🇺🇸
TPI-Abuse
2026-09-06 21:08:20
(16 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.10.50.249 (249.50.10.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.10.50.249 (249.50.10.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 17:08:14.424215 2026] [security2:error] [pid 26775:tid 26775] [client 34.10.50.249:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.abdulhameeds.art|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.abdulhameeds.art"] [uri "/server.key"] [unique_id "ap3WPl8DrGBVYJyQ6ewrXQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Savvii
2026-09-06 19:48:31
(17 hours ago)
20 attempts against mh-misbehave-ban on kiwi
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 19:33:19
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.10.50.249 (249.50.10.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.10.50.249 (249.50.10.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 15:33:15.505403 2026] [security2:error] [pid 22208:tid 22208] [client 34.10.50.249:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.antitribu.com"] [uri "/@fs/src/.env"] [unique_id "ap2_-wZdBahM1_b5OSoPrQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 18:26:09
(18 hours ago)
Blocked by ModSec and CSF
Port Scan
🇺🇸
TPI-Abuse
2026-09-06 17:20:53
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.10.50.249 (249.50.10.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.10.50.249 (249.50.10.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 13:20:46.265806 2026] [security2:error] [pid 26247:tid 26247] [client 34.10.50.249:57092] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "brazilianbikinis.com"] [uri "/__vite_rsc_findSourceMapURL"] [unique_id "ap2g7uabCFWx1vXe5Ii4ygAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
jormaster3k
2026-09-06 17:05:49
(20 hours ago)
Attack against Apache (too many 404s)
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 16:13:55
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.10.50.249 (249.50.10.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.10.50.249 (249.50.10.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 12:13:47.633745 2026] [security2:error] [pid 20701:tid 20701] [client 34.10.50.249:56826] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.astariafilms.com"] [uri "/api/fs/read"] [unique_id "ap2RO6eI9z6mr5GaHZO4AAAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-06 15:48:39
(21 hours ago)
Excessive 404/403 errors
Brute-Force
🇺🇸
TPI-Abuse
2026-09-06 13:16:30
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.10.50.249 (249.50.10.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.10.50.249 (249.50.10.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 09:16:24.856151 2026] [security2:error] [pid 18325:tid 18325] [client 34.10.50.249:43670] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.buggyshop.org"] [uri "/@fs/src/.env"] [unique_id "ap1nqOEeFB62Nf8Ubur3xAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 12:57:53
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.10.50.249 (249.50.10.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.10.50.249 (249.50.10.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 08:57:49.004322 2026] [security2:error] [pid 6051:tid 6051] [client 34.10.50.249:40484] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ardath.net|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ardath.net"] [uri "/rclone.conf"] [unique_id "ap1jTQHXoINtN1Or5wS-UQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 12:42:18
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.10.50.249 (249.50.10.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.10.50.249 (249.50.10.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 08:42:15.032053 2026] [security2:error] [pid 11340:tid 11340] [client 34.10.50.249:39784] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.3905ccn.us|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.3905ccn.us"] [uri "/rclone.conf"] [unique_id "ap1fpxdacvt6YgyZrZx-RgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 12:04:48
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.10.50.249 (249.50.10.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.10.50.249 (249.50.10.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 08:04:40.371068 2026] [security2:error] [pid 6716:tid 6716] [client 34.10.50.249:42192] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||30daysout.com|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "30daysout.com"] [uri "/server.key"] [unique_id "ap1W2CsJXysipsr0VAGAagAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 10:04:37
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.10.50.249 (249.50.10.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.10.50.249 (249.50.10.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 06:04:29.766061 2026] [security2:error] [pid 10006:tid 10006] [client 34.10.50.249:36848] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.accordionstars.com"] [uri "/@fs/src/.env"] [unique_id "ap06rRLje0x2X5bf3etZlwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-06 09:30:21
(1 day ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 09:27:06
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.10.50.249 (249.50.10.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.10.50.249 (249.50.10.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 05:26:59.398769 2026] [security2:error] [pid 17291:tid 17291] [client 34.10.50.249:48714] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.15tobefit.com"] [uri "/@fs/app/.env.production"] [unique_id "ap0x4-gAIkglAqj41WQy7wAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack