๐บ๐ธ
TPI-Abuse
2026-10-09 04:10:45
(10 minutes ago)
(mod_security) mod_security (id:210730) triggered by 34.139.226.242 (242.226.139.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.139.226.242 (242.226.139.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 00:10:39.635651 2026] [security2:error] [pid 27691:tid 27691] [client 34.139.226.242:57550] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||michaelgardner.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "michaelgardner.com"] [uri "/z9x8c7v6b5-debug-trigger-michaelgardner.com"] [unique_id "ashpP9UgG4uKQVady3O2xQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-09 04:05:38
(16 minutes ago)
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: US, Attack patterns: Clou ...
show more
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: US, Attack patterns: Cloud secrets probing, Directory traversal
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 03:42:16
(39 minutes ago)
(mod_security) mod_security (id:210730) triggered by 34.139.226.242 (242.226.139.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.139.226.242 (242.226.139.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 23:42:11.170239 2026] [security2:error] [pid 24263:tid 24263] [client 34.139.226.242:33274] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||menafert.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "menafert.com"] [uri "/z9x8c7v6b5-debug-trigger-menafert.com"] [unique_id "ashik0czERwZfuU7ol4YZQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-09 03:03:03
(1 hour ago)
[cb-06al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[cb-06al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.139.226.242 - - [09/Oct/2026:05:03:00 +0200] "GET /css../.env HTTP/2.0" 404 1338 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)"
...
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-10-09 01:13:52
(3 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
Anonymous
2026-10-09 01:11:42
(3 hours ago)
Blocked by ModSec and CSF
Port Scan
๐ณ๐ฑ
Site.eu
2026-10-09 01:01:35
(3 hours ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-10-09 00:54:17
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.139.226.242 (242.226.139.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.139.226.242 (242.226.139.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 20:54:09.864442 2026] [security2:error] [pid 18798:tid 18798] [client 34.139.226.242:39228] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||luciferdirective.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "luciferdirective.com"] [uri "/z9x8c7v6b5-debug-trigger-luciferdirective.com"] [unique_id "asg7MeITneCavXj9u9l-EQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
masterguru
2026-10-09 00:38:11
(3 hours ago)
BAD BOT - Detected and Blocked.. Matched phrase "ccbot" at REQUEST_HEADERS:User-Agent. (1100000-122)
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-08 23:14:15
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.139.226.242 (242.226.139.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.139.226.242 (242.226.139.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 19:14:07.984656 2026] [security2:error] [pid 8353:tid 8353] [client 34.139.226.242:50594] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "leonardodecaprio.com"] [uri "/.env.js"] [unique_id "asgjv1aMpG9DHtH-w7s3DwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 22:40:40
(5 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.139.226.242 (242.226.139.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.139.226.242 (242.226.139.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 18:40:35.068365 2026] [security2:error] [pid 1766:tid 1766] [client 34.139.226.242:50222] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||laura-stone.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "laura-stone.com"] [uri "/z9x8c7v6b5-debug-trigger-laura-stone.com"] [unique_id "asgb427EKeL3KRqyjv-21gAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-10-08 22:23:18
(5 hours ago)
csagent: score 20.0: secrets grab x2; 1 domain(s) in 2s
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 22:15:12
(6 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.139.226.242 (242.226.139.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.139.226.242 (242.226.139.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 18:15:05.014477 2026] [security2:error] [pid 5774:tid 5774] [client 34.139.226.242:45702] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||lamariposagallery.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "lamariposagallery.com"] [uri "/z9x8c7v6b5-debug-trigger-lamariposagallery.com"] [unique_id "asgV6Yn0hDCEkWKTdf9qMQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-08 21:58:04
(6 hours ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-10-08 21:34:10
(6 hours ago)
(mod_security) mod_security (id:218420) triggered by 34.139.226.242 (242.226.139.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:218420) triggered by 34.139.226.242 (242.226.139.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 17:34:07.087774 2026] [security2:error] [pid 26283:tid 26283] [client 34.139.226.242:57916] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i)php://(std(in|out|err)|(in|out)put|fd|memory|temp|filter)" at ARGS_NAMES:\\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/21_PHP_PHPGen.conf"] [line "22"] [id "218420"] [rev "2"] [msg "COMODO WAF: PHP Injection Attack: I/O Stream Found||kritaka.ai|F|2"] [data "Matched Data: php://input found within ARGS_NAMES:\\x5cxadd allow_url_include=1 \\x5cxadd auto_prepend_file=php://input: \\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input"] [severity "CRITICAL"] [tag "CWAF"] [tag "PHPGen"] [hostname "kritaka.ai"] [uri "/index.php"] [unique_id "asgMTyEkZkTZW8n5DWnLegAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack