๐บ๐ธ
TPI-Abuse
2026-09-11 16:36:23
(17 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.94.89.163 (163.89.94.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.94.89.163 (163.89.94.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 12:36:16.907562 2026] [security2:error] [pid 4174:tid 4174] [client 34.94.89.163:43900] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mvscouts.org"] [uri "/@fs/.env"] [unique_id "aqQuAJJHjgf2iawyUjGX1AAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-11 16:28:36
(25 minutes ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-11 16:20:39
(33 minutes ago)
(mod_security) mod_security (id:210730) triggered by 34.94.89.163 (163.89.94.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.94.89.163 (163.89.94.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 12:20:34.496379 2026] [security2:error] [pid 26061:tid 26061] [client 34.94.89.163:48024] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mroxygen.org|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mroxygen.org"] [uri "/host.key"] [unique_id "aqQqUjK8tYbXgGm-ph854gAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-11 16:15:03
(39 minutes ago)
crowdsecurity/http-path-traversal-probing
Brute-Force
Web App Attack
๐บ๐ธ
IndigoRidge
2026-09-11 16:13:41
(40 minutes ago)
34.94.89.163 - - [11/Sep/2026:12:13:39 -0400] "GET /@fs/src/.env?raw?? HTTP/1.1" 404 68844 "-" "Mozi ...
show more
34.94.89.163 - - [11/Sep/2026:12:13:39 -0400] "GET /@fs/src/.env?raw?? HTTP/1.1" 404 68844 "-" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)"
34.94.89.163 - - [11/Sep/2026:12:13:39 -0400] "GET /@fs/../.env?raw?? HTTP/1.1" 404 68844 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.3; +https://openai.com/gptbot)"
34.94.89.163 - - [11/Sep/2026:12:13:39 -0400] "GET /@fs/app/.env?raw?? HTTP/1.1" 404 68844 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; OAI-SearchBot/1.0; +https://openai.com/searchbot)"
...
show less
Web App Attack
Anonymous
2026-09-11 16:05:26
(48 minutes ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐ฎ๐น
VHosting
2026-09-11 16:05:03
(49 minutes ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ซ๐ท
Octopuce
2026-09-11 16:01:13
(52 minutes ago)
Aggressive web search of vulnerable pages: /secrets.env /config/env/aws_credentials.env /_nuxt/../.e ...
show more
Aggressive web search of vulnerable pages: /secrets.env /config/env/aws_credentials.env /_nuxt/../.env /@fs/src/.env?raw?? /@fs/app/.env?raw?? ...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-11 15:59:13
(54 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.94.89.163 (163.89.94.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.94.89.163 (163.89.94.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 11:59:07.771373 2026] [security2:error] [pid 1576:tid 1576] [client 34.94.89.163:37224] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "moleculardetective.org"] [uri "/.git/HEAD"] [unique_id "aqQlSxA6NkCHtFkKPWzztwAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack