๐บ๐ธ
TPI-Abuse
2026-09-22 00:35:59
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.140.111.243 (243.111.140.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.140.111.243 (243.111.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 20:35:52.751166 2026] [security2:error] [pid 7270:tid 7270] [client 34.140.111.243:51362] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||debosden.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "debosden.com"] [uri "/z9x8c7v6b5-debug-trigger-debosden.com"] [unique_id "arHNaPMk4dGhV8hHMshIFgAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-21 23:57:19
(1 day ago)
[ssd1.kdns.gr] httpd-config-scan: sites=www.dacorlaw.com; logs=/var/log/httpd/domains/dacorlaw.com.l ...
show more
[ssd1.kdns.gr] httpd-config-scan: sites=www.dacorlaw.com; logs=/var/log/httpd/domains/dacorlaw.com.log; samples=/.env.www | /.env.live | /.env_1
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 23:24:59
(1 day ago)
(mod_security) mod_security (id:243320) triggered by 34.140.111.243 (243.111.140.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:243320) triggered by 34.140.111.243 (243.111.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 19:24:54.788439 2026] [security2:error] [pid 8468:tid 8508] [client 34.140.111.243:48380] ModSecurity: Access denied with code 403 (phase 2). String match "/.profile" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6621"] [id "243320"] [rev "1"] [msg "COMODO WAF: Information disclosure vulnerability in Cloud Foundry PHP Buildpack (aka php-buildpack) before 4.3.18 and PHP Buildpack Cf-release before 242, as used in Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.6.38 and 1.7.x before 1.7.19 and other products (CVE-2016-6639)||www.deathbyaudiostore.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.deathbyaudiostore.com"] [uri "/.profile"] [unique_id "arG8xnqvK6KaCzEV_BAQOAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-09-21 22:47:50
(1 day ago)
174 requests with url.path */@fs/*
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-21 22:34:55
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.140.111.243 (243.111.140.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.140.111.243 (243.111.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 18:34:51.475190 2026] [security2:error] [pid 19824:tid 19840] [client 34.140.111.243:45000] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "danfriel.com"] [uri "/.env.example"] [unique_id "arGxC5ANsXN-Rk1tQQjX8AAAAQ0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 22:01:35
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.140.111.243 (243.111.140.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.140.111.243 (243.111.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 18:01:29.580389 2026] [security2:error] [pid 12716:tid 12716] [client 34.140.111.243:49146] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.curryfirm.com|F|2"] [data ".curryfirm.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.curryfirm.com"] [uri "/z9x8c7v6b5-debug-trigger-mail.curryfirm.com"] [unique_id "arGpOUMr7MBGWgjj1v-mhAAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 21:26:57
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.140.111.243 (243.111.140.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.140.111.243 (243.111.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 17:26:52.230193 2026] [security2:error] [pid 28030:tid 28030] [client 34.140.111.243:55828] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.debbieweibler.com|F|2"] [data ".debbieweibler.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.debbieweibler.com"] [uri "/z9x8c7v6b5-debug-trigger-www.debbieweibler.com"] [unique_id "arGhHDrZUpVgb4gsIL21lgAAADo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 21:10:32
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.140.111.243 (243.111.140.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.140.111.243 (243.111.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 17:10:27.304715 2026] [security2:error] [pid 5320:tid 5320] [client 34.140.111.243:36568] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.dave-curtis.com|F|2"] [data ".dave-curtis.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.dave-curtis.com"] [uri "/z9x8c7v6b5-debug-trigger-www.dave-curtis.com"] [unique_id "arGdQ8YsofJW_n5geoy7UwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-21 20:35:22
(2 days ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 20:30:33
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.140.111.243 (243.111.140.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.140.111.243 (243.111.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 16:30:25.717045 2026] [security2:error] [pid 9689:tid 9689] [client 34.140.111.243:44402] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cygnetsilks.com"] [uri "/.git/HEAD"] [unique_id "arGT4bNaMjdY0MrBoGUM3gAAAEI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-21 19:59:53
(2 days ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
๐ซ๐ท
dynamix
2026-09-21 19:53:32
(2 days ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 19:36:17
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.140.111.243 (243.111.140.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.140.111.243 (243.111.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 15:36:09.571314 2026] [security2:error] [pid 11449:tid 11449] [client 34.140.111.243:43006] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.dawnmazur.com"] [uri "/.git/config"] [unique_id "arGHKfSFFUNOwMaZ60D1BgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
polycoda
2026-09-21 16:27:33
(2 days ago)
AutoBlock: ๐ก Port Scan (Non Decay-Based)
Port Scan
๐บ๐ธ
TPI-Abuse
2026-09-21 10:38:10
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.140.111.243 (243.111.140.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.140.111.243 (243.111.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 06:38:04.557754 2026] [security2:error] [pid 6256:tid 6256] [client 34.140.111.243:46868] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.ramabahama.net|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.ramabahama.net"] [uri "/ssl/localhost.key"] [unique_id "arEJDCaPWtc3cH0fQONk-QAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack