πΏπ¦
conure.sh
2026-09-30 04:52:13
(2 days ago)
csagent: score 20.0: secrets grab x2; 1 domain(s) in 1s
Web App Attack
π²πΎ
Rizzy
2026-09-30 01:47:59
(3 days ago)
Multiple WAF Violations
Brute-Force
Web App Attack
π«π·
GabrielJST
2026-09-30 01:41:42
(3 days ago)
(mod_security) mod_security triggered on hostname [redacted] 34.141.160.36 (36.160.141.34.bc.googleu ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.141.160.36 (36.160.141.34.bc.googleusercontent.com): (CF_ENABLE)
show less
SQL Injection
Anonymous
2026-09-30 00:41:05
(3 days ago)
Blocked by ModSec and CSF
Port Scan
πͺπΈ
masterguru
2026-09-30 00:30:16
(3 days ago)
BAD BOT - Detected and Blocked.. Matched phrase "GPTBot" at REQUEST_HEADERS:user-agent. (1100000-122 ...
show more
BAD BOT - Detected and Blocked.. Matched phrase "GPTBot" at REQUEST_HEADERS:user-agent. (1100000-122)
show less
Bad Web Bot
π¬π§
Steve
2026-09-30 00:28:36
(3 days ago)
SQL Injection Attempts
Brute-Force
SQL Injection
πΊπΈ
TPI-Abuse
2026-09-30 00:25:04
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 34.141.160.36 (36.160.141.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.141.160.36 (36.160.141.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 20:24:56.205287 2026] [security2:error] [pid 1147:tid 1147] [client 34.141.160.36:43810] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||berklie.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "berklie.com"] [uri "/z9x8c7v6b5-debug-trigger-berklie.com"] [unique_id "arxW2PffzKWJ5jlx6J_WnAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-29 23:59:22
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.141.160.36 (36.160.141.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.141.160.36 (36.160.141.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 19:59:15.963576 2026] [security2:error] [pid 25490:tid 25490] [client 34.141.160.36:44826] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ctrussell.us"] [uri "/.env"] [unique_id "arxQ0_t3g8YktUZSZIUlTQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-29 23:40:12
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.141.160.36 (36.160.141.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.141.160.36 (36.160.141.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 19:40:05.892641 2026] [security2:error] [pid 28185:tid 28185] [client 34.141.160.36:47884] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.cms2020.com"] [uri "/.env.production"] [unique_id "arxMVT7xb4TKiFEQpBDpIgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-29 22:57:52
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.141.160.36 (36.160.141.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.141.160.36 (36.160.141.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 18:57:48.507365 2026] [security2:error] [pid 31645:tid 31645] [client 34.141.160.36:46104] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/Web.config" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.davidwoodard.com"] [uri "/web.config"] [unique_id "arxCbAF-bX9VIz2dUPUtMQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-29 22:39:04
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 34.141.160.36 (36.160.141.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.141.160.36 (36.160.141.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 18:38:58.233427 2026] [security2:error] [pid 20873:tid 20873] [client 34.141.160.36:36732] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bodybuildbid.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bodybuildbid.com"] [uri "/z9x8c7v6b5-debug-trigger-bodybuildbid.com"] [unique_id "arw-AiRVnD51gypxy0dzRAAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-29 22:07:01
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.141.160.36 (36.160.141.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.141.160.36 (36.160.141.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 18:06:56.930199 2026] [security2:error] [pid 15458:tid 15458] [client 34.141.160.36:60660] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.cvoguemag.com"] [uri "/userfiles/x"] [unique_id "arw2gODpUsv8Fet7o8uo5AAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Savvii
2026-09-29 21:58:57
(3 days ago)
21 attempts against mh_ha-misbehave-ban on ec102950
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-29 21:49:52
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 34.141.160.36 (36.160.141.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.141.160.36 (36.160.141.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 17:49:45.556106 2026] [security2:error] [pid 10072:tid 10072] [client 34.141.160.36:46794] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||astrology7.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "astrology7.com"] [uri "/z9x8c7v6b5-debug-trigger-astrology7.com"] [unique_id "arwyeeV5B94YI_vBA6LUNgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Alt255
2026-09-29 21:25:48
(3 days ago)
[ti-07al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-07al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.141.160.36 - - [29/Sep/2026:23:25:39 +0200] "GET /.env HTTP/1.1" 404 2050 "-" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)"
...
show less
Bad Web Bot
Web App Attack