π²πΎ
Rizzy
2026-09-22 01:08:50
(3 days ago)
Multiple WAF Violations
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 23:55:12
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.81.61.230 (230.61.81.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.61.230 (230.61.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 19:55:07.217216 2026] [security2:error] [pid 31258:tid 31258] [client 34.81.61.230:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.kidswithcamerasmovie.com"] [uri "/shared/.env"] [unique_id "arHD25YYtl99fC_1JT1TGAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 23:18:28
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.81.61.230 (230.61.81.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.61.230 (230.61.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 19:18:23.807392 2026] [security2:error] [pid 3872:tid 3889] [client 34.81.61.230:45596] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.kellenlee.com"] [uri "/.git/config"] [unique_id "arG7P71L6xuAZ54SjrjyZgAAAU8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
Gwyneth Llewelyn
2026-09-21 21:59:51
(3 days ago)
2026/09/21 22:59:49 [error] 325888#325888: *1145685 access forbidden by rule, client: 34.81.61.230, ...
show more
2026/09/21 22:59:49 [error] 325888#325888: *1145685 access forbidden by rule, client: 34.81.61.230, server: zonadetestes.com, request: "GET /.env HTTP/2.0", host: "zonadetestes.com"
34.81.61.230 - - [21/Sep/2026:22:59:49 +0100] "GET /.env HTTP/2.0" 403 1045 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)"
2026/09/21 22:59:49 [error] 325888#325888: *1145685 access forbidden by rule, client: 34.81.61.230, server: zonadetestes.com, request: "GET /project/.env HTTP/2.0", host: "zonadetestes.com"
show less
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 21:50:36
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.81.61.230 (230.61.81.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.61.230 (230.61.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 17:50:29.571231 2026] [security2:error] [pid 10705:tid 10705] [client 34.81.61.230:38530] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.khovanov.com"] [uri "/.git/HEAD"] [unique_id "arGmpSNiGZgYZVCs3CUvJQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-21 20:30:03
(3 days ago)
CrowdSec decision: LePresidente/http-generic-401-bf (origin: crowdsec)
Port Scan
πΊπΈ
TPI-Abuse
2026-09-21 20:08:02
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.81.61.230 (230.61.81.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.61.230 (230.61.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 16:07:56.970745 2026] [security2:error] [pid 8159:tid 8159] [client 34.81.61.230:34378] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.kevincodymusic.com"] [uri "/deploy/.env"] [unique_id "arGOnH3jsxRdehmHbArOWAAAADI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
rsa
2026-09-21 19:56:00
(3 days ago)
GET /console HTTP/1.1
DDoS Attack
Exploited Host
Web App Attack
πΊπΈ
H24
2026-09-21 18:32:10
(3 days ago)
/dist/.env /llm/.env /static/.env /backend/.env /store/.env /packages/.env /bot/.env /auth/.env /bui ...
show more
/dist/.env /llm/.env /static/.env /backend/.env /store/.env /packages/.env /bot/.env /auth/.env /build/.env /admin/.env
show less
Web App Attack
π©πͺ
Gwyneth Llewelyn
2026-09-21 18:27:17
(3 days ago)
2026/09/21 19:27:14 [error] 325888#325888: *1092602 access forbidden by rule, client: 34.81.61.230, ...
show more
2026/09/21 19:27:14 [error] 325888#325888: *1092602 access forbidden by rule, client: 34.81.61.230, server: zonadetestes.com, request: "GET /services/.env HTTP/2.0", host: "zonadetestes.com", referrer: "https://www.zonadetestes.com/services/.env"
2026/09/21 19:27:14 [error] 325888#325888: *1092602 access forbidden by rule, client: 34.81.61.230, server: zonadetestes.com, request: "GET /api/v1/.env HTTP/2.0", host: "zonadetestes.com", referrer: "https://www.zonadetestes.com/api/v1/.env"
2026/09/21 19:27:15 [error] 325888#325888: *1092602 access forbidden by rule, client: 34.81.61.230, server: zonadetestes.com, request: "GET /project/.env HTTP/2.0", host: "zonadetestes.com", referrer: "https://www.zonadetestes.com/project/.env"
show less
Brute-Force
Web App Attack
π³π±
Alt255
2026-09-21 17:30:57
(3 days ago)
[ti-04al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apac ...
show more
[ti-04al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apache-404. Example: 34.81.61.230 - - [21/Sep/2026:19:30:46 +0200] "GET /__/firebase/init.json HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)"
34.81.61.230 - - [21/Sep/2026:19:30:46 +0200] "GET /config.json HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)"
34.81.61.230 - - [21/Sep/2026:19:30:46 +0200] "GET /api/config HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)"
34.81.61.230 - - [21/Sep/2026:19:30:46 +0200] "GET /wp-json HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1)"
34.81.61.23
...
show less
Bad Web Bot
Web App Attack
π¨π¦
Mediashaker
2026-09-21 16:56:59
(3 days ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 34.81.61.230 (TW/Tai ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 34.81.61.230 (TW/Taiwan/230.61.81.34.bc.googleusercontent.com)
show less
Bad Web Bot
π©πͺ
big-cloud.nl
2026-09-21 15:40:37
(3 days ago)
Try to access /llm/.env
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 15:36:42
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 34.81.61.230 (230.61.81.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.81.61.230 (230.61.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 11:36:38.549300 2026] [security2:error] [pid 17846:tid 17846] [client 34.81.61.230:48112] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.keithbowles.com|F|2"] [data ".keithbowles.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.keithbowles.com"] [uri "/z9x8c7v6b5-debug-trigger-mail.keithbowles.com"] [unique_id "arFPBo5Sqhq6iOFUY2n7tQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 15:11:29
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 34.81.61.230 (230.61.81.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.81.61.230 (230.61.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 11:11:26.306502 2026] [security2:error] [pid 3405:tid 3405] [client 34.81.61.230:58638] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kinnairdwoodworking.com.pages4you.com|F|2"] [data ".com.pages4you.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kinnairdwoodworking.com.pages4you.com"] [uri "/z9x8c7v6b5-debug-trigger-kinnairdwoodworking.com.pages4you.com"] [unique_id "arFJHqsmpIitcF5appRt3QAAAG4"]
show less
Brute-Force
Bad Web Bot
Web App Attack