๐บ๐ธ
TPI-Abuse
2026-09-20 15:30:23
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.87.34.196 (196.34.87.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.34.196 (196.34.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 11:30:17.944351 2026] [security2:error] [pid 23247:tid 23247] [client 34.87.34.196:39822] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jordanware.com"] [uri "/internal/.env"] [unique_id "aq_8Ce80yv1ZjAZ3q1Zw8wAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-20 15:23:40
(3 days ago)
[ti-24al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-24al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.87.34.196 - - [20/Sep/2026:17:23:26 +0200] "GET /api/.env HTTP/2.0" 302 139 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-09-20 15:05:13
(4 days ago)
Too many Status 40X (13)
Brute-Force
Web App Attack
๐ณ๐ฑ
ConsulHosting
2026-09-20 15:03:22
(4 days ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
๐ซ๐ท
masterguru
2026-09-20 15:01:27
(4 days ago)
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .back/ .b ...
show more
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .back/ .backup/ .bak/ .bck/ .bk/ .bkp/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .cnf/ .com/ .compositefont/ .config/ .conf/ .copy/ .crt/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dist/ .dll/ .dos/ .dpkg-dist/ .drv/ .gadget/ .hta/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .inf/ .ini/ .jks/ .jse/ .key/ .licx/ .lnk/ .log/ .mdb/ .msc/ .ocx/ .old/ .pass/ .pdb/ .pfx/ .pif/ .pem/ .pol/ .prf/ .printer/ .pwd/ .rdb/ .rdp/ .reg/ .resources/ .resx/ .sav/ .save/ .scr/ .sct/ .sh/ .shs/ .sql/ .sqlite/ .sqlite3/ .swap/ .swo/ .swp/ .sys/ .temp/ .tfstate/ .tlb/ .tmp/ .vb/ .vbe/ .vbs/ .vbproj/ .vsdisco/ .vxd/ .webinfo/ .ws/ .wsc/ .wsf/ .wsh/ .xsd/ .xsx/" at TX:extension. (920440-193)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-20 14:56:49
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 34.87.34.196 (196.34.87.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.87.34.196 (196.34.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 10:56:46.132732 2026] [security2:error] [pid 30791:tid 30791] [client 34.87.34.196:54464] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||jomorise.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "jomorise.com"] [uri "/z9x8c7v6b5-debug-trigger-jomorise.com"] [unique_id "aq_0LmaJVQ-0__RfZ4nlEwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-20 14:47:08
(4 days ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐ซ๐ท
dynamix
2026-09-20 14:02:29
(4 days ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-09-20 13:50:16
(4 days ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ฉ๐ช
yitzhaq
2026-09-20 13:45:33
(4 days ago)
34.87.34.196 - - [20/Sep/2026:15:45:31 +0200] "GET /config/env/aws_credentials.env HTTP/2.0" 404 296 ...
show more
34.87.34.196 - - [20/Sep/2026:15:45:31 +0200] "GET /config/env/aws_credentials.env HTTP/2.0" 404 296 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
34.87.34.196 - - [20/Sep/2026:15:45:31 +0200] "GET /.idea/WebServers.xml HTTP/2.0" 404 296 "-" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)"
34.87.34.196 - - [20/Sep/2026:15:45:31 +0200] "GET /.ssh/id_ecdsa HTTP/2.0" 404 296 "-" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)"
34.87.34.196 - - [20/Sep/2026:15:45:31 +0200] "GET /.vscode/launch.json HTTP/2.0" 404 296 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)"
34.87.34.196 - - [20/Sep/2026:15:45:31 +0200] "GET /.ssh/id_dsa HTTP/2.0" 404 296 "-" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)"
34.87.34.196 - - [20/Sep/2026:15:45:31 +0200] "GET /docker-compose.yaml HTTP/2.0" 403 298 "-" "Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)"
34.87.34.196 - - [20/Sep/2026:15:45:31 +02
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-20 13:41:49
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 34.87.34.196 (196.34.87.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.87.34.196 (196.34.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 09:41:45.115970 2026] [security2:error] [pid 5347:tid 5347] [client 34.87.34.196:39138] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||jogmabogadospenalistas.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "jogmabogadospenalistas.com"] [uri "/rclone.conf"] [unique_id "aq_imRqy1iF1n_f4VikIAQAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 13:25:04
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 34.87.34.196 (196.34.87.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.87.34.196 (196.34.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 09:24:57.646697 2026] [security2:error] [pid 12356:tid 12359] [client 34.87.34.196:36390] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||joeandlane.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "joeandlane.com"] [uri "/z9x8c7v6b5-debug-trigger-joeandlane.com"] [unique_id "aq_eqXxC0kT9B5KaHY8ABQAAAIE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-20 13:09:29
(4 days ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 12:51:31
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.87.34.196 (196.34.87.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.34.196 (196.34.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 08:51:23.077256 2026] [security2:error] [pid 28043:tid 28043] [client 34.87.34.196:48978] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "indie100.com"] [uri "/scripts/.env"] [unique_id "aq_Wy0W905SA3Au51iyCpgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 12:35:04
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.87.34.196 (196.34.87.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.34.196 (196.34.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 08:34:56.201241 2026] [security2:error] [pid 4447:tid 4447] [client 34.87.34.196:48730] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gonzalez.com"] [uri "/.env"] [unique_id "aq_S8DlOu6WjbBDmdAIPRwAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack