๐บ๐ธ
TPI-Abuse
2026-10-09 06:05:57
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.118.179.137 (137.179.118.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.118.179.137 (137.179.118.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 02:05:52.830916 2026] [security2:error] [pid 838:tid 838] [client 34.118.179.137:33028] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||chicagowca.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "chicagowca.com"] [uri "/z9x8c7v6b5-debug-trigger-chicagowca.com"] [unique_id "asiEQG0_jLOSk4pHEtUmQwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-09 05:28:11
(4 hours ago)
Blocked by ModSec and CSF
Port Scan
๐ณ๐ฑ
Site.eu
2026-10-09 04:55:33
(5 hours ago)
Excessive 404/403 errors
Brute-Force
Anonymous
2026-10-09 04:10:54
(6 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.118.179.137 (CA/Canada/137.179.118.3 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.118.179.137 (CA/Canada/137.179.118.34.bc.googleusercontent.com)
show less
SQL Injection
๐ท๐ธ
pexodelic
2026-10-09 03:05:02
(7 hours ago)
Automated report from web, SSH and FTP server logs: 168 requests probing for exposed secrets (.env, ...
show more
Automated report from web, SSH and FTP server logs: 168 requests probing for exposed secrets (.env, .git, config files). First reported 2026-10-09 02:05 UTC, last reported 2026-10-09 05:05 UTC; counts cover the current log rotation window.
show less
Hacking
Web App Attack
๐ฆ๐บ
rubixstudios
2026-10-09 02:56:02
(7 hours ago)
Excessive HTTP requests consistent with automated attack behaviour detected by Imunify360
DDoS Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 02:09:09
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.118.179.137 (137.179.118.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.118.179.137 (137.179.118.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 22:09:03.047621 2026] [security2:error] [pid 26510:tid 26510] [client 34.118.179.137:55436] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "blackriverarc.org"] [uri "/static../.env"] [unique_id "ashMvx885ie5KNap87rHjwAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-10-09 01:48:29
(8 hours ago)
20 attempts against mh-misbehave-ban on kiwi
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Stara
2026-10-09 01:42:18
(8 hours ago)
ModSecurity detected web attack - .env/config probing or SQLi/Code injection (Rule 949110)
Brute-Force
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 01:41:06
(8 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.118.179.137 (137.179.118.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.118.179.137 (137.179.118.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 21:41:01.519683 2026] [security2:error] [pid 24135:tid 24135] [client 34.118.179.137:51918] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||bikinipageone.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bikinipageone.com"] [uri "/z9x8c7v6b5-debug-trigger-bikinipageone.com"] [unique_id "ashGLYQGliy8LhVy2pm8agAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Greg Poulson
2026-10-09 01:16:48
(9 hours ago)
Our website was hit by this DDOS at a rate of 108 in 5 minutes.
DDoS Attack
Web Spam
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-10-09 00:55:43
(9 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.118.179.137 (137.179.118.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.118.179.137 (137.179.118.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 20:55:36.692764 2026] [security2:error] [pid 11525:tid 11525] [client 34.118.179.137:34118] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||belize-boat-registration.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "belize-boat-registration.com"] [uri "/z9x8c7v6b5-debug-trigger-belize-boat-registration.com"] [unique_id "asg7iHToxQV5O3D05BFzkgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-10-09 00:54:34
(9 hours ago)
Excessive multi-domain requests
Brute-Force
๐ซ๐ท
GabrielJST
2026-10-09 00:45:23
(9 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.118.179.137 (CA/Canada/137.179.118.3 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.118.179.137 (CA/Canada/137.179.118.34.bc.googleusercontent.com): (CF_ENABLE)
show less
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-10-09 00:14:42
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.118.179.137 (137.179.118.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.118.179.137 (137.179.118.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 20:14:36.734001 2026] [security2:error] [pid 27628:tid 27628] [client 34.118.179.137:59360] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "barecreationsaz.com"] [uri "/static../.env"] [unique_id "asgx7Cisc550rRWyfTAu-QAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack