🇺🇸
TPI-Abuse
2026-09-13 08:12:24
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.87.149.133 (133.149.87.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.149.133 (133.149.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 04:12:17.825276 2026] [security2:error] [pid 13463:tid 13463] [client 34.87.149.133:53776] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.45"] [uri "/static../.env"] [unique_id "aqZa4Voe9IxV4BHO4T_77QAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
2000cn.com.au
2026-09-13 06:43:15
(11 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇹🇭
Sawasdee
2026-09-13 05:36:13
(12 hours ago)
Unwanted checking 80 or 443 port
...
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-12 22:53:34
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.87.149.133 (133.149.87.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.149.133 (133.149.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 18:53:29.394321 2026] [security2:error] [pid 24592:tid 24592] [client 34.87.149.133:56650] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.20"] [uri "/static../.env"] [unique_id "aqXX6RQXeBlKiqZlgs1OEgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇪🇸
Yoeph
2026-09-12 22:52:17
(18 hours ago)
Attacking server service nginx-movimientos-forbidden (Permanently Banned by Fail2ban on TurnoControl ...
show more
Attacking server service nginx-movimientos-forbidden (Permanently Banned by Fail2ban on TurnoControlPro VPS)
show less
Hacking
Brute-Force
Bad Web Bot
Web App Attack
🇪🇸
Yoeph
2026-09-12 21:55:03
(19 hours ago)
Malicious probe on /.aws/credentials (Permanently Banned) by TurnoControlPro Web Shield
Hacking
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 18:06:15
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.87.149.133 (133.149.87.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.149.133 (133.149.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 14:06:08.392075 2026] [security2:error] [pid 23935:tid 23935] [client 34.87.149.133:45290] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.5"] [uri "/static../.env"] [unique_id "aqWUkPV8jLys1NNl5MCt-gAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
kivitendo.de
2026-09-12 17:00:30
(1 day ago)
[Sat Sep 12 19:00:36.217851 2026] [access_compat:error] [pid 158632:tid 158679] [client 34.87.149.13 ...
show more
[Sat Sep 12 19:00:36.217851 2026] [access_compat:error] [pid 158632:tid 158679] [client 34.87.149.133:37774] AH01797: client denied by server configuration: /var/www/kivitendo-erp/.git/HEAD
[Sat Sep 12 19:00:36.642611 2026] [access_compat:error] [pid 158632:tid 158657] [client 34.87.149.133:37938] AH01797: client denied by server configuration: /var/www/kivitendo-erp/config/.env
...
show less
Brute-Force
Web App Attack
🇳🇱
Savvii
2026-09-12 15:19:32
(1 day ago)
20 attempts against mh_ha-misbehave-ban on crop
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
big-cloud.nl
2026-09-12 14:23:09
(1 day ago)
Try to access /static../.env
Web App Attack
🇳🇱
Savvii
2026-09-12 14:13:25
(1 day ago)
16 attempts against mh-misc-ban on neon
Web App Attack
Anonymous
2026-09-12 14:02:21
(1 day ago)
PAD: ModSec_Scanner! detected
Bad Web Bot
🇨🇭
dalslab ltd
2026-09-12 10:35:20
(1 day ago)
34.87.149.133 - - [12/Sep/2026:12:35:19 +0200] "GET /assets../../../etc/passwd HTTP/1.1" 400 154 "-" ...
show more
34.87.149.133 - - [12/Sep/2026:12:35:19 +0200] "GET /assets../../../etc/passwd HTTP/1.1" 400 154 "-" "-"
34.87.149.133 - - [12/Sep/2026:12:35:20 +0200] "POST /proxy HTTP/1.1" 405 556 "http://83.228.214.125:80" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexity-user) Chrome/148.0.2770.154 Safari/537.36"
34.87.149.133 - - [12/Sep/2026:12:35:20 +0200] "POST /api/fetch HTTP/1.1" 405 556 "http://83.228.214.125:80" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko; compatible; Discordbot/2.0; +https://discordapp.com) Chrome/148.0.5586.187 Safari/537.36 Edg/148.0.5586.187"
34.87.149.133 - - [12/Sep/2026:12:35:20 +0200] "POST /api/graphql HTTP/1.1" 405 556 "http://83.228.214.125:80" "Mozilla/5.0 (Linux; Android 14; Pixel 8) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.4165.76 Mobile Safari/537.36; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexity-
...
show less
Web Spam
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Ilop
2026-09-12 09:30:07
(1 day ago)
[v6-22] Firewall dropped 4 unsolicited packet(s) proto=tcp to port(s) 443,80 from 34.87.149.133 — WA ...
show more
[v6-22] Firewall dropped 4 unsolicited packet(s) proto=tcp to port(s) 443,80 from 34.87.149.133 — WAN scan (automated sensor)
show less
Port Scan
Anonymous
2026-09-12 08:23:42
(1 day ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking