🇺🇸
TPI-Abuse
2026-09-12 08:33:59
(5 minutes ago)
(mod_security) mod_security (id:210730) triggered by 34.139.159.53 (53.159.139.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.139.159.53 (53.159.139.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 04:33:53.848904 2026] [security2:error] [pid 9414:tid 9414] [client 34.139.159.53:56090] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.cookaccounting.com|F|2"] [data ".cookaccounting.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.cookaccounting.com"] [uri "/z9x8c7v6b5-debug-trigger-mail.cookaccounting.com"] [unique_id "aqUOcQYLKopywG3ozV7jJgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇲🇽
octageeks.com
2026-09-12 04:21:29
(4 hours ago)
Wordpress malicious attack:[octablocked]
Web App Attack
🇩🇪
Hazzard
2026-09-11 23:50:53
(8 hours ago)
(PERMBLOCK) 34.139.159.53 (US/United States/South Carolina/North Charleston/53.159.139.34.bc.googleu ...
show more
(PERMBLOCK) 34.139.159.53 (US/United States/South Carolina/North Charleston/53.159.139.34.bc.googleusercontent.com/[redacted]) has had more than 4 temp blocks
show less
Hacking
🇩🇪
Hazzard
2026-09-11 19:09:24
(13 hours ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
🇬🇧
consul.to
2026-09-11 18:35:31
(14 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇳🇱
Savvii
2026-09-11 18:33:20
(14 hours ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-09-11 18:05:36
(14 hours ago)
Scanning/Probing (11)
Brute-Force
Web App Attack
🇫🇷
dynamix
2026-09-11 17:46:43
(14 hours ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 17:34:26
(15 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.139.159.53 (53.159.139.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.139.159.53 (53.159.139.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 13:34:19.279167 2026] [security2:error] [pid 2047:tid 2047] [client 34.139.159.53:42892] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||corepest.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "corepest.com"] [uri "/z9x8c7v6b5-debug-trigger-corepest.com"] [unique_id "aqQ7m3CgfvawI_HMSC1IOAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-11 17:20:04
(15 hours ago)
Excessive 404/403 errors
Brute-Force
Anonymous
2026-09-11 17:14:56
(15 hours ago)
Blocked by ModSec and CSF
Port Scan
🇫🇷
masterguru
2026-09-11 17:06:20
(15 hours ago)
BAD BOT - Detected and Blocked.. Matched phrase "bytespider" at REQUEST_HEADERS:User-Agent. (1100000 ...
show more
BAD BOT - Detected and Blocked.. Matched phrase "bytespider" at REQUEST_HEADERS:User-Agent. (1100000-193)
show less
Bad Web Bot
🇺🇸
IndigoRidge
2026-09-11 17:04:35
(15 hours ago)
34.139.159.53 - - [11/Sep/2026:13:04:23 -0400] "GET /.aws/credentials HTTP/1.1" 404 98401 "-" "Mozil ...
show more
34.139.159.53 - - [11/Sep/2026:13:04:23 -0400] "GET /.aws/credentials HTTP/1.1" 404 98401 "-" "Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)"
34.139.159.53 - - [11/Sep/2026:13:04:26 -0400] "GET /.git/config HTTP/1.1" 404 98401 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.3; +https://openai.com/gptbot)"
34.139.159.53 - - [11/Sep/2026:13:04:32 -0400] "GET /.env HTTP/1.1" 404 98401 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)"
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 17:04:16
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.139.159.53 (53.159.139.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.139.159.53 (53.159.139.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 13:04:09.444579 2026] [security2:error] [pid 320920:tid 320920] [client 34.139.159.53:55060] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cor-ex.com"] [uri "/.git/HEAD"] [unique_id "aqQ0ic3f3anYl_CpZQDlcAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 16:38:12
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.139.159.53 (53.159.139.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.139.159.53 (53.159.139.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 12:38:04.145398 2026] [security2:error] [pid 12504:tid 12504] [client 34.139.159.53:49034] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "coopstehedwidge.com"] [uri "/.env"] [unique_id "aqQubM8zyFkn3FugAlDzowAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack