๐บ๐ธ
TPI-Abuse
2026-09-17 03:00:47
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 34.153.203.244 (244.203.153.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.153.203.244 (244.203.153.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 23:00:43.959845 2026] [security2:error] [pid 7439:tid 7439] [client 34.153.203.244:56146] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.gadgeteer.net|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.gadgeteer.net"] [uri "/backup.sql"] [unique_id "aqtX2yVWyO81qtMeHZ5ghwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 00:18:11
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 34.153.203.244 (244.203.153.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.153.203.244 (244.203.153.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 20:18:04.239593 2026] [security2:error] [pid 3736:tid 3736] [client 34.153.203.244:55470] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ftp.dealandriaproperties.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ftp.dealandriaproperties.com"] [uri "/backup.sql"] [unique_id "aqsxvIzgO9QpFEiWM43h3AAAADU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 01:42:24
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.153.203.244 (244.203.153.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.153.203.244 (244.203.153.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 21:42:16.601740 2026] [security2:error] [pid 11314:tid 11314] [client 34.153.203.244:51078] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.pcmec.com"] [uri "/.htaccess"] [unique_id "aqiieAmZhupA4dWZcNe_YgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2026-09-14 11:35:31
(1 week ago)
Attempted access to sensitive endpoint (/.vscode/mcp.json) detected. Automated scan or unauthorized ...
show more
Attempted access to sensitive endpoint (/.vscode/mcp.json) detected. Automated scan or unauthorized probing.
show less
Web App Attack
๐บ๐ธ
IndigoRidge
2026-09-11 19:55:12
(1 week ago)
34.153.203.244 - - [11/Sep/2026:15:55:11 -0400] "GET /dump.sql HTTP/1.1" 500 5330 "-" "Mozilla/5.0 ( ...
show more
34.153.203.244 - - [11/Sep/2026:15:55:11 -0400] "GET /dump.sql HTTP/1.1" 500 5330 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36"
34.153.203.244 - - [11/Sep/2026:15:55:11 -0400] "GET /backup.tar.gz HTTP/1.1" 500 5330 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36"
34.153.203.244 - - [11/Sep/2026:15:55:11 -0400] "GET /public_html.zip HTTP/1.1" 500 5330 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36"
...
show less
Web App Attack
Anonymous
2026-09-10 03:23:28
(2 weeks ago)
DNS Compromise
DDoS Attack
๐ฉ๐ช
Hazzard
2026-09-09 09:50:09
(2 weeks ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
๐ณ๐ฑ
BlueWire Hosting
2026-09-08 21:38:16
(2 weeks ago)
Probing websites for vulnerabilities
Web App Attack
SQL Injection
๐ฆ๐น
Tobias Gion
2026-09-08 01:01:48
(2 weeks ago)
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 10:41:17
(2 weeks ago)
34.153.203.244 - - [06/Sep/2026:12:41:16 +0200] "GET /backup.zip HTTP/1.1" 404 548 "-" "Mozilla/5.0 ...
show more
34.153.203.244 - - [06/Sep/2026:12:41:16 +0200] "GET /backup.zip HTTP/1.1" 404 548 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36"
34.153.203.244 - - [06/Sep/2026:12:41:16 +0200] "GET /dump.sql HTTP/1.1" 404 548 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36"
34.153.203.244 - - [06/Sep/2026:12:41:16 +0200] "GET /backup.tar.gz HTTP/1.1" 404 548 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36"
show less
Web App Attack
๐ณ๐ฑ
Cloud86 B.V.
2026-09-06 05:24:02
(2 weeks ago)
categories: DDoS Attack
DDoS Attack
๐บ๐ธ
TPI-Abuse
2026-09-06 05:23:23
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 34.153.203.244 (244.203.153.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.153.203.244 (244.203.153.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 01:23:16.972046 2026] [security2:error] [pid 4449:tid 4449] [client 34.153.203.244:48366] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||travelto.anthonyjoseph.us|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "travelto.anthonyjoseph.us"] [uri "/dump.sql"] [unique_id "apz4xNTFpe8qgUYHmNBwMQAAADQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
interbiznw.com
2026-09-06 04:31:18
(2 weeks ago)
fail2ban-ban
Hacking
Brute-Force
Exploited Host
Web App Attack
๐ฎ๐น
VHosting
2026-09-04 23:40:04
(2 weeks ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ณ๐ฑ
Cloud86 B.V.
2026-09-04 13:42:02
(2 weeks ago)
categories: DDoS Attack
DDoS Attack