๐ณ๐ฑ
Site.eu
2026-10-03 08:19:24
(7 minutes ago)
Excessive multi-domain requests
Brute-Force
๐ซ๐ท
dynamix
2026-10-03 06:29:21
(1 hour ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-03 06:27:42
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.95.203.99 (99.203.95.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.95.203.99 (99.203.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 03 02:27:38.656729 2026] [security2:error] [pid 7132:tid 7132] [client 34.95.203.99:48732] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.garrelsms.com"] [uri "/.env.swp"] [unique_id "asCgWjtjTGYohaC9UlApvgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-03 04:55:34
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.95.203.99 (99.203.95.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.95.203.99 (99.203.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 03 00:55:28.475761 2026] [security2:error] [pid 3002:tid 3002] [client 34.95.203.99:46020] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.salernospizza.com|F|2"] [data ".salernospizza.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.salernospizza.com"] [uri "/z9x8c7v6b5-debug-trigger-www.salernospizza.com"] [unique_id "asCKwBiimxVO-PDpUEBM0AAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
bazter.pro
2026-10-03 04:21:41
(4 hours ago)
Fail2Ban: plesk-bot-aggressive - 15 failures
Port Scan
Bad Web Bot
Web App Attack
Anonymous
2026-10-03 02:07:03
(6 hours ago)
Automated web scanner. Requested suspicious paths: /.vite/manifest.json | /dist/.vite/manifest.json ...
show more
Automated web scanner. Requested suspicious paths: /.vite/manifest.json | /dist/.vite/manifest.json | /build/manifest.json | /dist/manifest.json | /z9x8c7v6b5-debug-trigger-www.tigzig.com. UTC: 2026-10-03 01:11:38.
show less
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-03 01:06:19
(7 hours ago)
[ti-03tr] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-03tr] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.95.203.99 - - [03/Oct/2026:03:06:14 +0200] "GET /js../.env HTTP/2.0" 404 2918 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-03 00:57:39
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.95.203.99 (99.203.95.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.95.203.99 (99.203.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 20:57:35.054224 2026] [security2:error] [pid 8012:tid 8032] [client 34.95.203.99:55756] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.geekshop.com"] [uri "/media../.env"] [unique_id "asBS_8che2yC4qf5aNchdQAAAU0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
raph
2026-10-03 00:05:35
(8 hours ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
๐ฉ๐ช
thesimonmanuel
2026-10-02 19:02:03
(13 hours ago)
34.95.203.99 - - [03/Oct/2026:00:32:03 +0530] "GET /img../.env HTTP/2.0" 403 106 "-" "Mozilla/5.0 Ap ...
show more
34.95.203.99 - - [03/Oct/2026:00:32:03 +0530] "GET /img../.env HTTP/2.0" 403 106 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot)"
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 18:03:43
(14 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.95.203.99 (99.203.95.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.95.203.99 (99.203.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 14:03:36.851963 2026] [security2:error] [pid 8297:tid 8297] [client 34.95.203.99:45232] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||gellertdealers.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "gellertdealers.com"] [uri "/z9x8c7v6b5-debug-trigger-gellertdealers.com"] [unique_id "ar_x-DgsPXwAGdwB1Pw1ggAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ardexter
2026-10-02 17:12:17
(15 hours ago)
Wordpress attack and DDOS
DDoS Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 16:50:49
(15 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.95.203.99 (99.203.95.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.95.203.99 (99.203.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 12:50:44.652147 2026] [security2:error] [pid 26099:tid 26201] [client 34.95.203.99:50424] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.thebiglies.com|F|2"] [data ".thebiglies.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.thebiglies.com"] [uri "/z9x8c7v6b5-debug-trigger-www.thebiglies.com"] [unique_id "ar_g5M7CcA9n15cxLlt1fwAAAMA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
middelkoopcc
2026-10-02 15:27:01
(17 hours ago)
2026-10-02 17:18:44 GET /firebase.json [301] && 2026-10-02 17:18:44 GET /api/console/api_server?sens ...
show more
2026-10-02 17:18:44 GET /firebase.json [301] && 2026-10-02 17:18:44 GET /api/console/api_server?sense_version=%40%40SENSE_VERSION&apis=../../../../../../.env [301] && 2026-10-02 17:18:45 GET /settings.json [301] && 172 more within 20 minutes
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 15:24:44
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.95.203.99 (99.203.95.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.95.203.99 (99.203.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 11:24:39.485983 2026] [security2:error] [pid 8574:tid 8574] [client 34.95.203.99:56930] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.gemco-mfg.com"] [uri "/.htpasswd"] [unique_id "ar_Mtyzi_5ePhM40Dg8cTgAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack