🇺🇸
TPI-Abuse
2026-09-12 06:06:36
(8 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.140.118.216 (216.118.140.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.140.118.216 (216.118.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 02:06:32.867073 2026] [security2:error] [pid 22397:tid 22397] [client 34.140.118.216:32918] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.daytonatactical.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.daytonatactical.com"] [uri "/rclone.conf"] [unique_id "aqTr6F4mfC_-4QgFQI-KxgAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 18:56:11
(19 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.140.118.216 (216.118.140.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.140.118.216 (216.118.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 14:56:06.033457 2026] [security2:error] [pid 20504:tid 20504] [client 34.140.118.216:44114] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||dbrooketaylor.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "dbrooketaylor.com"] [uri "/rclone.conf"] [unique_id "aqROxhq_Hm4rD2TdprslzQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇹
penguin-solutions.at
2026-09-11 18:16:43
(20 hours ago)
Excessive 403/404 errors
...
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 17:50:01
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.140.118.216 (216.118.140.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.140.118.216 (216.118.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 13:49:55.416009 2026] [security2:error] [pid 1527:tid 1527] [client 34.140.118.216:56644] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "davidrayskinner.com"] [uri "/uploads../.env"] [unique_id "aqQ_Q66ZKN1eHrTtyl6_TwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-11 17:50:01
(20 hours ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection
🇯🇵
Valhalla
2026-09-11 17:38:19
(20 hours ago)
/.aws/config
Hacking
Web App Attack
🇫🇷
masterguru
2026-09-11 17:37:01
(20 hours ago)
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encod ...
show more
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encoding/ /proxy/ /lock-token/ /content-range/ /if/ /x-http-method-override/ /x-http-method/ /x-method-override/ /x-middleware-subrequest/ /expect/" at TX:header_name_920450_x-middleware-subrequest. (920450-197)
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-11 17:34:57
(20 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.140.118.216 (216.118.140.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.140.118.216 (216.118.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 13:34:49.678480 2026] [security2:error] [pid 31973:tid 31973] [client 34.140.118.216:50754] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||daviddenotaris.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "daviddenotaris.com"] [uri "/z9x8c7v6b5-debug-trigger-daviddenotaris.com"] [unique_id "aqQ7ufLLPCMONs6Handv1AAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 17:17:13
(21 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.140.118.216 (216.118.140.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.140.118.216 (216.118.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 13:17:09.096273 2026] [security2:error] [pid 3930:tid 3930] [client 34.140.118.216:42818] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||daveclick.com|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "daveclick.com"] [uri "/server.key"] [unique_id "aqQ3lSBLzrXzzTm-vqyrugAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-11 16:53:29
(21 hours ago)
Web application attack detected.
Web App Attack
🇩🇪
ghostwarriors
2026-09-11 16:50:04
(21 hours ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
🇩🇪
yitzhaq
2026-09-11 16:32:32
(21 hours ago)
34.140.118.216 - - [11/Sep/2026:18:32:30 +0200] "GET /serverless.yml HTTP/2.0" 404 25751 "-" "DuckAs ...
show more
34.140.118.216 - - [11/Sep/2026:18:32:30 +0200] "GET /serverless.yml HTTP/2.0" 404 25751 "-" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)"
34.140.118.216 - - [11/Sep/2026:18:32:30 +0200] "GET /.ssh/known_hosts HTTP/2.0" 404 25751 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)"
34.140.118.216 - - [11/Sep/2026:18:32:30 +0200] "GET /docker-compose.yaml HTTP/2.0" 404 25751 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email])"
34.140.118.216 - - [11/Sep/2026:18:32:30 +0200] "GET /serverless.yaml HTTP/2.0" 404 25751 "-" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)"
34.140.118.216 - - [11/Sep/2026:18:32:30 +0200] "GET /config/env/aws_credentials.env HTTP/2.0" 404 25751 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)"
34.140.118.216 - - [11/Sep/2026:18:32:30 +0200] "GET /id_rsa HTTP/2.0" 404 25742 "-" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)"
34.140.118.21
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-11 16:27:42
(21 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.140.118.216 (216.118.140.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.140.118.216 (216.118.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 12:27:37.237637 2026] [security2:error] [pid 15975:tid 15999] [client 34.140.118.216:35580] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||dashcammvp.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "dashcammvp.com"] [uri "/z9x8c7v6b5-debug-trigger-dashcammvp.com"] [unique_id "aqQr-Uv_4QzT3u-EZQ5UWwAAAVY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-11 16:25:23
(21 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇳🇱
Savvii
2026-09-11 16:13:59
(22 hours ago)
20 attempts against mh-misbehave-ban on chive
Brute-Force
Bad Web Bot
Web App Attack