๐บ๐ธ
TPI-Abuse
2026-09-11 17:04:26
(1 hour ago)
(mod_security) mod_security (id:210580) triggered by 8.234.254.221 (221.254.234.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210580) triggered by 8.234.254.221 (221.254.234.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 13:04:20.201147 2026] [security2:error] [pid 312573:tid 312573] [client 8.234.254.221:44760] ModSecurity: Access denied with code 403 (phase 2). Matched phrase ".ssh/id_rsa" at ARGS:filename. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||ic1.biz|F|2"] [data "Matched Data: .ssh/id_rsa found within ARGS:filename: file:/root/.ssh/id_rsa"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "ic1.biz"] [uri "/__vite_rsc_findSourceMapURL"] [unique_id "aqQ0lEEG9wj1xGFuoU506AAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
maxxsense
2026-09-11 16:58:19
(1 hour ago)
(mod_security) mod_security triggered on hostname [redacted] 8.234.254.221 (US/United States/221.254 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 8.234.254.221 (US/United States/221.254.234.8.bc.googleusercontent.com)
show less
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-09-11 16:41:59
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 8.234.254.221 (221.254.234.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 8.234.254.221 (221.254.234.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 12:41:55.260325 2026] [security2:error] [pid 22972:tid 22972] [client 8.234.254.221:59518] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||fastpc.biz|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "fastpc.biz"] [uri "/rclone.conf"] [unique_id "aqQvU1BAem7sReqwK-fs9gAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
Progetto1
2026-09-11 16:30:22
(1 hour ago)
Multiple exploit attempts
Hacking
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-11 16:25:14
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 8.234.254.221 (221.254.234.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.234.254.221 (221.254.234.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 12:25:08.894495 2026] [security2:error] [pid 23985:tid 23985] [client 8.234.254.221:56096] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "eclipsesoftware.biz"] [uri "/__vite_rsc_findSourceMapURL"] [unique_id "aqQrZI8S65tbo_k9H86VwAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
zynex
2026-09-11 16:23:55
(1 hour ago)
URL Probing: /.env
Web App Attack
๐ฌ๐ง
consul.to
2026-09-11 16:14:08
(1 hour ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-11 16:10:10
(1 hour ago)
(mod_security) mod_security (id:949110) triggered by 8.234.254.221 (221.254.234.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:949110) triggered by 8.234.254.221 (221.254.234.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 12:10:06.923115 2026] [security2:error] [pid 9429:tid 9429] [client 8.234.254.221:58570] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "clintess.biz"] [uri "/rclone.conf"] [unique_id "aqQn3lJtfrRbHHUDTUjO4AAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-09-11 16:10:04
(1 hour ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ฆ๐บ
2000cn.com.au
2026-09-11 16:00:42
(2 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐จ๐ญ
4server
2026-09-11 15:54:45
(2 hours ago)
[FriSep1117:54:38.4053322026][security2:error][pid3798366:tid3798534][client8.234.254.221:0]ModSecur ...
show more
[FriSep1117:54:38.4053322026][security2:error][pid3798366:tid3798534][client8.234.254.221:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"610\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"benvenutialfood.biz\"][uri\"/@fs/..%2f..%2f..%2f..%2f..%2froot/.env\"][unique_id\"aqQkPmmwcJKX4OHaCAmp3QAAAIE\"]
show less
Hacking
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-11 15:50:42
(2 hours ago)
20 attempts against mh-misbehave-ban on ozone
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-11 15:44:34
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.234.254.221 (221.254.234.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.234.254.221 (221.254.234.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 11:44:26.666666 2026] [security2:error] [pid 21294:tid 21294] [client 8.234.254.221:42238] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "amaia.biz"] [uri "/@fs/.env"] [unique_id "aqQh2pOfPd_Can3L5EAA6gAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Octopuce
2026-09-11 15:37:45
(2 hours ago)
Aggressive web search of vulnerable pages: /dist../.env /js../.env /css../.env /config/.env.php /cor ...
show more
Aggressive web search of vulnerable pages: /dist../.env /js../.env /css../.env /config/.env.php /core/.env ...
show less
Web App Attack