๐ซ๐ฎ
paissangroup
2026-09-22 01:09:41
(1 day ago)
Multiple WAF Violations
Web App Attack
๐จ๐ญ
zynex
2026-09-21 20:55:05
(1 day ago)
URL Probing: /llm/.env
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 19:45:22
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.81.235.111 (111.235.81.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.235.111 (111.235.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 15:45:15.487478 2026] [security2:error] [pid 30632:tid 30737] [client 34.81.235.111:53976] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.idwic.com"] [uri "/appearance/../../.env"] [unique_id "arGJSzW9OP9Db4Q3BTa2EQAAAE0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Quarks Solutions
2026-09-21 18:37:42
(1 day ago)
crowdsecurity/appsec-vpatch
Web App Attack
๐ฉ๐ช
[email protected]
2026-09-21 17:24:14
(1 day ago)
Brute force 90 attempts
DDoS Attack
SQL Injection
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-09-21 15:33:53
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.81.235.111 (111.235.81.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.235.111 (111.235.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 11:33:46.521888 2026] [security2:error] [pid 10290:tid 10290] [client 34.81.235.111:33720] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "al-harbi.com"] [uri "/uploads../.env"] [unique_id "arFOWpR6myCRgNfVuBuhVQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 15:03:59
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.81.235.111 (111.235.81.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.235.111 (111.235.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 11:03:52.707168 2026] [security2:error] [pid 17740:tid 17740] [client 34.81.235.111:37364] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.hyps.com"] [uri "/@fs/app/.env"] [unique_id "arFHWNj-e8syhTG4kk4NJwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
deskpass.com
2026-09-21 14:27:41
(2 days ago)
POST /icecoder/lib/terminal-xhr.php
Web App Attack
๐ซ๐ท
COMAITE
2026-09-21 14:27:38
(2 days ago)
Common web attack from 34.81.235.111.
Web App Attack
Anonymous
2026-09-21 14:09:31
(2 days ago)
Aggressive web scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 14:01:19
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.81.235.111 (111.235.81.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.235.111 (111.235.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 10:01:15.303350 2026] [security2:error] [pid 14964:tid 14964] [client 34.81.235.111:43388] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/Web.config" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.hwy251.com"] [uri "/web.config"] [unique_id "arE4qxLxru-6pxA0mW-g4wAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 13:36:11
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.81.235.111 (111.235.81.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.81.235.111 (111.235.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 09:36:04.135566 2026] [security2:error] [pid 25857:tid 25857] [client 34.81.235.111:47316] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||iconbizpromo.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "iconbizpromo.com"] [uri "/z9x8c7v6b5-debug-trigger-iconbizpromo.com"] [unique_id "arEyxPV_TgkE1t3tFS0c6QAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-21 13:20:57
(2 days ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-09-21 13:20:12
(2 days ago)
| [Dangerous/Taiwan] Aggressive IP 34.81.235.111 (~30 hits). Type: DoS Defender- Web server 400 erro ...
show more
| [Dangerous/Taiwan] Aggressive IP 34.81.235.111 (~30 hits). Type: DoS Defender- Web server 400 error code
show less
Web App Attack
Hacking
SQL Injection
๐ณ๐ฑ
Alt255
2026-09-21 13:15:06
(2 days ago)
[ti-03ov] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-03ov] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.81.235.111 - - [21/Sep/2026:15:14:47 +0200] "GET /.ssh/config HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)"
...
show less
Bad Web Bot
Web App Attack