๐ฉ๐ช
Vegascosmetics
2026-09-16 08:13:42
(1 day ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure probe. Evidence: AttackPattern: /\.env (Match: /.env)
show less
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 07:46:04
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.84.176.249 (249.176.84.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.176.249 (249.176.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 03:46:00.502793 2026] [security2:error] [pid 14195:tid 14195] [client 34.84.176.249:42464] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mimitudordesigns.com"] [uri "/.env"] [unique_id "aqpJOJQ8WEMhnCGSHI5VYgAAAA4"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ช
RoboSOC
2026-09-15 22:08:43
(1 day ago)
phpunit Remote Code Execution Vulnerability, PTR: 249.176.84.34.bc.googleusercontent.com.
Hacking
๐ซ๐ท
dynamix
2026-09-15 15:46:22
(2 days ago)
Multiple WAF Violations
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-15 15:08:20
(2 days ago)
[ti-01ov] Web exploit scanning: 51 suspicious requests detected by fail2ban jail <name>. Example: 34 ...
show more
[ti-01ov] Web exploit scanning: 51 suspicious requests detected by fail2ban jail <name>. Example: 34.84.176.249 - - \[15/Sep/2026:17:06:03 +0200\] "GET /.env HTTP/1.1" 301 594 "https://www.google.com/" "Mozilla/5.0 \(Windows\; U\; MSIE 8.0\; Macintosh\; Trident/4.0\; Intel Mac OS X 10_0_4\)"
34.84.176.249 - - \[15/Sep/2026:17:06:04 +0200\] "GET /.env HTTP/1.1" 404 203493 "https://www.google.com/" "Mozilla/5.0 \(Windows\; U\; MSIE 8.0\; Macintosh\; Trident/4.0\; Intel Mac OS X 10_0_4\)"
34.84.176.249 - - \[15/Sep/2026:17:06:15 +0200\] "GET //vendor/.env HTTP/1.1" 301 607 "https://www.google.com/" "Mozilla/5.0 \(Windows\; U\; MSIE 8.0\; Macintosh\; Trident/4.0\; Intel Mac OS X 10_0_4\)"
34.84.176.249 - - \[15/Sep/2026:17:06:16 +0200\] "GET /vendor/.env HTTP/1.1" 404 198321 "https://www.google.co
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
factor1
2026-09-15 12:47:18
(2 days ago)
CrowdSec at sherman Reports Abuse
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 10:56:46
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.84.176.249 (249.176.84.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.176.249 (249.176.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 06:56:42.896123 2026] [security2:error] [pid 4493:tid 4493] [client 34.84.176.249:57490] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "agworldmissions.org"] [uri "/.env"] [unique_id "aqkkagXnKbcH-K8fuW41hgAAAAU"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
robotstxt
2026-09-15 10:18:25
(2 days ago)
34.84.176.249 - - [15/Sep/2026:10:17:41 +0000] "GET /.remote HTTP/1.1" 403 10680 "https://www.google ...
show more
34.84.176.249 - - [15/Sep/2026:10:17:41 +0000] "GET /.remote HTTP/1.1" 403 10680 "https://www.google.com/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_1_2) AppleWebKit/535.9 (KHTML, like Gecko) Chrome/14.0.337.18 Safari/535.17" "-" edge="34.84.176.249"
34.84.176.249 - - [15/Sep/2026:10:17:42 +0000] "GET /.local HTTP/1.1" 403 10680 "https://www.google.com/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_1_2) AppleWebKit/535.9 (KHTML, like Gecko) Chrome/14.0.337.18 Safari/535.17" "-" edge="34.84.176.249"
34.84.176.249 - - [15/Sep/2026:10:17:43 +0000] "GET /.production HTTP/1.1" 403 10680 "https://www.google.com/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_1_2) AppleWebKit/535.9 (KHTML, like Gecko) Chrome/14.0.337.18 Safari/535.17" "-" edge="34.84.176.249"
34.84.176.249 - - [15/Sep/2026:10:17:44 +0000] "GET //vendor/.env HTTP/1.1" 403 12 "https://www.google.com/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_1_2) AppleWebKit/535.9 (KHTML, like Gecko) Chrome/14.0.337.18 Safari/535.17" "-" edge="34
...
show less
Web App Attack
๐ณ๐ฑ
maxxsense
2026-09-15 07:14:00
(2 days ago)
(mod_security) mod_security triggered on hostname [redacted] 34.84.176.249 (JP/Japan/249.176.84.34.b ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.84.176.249 (JP/Japan/249.176.84.34.bc.googleusercontent.com)
show less
SQL Injection