πΊπΈ
TPI-Abuse
2026-09-22 01:09:52
(6 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.82.60.123 (123.60.82.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.82.60.123 (123.60.82.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 21:09:45.184754 2026] [security2:error] [pid 990246:tid 990246] [client 34.82.60.123:34422] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.leagueloch.com"] [uri "/.env.js"] [unique_id "arHVWYECJepc3EkgTdwdVQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Site.eu
2026-09-22 00:58:30
(17 minutes ago)
Excessive multi-domain requests
Brute-Force
πΊπΈ
IndigoRidge
2026-09-21 22:21:09
(2 hours ago)
34.82.60.123 - - [21/Sep/2026:18:21:08 -0400] "GET /.aws/credentials HTTP/1.1" 404 5750 "-" "Mozilla ...
show more
34.82.60.123 - - [21/Sep/2026:18:21:08 -0400] "GET /.aws/credentials HTTP/1.1" 404 5750 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1)"
34.82.60.123 - - [21/Sep/2026:18:21:08 -0400] "GET /.git/config HTTP/1.1" 404 5750 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )"
34.82.60.123 - - [21/Sep/2026:18:21:08 -0400] "GET /.env HTTP/1.1" 404 5750 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )"
...
show less
Web App Attack
πΊπΈ
nasset
2026-09-21 21:44:45
(3 hours ago)
34.82.60.123 - - [21/Sep/2026:14:44:45 -0700] "GET /admin/.env HTTP/1.1" 403 584 "-" "Mozilla/5.0 Ap ...
show more
34.82.60.123 - - [21/Sep/2026:14:44:45 -0700] "GET /admin/.env HTTP/1.1" 403 584 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot"
34.82.60.123 - - [21/Sep/2026:14:44:45 -0700] "GET /.env HTTP/1.1" 403 584 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)"
34.82.60.123 - - [21/Sep/2026:14:44:45 -0700] "GET /backend/.env HTTP/1.1" 403 584 "-" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/)"
34.82.60.123 - - [21/Sep/2026:14:44:45 -0700] "GET /api/v2/settings HTTP/1.1" 403 584 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1)"
34.82.60.123 - - [21/Sep/2026:14:44:45 -0700] "GET /manifest.webmanifest HTTP/1.1" 403 584 "-" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/)"
...
show less
Bad Web Bot
Web App Attack
π©πͺ
netclix.gr
2026-09-21 21:35:50
(3 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.82.60.123 (US/United States/123.60.8 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.82.60.123 (US/United States/123.60.82.34.bc.googleusercontent.com): (CF_ENABLE)
show less
SQL Injection
πΊπΈ
mnsf
2026-09-21 21:05:42
(4 hours ago)
Scanning/Probing (11)
Brute-Force
Web App Attack
π©πͺ
LRob
2026-09-21 20:48:24
(4 hours ago)
This address is looking for secret files on our sites: .git directories, .env files, credential and ...
show more
This address is looking for secret files on our sites: .git directories, .env files, credential and configuration files, database dumps, backups. This is a targeted search for credentials to break into the sites, blocked at the first request. Please check the machine behind it for an attack tool or malware. | method: GET | path: /.env.example | 2026-09-21 20:48 UTC
show less
Hacking
Web App Attack
Anonymous
2026-09-21 19:16:00
(6 hours ago)
Excessive crawling/scraping. Vulnerable file probing.
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 16:50:43
(8 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.82.60.123 (123.60.82.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.82.60.123 (123.60.82.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 12:50:36.843468 2026] [security2:error] [pid 5707:tid 5707] [client 34.82.60.123:44630] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.13waggoners.com|F|2"] [data ".13waggoners.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.13waggoners.com"] [uri "/z9x8c7v6b5-debug-trigger-mail.13waggoners.com"] [unique_id "arFgXAukRDKSPBG7sCo9cwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-21 16:44:29
(8 hours ago)
Aggressive web scan
Web App Attack
π«π·
COMAITE
2026-09-21 15:29:43
(9 hours ago)
Common web attack from 34.82.60.123.
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 15:08:27
(10 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.82.60.123 (123.60.82.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.82.60.123 (123.60.82.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 11:08:22.703708 2026] [security2:error] [pid 6973:tid 7215] [client 34.82.60.123:55562] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.anthonydalessandro.com|F|2"] [data ".anthonydalessandro.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.anthonydalessandro.com"] [uri "/z9x8c7v6b5-debug-trigger-mail.anthonydalessandro.com"] [unique_id "arFIZunGAoDSm12nz2RgKQAAAY4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 14:43:49
(10 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.82.60.123 (123.60.82.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.82.60.123 (123.60.82.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 10:43:45.832972 2026] [security2:error] [pid 2220:tid 2220] [client 34.82.60.123:44576] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||leighcunningham.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "leighcunningham.com"] [uri "/z9x8c7v6b5-debug-trigger-leighcunningham.com"] [unique_id "arFCoXKExmwAP3073jjHwQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 14:25:12
(10 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.82.60.123 (123.60.82.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.82.60.123 (123.60.82.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 10:25:07.715494 2026] [security2:error] [pid 5990:tid 6028] [client 34.82.60.123:41866] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.teritemme.com|F|2"] [data ".teritemme.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.teritemme.com"] [uri "/z9x8c7v6b5-debug-trigger-mail.teritemme.com"] [unique_id "arE-Q4HLiMRjksrxh6DtnQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 14:07:03
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.82.60.123 (123.60.82.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.82.60.123 (123.60.82.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 10:06:57.121109 2026] [security2:error] [pid 17774:tid 17774] [client 34.82.60.123:46742] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.my-spec.com"] [uri "/@fs/app/.env"] [unique_id "arE6AULDdkxrmfnfmAikIwAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack