๐ฟ๐ฆ
conure.sh
2026-10-02 12:09:51
(1 day ago)
csagent: score 22.2: 404 noise floor x43, php 404 x1, secrets grab x1; 1 domain(s) in 1s
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 17:55:41
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.156.174.231 (231.174.156.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.156.174.231 (231.174.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 13:55:36.818599 2026] [security2:error] [pid 17983:tid 17983] [client 34.156.174.231:56732] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.dwars.net"] [uri "/wp-config.php.old"] [unique_id "ar6emImTg1oCIEkeWgw1AAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 17:35:39
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.156.174.231 (231.174.156.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.156.174.231 (231.174.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 13:35:35.067281 2026] [security2:error] [pid 20588:tid 20588] [client 34.156.174.231:47500] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.calentadoresdemexico.com.mx|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.calentadoresdemexico.com.mx"] [uri "/rclone.conf"] [unique_id "ar6Z5_sAXF9fXlhp5yBLUgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-01 16:40:02
(2 days ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 15:43:41
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.156.174.231 (231.174.156.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.156.174.231 (231.174.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 11:43:34.381036 2026] [security2:error] [pid 22499:tid 22499] [client 34.156.174.231:59824] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||cdhcreations.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "cdhcreations.com"] [uri "/z9x8c7v6b5-debug-trigger-cdhcreations.com"] [unique_id "ar5_pqhS75sZIcVhurEr5gAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-10-01 15:08:44
(2 days ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-10-01 14:18:35
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.156.174.231 (231.174.156.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.156.174.231 (231.174.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 10:18:27.741824 2026] [security2:error] [pid 659:tid 659] [client 34.156.174.231:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.bbproductionsonline.com"] [uri "/.htpasswd"] [unique_id "ar5rswphk7NgPjwJks9-EwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 14:03:08
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.156.174.231 (231.174.156.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.156.174.231 (231.174.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 10:03:02.048704 2026] [security2:error] [pid 6845:tid 6845] [client 34.156.174.231:56086] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/Web.config" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.cspminc.com"] [uri "/web.config"] [unique_id "ar5oFiIf5O7aYcJdW5S9UAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 13:39:47
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.156.174.231 (231.174.156.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.156.174.231 (231.174.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 09:39:41.973098 2026] [security2:error] [pid 6158:tid 6158] [client 34.156.174.231:41540] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.antoniocobo.com"] [uri "/.env.js"] [unique_id "ar5inQjiAFU1ufca82YkpAAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 13:14:57
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.156.174.231 (231.174.156.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.156.174.231 (231.174.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 09:14:51.348830 2026] [security2:error] [pid 10494:tid 10494] [client 34.156.174.231:39374] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.brianwhitty.com"] [uri "/.env.production"] [unique_id "ar5cy703bZj5GY7UbOdV5AAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alboweb B.V.
2026-10-01 13:11:03
(2 days ago)
Bad web bot activity detected by Fail2Ban in plesk-apache-badbot jail
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-01 12:55:45
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.156.174.231 (231.174.156.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.156.174.231 (231.174.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 08:55:40.872514 2026] [security2:error] [pid 11710:tid 11720] [client 34.156.174.231:59928] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.docdalton.com|F|2"] [data ".docdalton.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.docdalton.com"] [uri "/z9x8c7v6b5-debug-trigger-www.docdalton.com"] [unique_id "ar5YTITzA043BtsmzAJfHgAAAMg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
oralunal
2026-10-01 12:34:53
(2 days ago)
IP banned by Fail2Ban in jail ah-suss access.log mvfnds
...
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 12:03:08
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.156.174.231 (231.174.156.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.156.174.231 (231.174.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 08:03:04.387239 2026] [security2:error] [pid 19560:tid 19560] [client 34.156.174.231:32982] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bookguardian.net"] [uri "/.env.js"] [unique_id "ar5L-NgT18qflx8k8VvfFQAAADE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 10:57:20
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.156.174.231 (231.174.156.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.156.174.231 (231.174.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 06:57:14.861344 2026] [security2:error] [pid 1463:tid 1463] [client 34.156.174.231:39628] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.canadianwildlifemuseum.com|F|2"] [data ".canadianwildlifemuseum.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.canadianwildlifemuseum.com"] [uri "/z9x8c7v6b5-debug-trigger-www.canadianwildlifemuseum.com"] [unique_id "ar48ihSImNerH_aaWpbcxgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack