Anonymous
2026-10-01 15:39:13
(2 days ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-01 15:24:04
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.143.157.201 (201.157.143.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.143.157.201 (201.157.143.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 11:24:00.998062 2026] [security2:error] [pid 24705:tid 24719] [client 34.143.157.201:52054] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.kincers.com"] [uri "/.env.development"] [unique_id "ar57EIA_c8aNdCvGBTagVgAAAIw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 14:56:11
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.143.157.201 (201.157.143.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.143.157.201 (201.157.143.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 10:56:07.540227 2026] [security2:error] [pid 3510:tid 3510] [client 34.143.157.201:39046] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||killeramps.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "killeramps.com"] [uri "/z9x8c7v6b5-debug-trigger-killeramps.com"] [unique_id "ar50hwJiXC4Zr6ilfbRbPgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Gwyneth Llewelyn
2026-10-01 14:40:08
(2 days ago)
34.143.157.201 - - [01/Oct/2026:15:40:06 +0100] "POST /cgi-bin/php-cgi.exe?%ADd+allow_url_include%3d ...
show more
34.143.157.201 - - [01/Oct/2026:15:40:06 +0100] "POST /cgi-bin/php-cgi.exe?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input HTTP/2.0" 404 994 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot)"
show less
Bad Web Bot
Anonymous
2026-10-01 14:39:18
(2 days ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
๐ณ๐ฑ
middelkoopcc
2026-10-01 14:08:27
(2 days ago)
2026-10-01 15:52:23 GET /local.settings.json [301] && 2026-10-01 15:52:23 GET /appsettings.Developme ...
show more
2026-10-01 15:52:23 GET /local.settings.json [301] && 2026-10-01 15:52:23 GET /appsettings.Development.json [301] && 2026-10-01 15:52:23 GET /appsettings.Production.json [301] && 102 more within 20 minutes
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 13:51:55
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.143.157.201 (201.157.143.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.143.157.201 (201.157.143.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 09:51:49.625404 2026] [security2:error] [pid 3288:tid 3288] [client 34.143.157.201:42488] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.alanmariotti.com|F|2"] [data ".alanmariotti.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.alanmariotti.com"] [uri "/z9x8c7v6b5-debug-trigger-www.alanmariotti.com"] [unique_id "ar5lddiGeUa-KZAau3W78wAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-10-01 13:50:04
(2 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ท๐ด
clauss
2026-10-01 13:37:45
(2 days ago)
34.143.157.201 - - [01/Oct/2026:16:37:43 +0300] "GET /rclone.conf HTTP/2.0" 403 146 "-" "Mozilla/5.0 ...
show more
34.143.157.201 - - [01/Oct/2026:16:37:43 +0300] "GET /rclone.conf HTTP/2.0" 403 146 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1)"
34.143.157.201 - - [01/Oct/2026:16:37:44 +0300] "GET /__vite_rsc_findSourceMapURL?filename=file:///root/.aws/credentials&environmentName=rsc HTTP/2.0" 404 13686 "-" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 13:32:47
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.143.157.201 (201.157.143.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.143.157.201 (201.157.143.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 09:32:39.394844 2026] [security2:error] [pid 5812:tid 5812] [client 34.143.157.201:33030] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.mykelmilur.com"] [uri "/.htpasswd"] [unique_id "ar5g92sdSKxid9tJ8bG9AAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-10-01 13:27:55
(2 days ago)
Remote Command Execution: Direct Unix Command Execution. Pattern match "(?i)(?:^|b (932250-195)
Hacking
Anonymous
2026-10-01 12:46:57
(2 days ago)
XSS Attempt
Hacking
๐บ๐ธ
JustMeHere
2026-10-01 12:18:12
(2 days ago)
[Thu Oct 01 08:18:07.946415 2026] [security2:error] [pid 1173:tid 1203] [client 34.143.157.201:45712 ...
show more
[Thu Oct 01 08:18:07.946415 2026] [security2:error] [pid 1173:tid 1203] [client 34.143.157.201:45712] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.15.0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "data.yorknation.com"] [uri "/"] [unique_id "ar5Pf6ZCfhWBSqag2xxlKQAAAMI"]
...
show less
Web App Attack