๐บ๐ธ
TPI-Abuse
2026-09-22 01:50:27
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.87.173.238 (238.173.87.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.173.238 (238.173.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 21:50:21.806603 2026] [security2:error] [pid 25623:tid 25623] [client 34.87.173.238:39418] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.meganmurph.com"] [uri "/@fs/../.env"] [unique_id "arHe3WkDKFwQlcixwgCYNAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 00:48:51
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.87.173.238 (238.173.87.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.173.238 (238.173.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 20:48:48.238668 2026] [security2:error] [pid 20289:tid 20289] [client 34.87.173.238:60318] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "megaandina.com"] [uri "/.env.backup"] [unique_id "arHQcPwPDorp9yKZtM_7MAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
cityhunter_rhone
2026-09-22 00:45:02
(2 weeks ago)
Mercurius trap auto report | source=APACHE_DENIED_AGGREGATE | last_seen=2026-09-22 02:39:42 | hits_4 ...
show more
Mercurius trap auto report | source=APACHE_DENIED_AGGREGATE | last_seen=2026-09-22 02:39:42 | hits_403=1 | hits_404=0 | ip=34.87.173.238 | sample_uri=/intro.php
show less
Port Scan
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 00:23:19
(2 weeks ago)
(mod_security) mod_security (id:210580) triggered by 34.87.173.238 (238.173.87.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210580) triggered by 34.87.173.238 (238.173.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 20:23:16.288198 2026] [security2:error] [pid 31926:tid 31926] [client 34.87.173.238:50592] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at ARGS:path. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||www.merrilymovie.com|F|2"] [data "Matched Data: proc/self/environ found within ARGS:path: ../../../../proc/self/environ"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "www.merrilymovie.com"] [uri "/userfiles"] [unique_id "arHKdFgqAw6QmRHGyf8E9AAAAFE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
snhosting
2026-09-21 23:57:36
(2 weeks ago)
34.87.173.238 - - [22/Sep/2026:01:57:26 +0200] "GET /.env.development?raw HTTP/2.0" 200 1606 "-" "Mo ...
show more
34.87.173.238 - - [22/Sep/2026:01:57:26 +0200] "GET /.env.development?raw HTTP/2.0" 200 1606 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)"
34.87.173.238 - - [22/Sep/2026:01:57:26 +0200] "GET /@fs/app/.env.local?import&raw?? HTTP/2.0" 200 1606 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot)"
34.87.173.238 - - [22/Sep/2026:01:57:26 +0200] "GET /.env.development?import&raw HTTP/2.0" 200 1606 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.4; +https://openai.com/gptbot"
34.87.173.238 - - [22/Sep/2026:01:57:26 +0200] "GET /@fs/app/.env?import&raw?? HTTP/2.0" 200 1606 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36; compatible; OAI-SearchBot/1.4; +https://openai.com/searchbot"
34.87.173.238 - - [22/Sep/2026:01:57:26 +0200] "GET /@fs/app/.env.production?import&raw?? HTTP/2.0" 200 1606
...
show less
DNS Compromise
DNS Poisoning
Phishing
Email Spam
Brute-Force
Web App Attack
SSH
๐บ๐ธ
TPI-Abuse
2026-09-21 23:21:34
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 34.87.173.238 (238.173.87.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.87.173.238 (238.173.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 19:21:29.076030 2026] [security2:error] [pid 32117:tid 32178] [client 34.87.173.238:34360] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mentzinger.com|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mentzinger.com"] [uri "/server.key"] [unique_id "arG7-ejPE2gcsqkHyJTMUwAAAEY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 22:48:53
(2 weeks ago)
(mod_security) mod_security (id:949110) triggered by 34.87.173.238 (238.173.87.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:949110) triggered by 34.87.173.238 (238.173.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 18:48:47.431355 2026] [security2:error] [pid 19174:tid 19174] [client 34.87.173.238:59728] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "mail.methowfishing.com"] [uri "/.env.example"] [unique_id "arG0T2KSQvnKs8iKOL0ZPwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-21 22:30:04
(2 weeks ago)
CrowdSec decision: crowdsecurity/http-admin-interface-probing (origin: crowdsec)
Web App Attack
๐ฌ๐ง
consul.to
2026-09-21 21:37:58
(2 weeks ago)
Web attack/malicious scanning detected
Web App Attack
Anonymous
2026-09-21 21:30:03
(2 weeks ago)
CrowdSec decision: crowdsecurity/http-bad-user-agent (origin: crowdsec)
Port Scan
๐บ๐ธ
TPI-Abuse
2026-09-21 21:20:35
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.87.173.238 (238.173.87.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.173.238 (238.173.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 17:20:31.422197 2026] [security2:error] [pid 16956:tid 16956] [client 34.87.173.238:51616] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.bestprostate.com"] [uri "/.env.local"] [unique_id "arGfnyZRe8KeGTo4OOjTHgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Octopuce
2026-09-21 20:26:19
(2 weeks ago)
Aggressive web search of vulnerable pages: /.env /build/.env /config/.env /src/.env /packages/.env ...
show more
Aggressive web search of vulnerable pages: /.env /build/.env /config/.env /src/.env /packages/.env ...
show less
Web App Attack
๐ต๐ซ
www.gregorymariani.com
2026-09-21 20:22:50
(2 weeks ago)
Web App Attack
๐ฉ๐ช
updown.io
2026-09-21 18:02:13
(2 weeks ago)
{"level":"info","ts":1790013721.0652845,"logger":"http.log.access.log1","msg":"handled request","req ...
show more
{"level":"info","ts":1790013721.0652845,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.87.173.238","remote_port":"49022","client_ip":"34.87.173.238","proto":"HTTP/2.0","method":"POST","host":"status.pickspace.com","uri":"/graphql","headers":{"Sec-Fetch-Site":["same-origin"],"Referer":["https://status.pickspace.com"],"Content-Type":["application/json"],"Sec-Ch-Ua-Mobile":["?1"],"Priority":["u=1, i"],"Sec-Fetch-Mode":["cors"],"Sec-Ch-Ua-Platform":["\"Android\""],"User-Agent":["Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Mobile Safari/537.36"],"Sec-Ch-Ua":["\"Not=A?Brand\";v=\"99\", \"Google Chrome\";v=\"151\", \"Chromium\";v=\"151\""],"Content-Length":["86"],"Accept":["*/*"],"Sec-Fetch-Dest":["empty"],"Accept-Encoding":["gzip, deflate, br, zstd"],"Origin":["https://status.pickspace.com"],"Accept-Language":["en-US,en;q=0.9"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"h2","server_name
...
show less
DDoS Attack
Web App Attack
๐ฆ๐บ
rubixstudios
2026-09-21 16:27:02
(2 weeks ago)
Excessive HTTP requests consistent with automated attack behaviour detected by Imunify360
DDoS Attack
Brute-Force
Web App Attack