10-03 01:46:55
(2 days ago)
Bad bot ignoring robot.txt
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-03 01:38:51
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.81.214.219 (219.214.81.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.81.214.219 (219.214.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 21:38:48.314493 2026] [security2:error] [pid 19909:tid 19909] [client 34.81.214.219:43846] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||dennisdsmith.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "dennisdsmith.com"] [uri "/z9x8c7v6b5-debug-trigger-dennisdsmith.com"] [unique_id "asBcqHrvz5DtSScO8J0dFwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-10-03 01:29:22
(2 days ago)
921 requests with url.path *.env
289 requests with url.path */@fs/*
102 requests with url.path */ ...
show more
921 requests with url.path *.env
289 requests with url.path */@fs/*
102 requests with url.path */proc/*
show less
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-03 01:04:41
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.81.214.219 (219.214.81.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.214.219 (219.214.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 21:04:34.437730 2026] [security2:error] [pid 32445:tid 32445] [client 34.81.214.219:33994] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.derek-stites.com"] [uri "/.htpasswd"] [unique_id "asBUoq1VJYMIS5Za_orCQgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
โจ
2026-10-03 00:44:10
(2 days ago)
Domain : dev.piranha-bi.com
Rule : hack
2026-10-03 00:43:33 79.171.39.6 GET /z9x8c7v6b5-debug-trigge ...
show more
Domain : dev.piranha-bi.com
Rule : hack
2026-10-03 00:43:33 79.171.39.6 GET /z9x8c7v6b5-debug-trigger-dev.piranha-bi.com - 443 - 34.81.214.219 HTTP/2.0 Mozilla/5.0 (compatible; xAI-Grok/1.0; https://x.ai/) - dev.piranha-bi.com 302 0 0 4040 465 1512 - -
show less
Hacking
SQL Injection
Brute-Force
๐ฉ๐ช
TheDjRider
2026-10-02 22:59:56
(2 days ago)
CrowdSec detected Web application reconnaissance. Scenario: crowdsecurity/http-probing. Automatic ba ...
show more
CrowdSec detected Web application reconnaissance. Scenario: crowdsecurity/http-probing. Automatic ban triggered. Detection time (UTC): 2026-10-02T22:59:54.096215857Z. Context: http_status=404
show less
Web App Attack
๐ฆ๐บ
AWW-Admin
2026-10-02 22:47:00
(2 days ago)
(mod_security) mod_security triggered on hostname [redacted] 34.81.214.219 (TW/Taiwan/219.214.81.34. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.81.214.219 (TW/Taiwan/219.214.81.34.bc.googleusercontent.com)
show less
SQL Injection
๐ซ๐ท
dynamix
2026-10-02 20:50:17
(2 days ago)
Multiple WAF Violations
Web App Attack
๐ณ๐ฑ
ConsulHosting
2026-10-02 19:25:38
(2 days ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack