๐บ๐ธ
chronos
2026-10-02 23:13:45
(4 hours ago)
[AUTORAVALT][[02/10/2026 - 20:13:45 -03:00 UTC]
Attack from [Google LLC]
[34.170.212.190][190.212.17 ...
show more
[AUTORAVALT][[02/10/2026 - 20:13:45 -03:00 UTC]
Attack from [Google LLC]
[34.170.212.190][190.212.170.34.bc.googleusercontent.com]
Action: BLocKed
DDoS Attack -> Participating in distributed denial-of-service.
Phishing -> Phishing websites and/or email.
Web Spam -> Comment/forum spam, HTTP referer spam, or other CMS spam.
Blog Spam -> CMS blog comment spam.
W]
...
show less
DDoS Attack
Phishing
Web Spam
Blog Spam
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 18:44:32
(8 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.170.212.190 (190.212.170.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.170.212.190 (190.212.170.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 14:44:28.812839 2026] [security2:error] [pid 26831:tid 26831] [client 34.170.212.190:53598] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kronrod.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kronrod.com"] [uri "/z9x8c7v6b5-debug-trigger-kronrod.com"] [unique_id "ar_7jFZ0biGj6Cjhrvu1rQAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 18:16:22
(9 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.170.212.190 (190.212.170.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.170.212.190 (190.212.170.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 14:16:17.730675 2026] [security2:error] [pid 30962:tid 30962] [client 34.170.212.190:59192] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||jhollingshead.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "jhollingshead.com"] [uri "/z9x8c7v6b5-debug-trigger-jhollingshead.com"] [unique_id "ar_08b-oMSw-47dakmUh7AAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
polycoda
2026-10-02 18:06:23
(9 hours ago)
AutoBlock: ๐ก Port Scan (Non Decay-Based) - โ Excessive 40X Errors (Decay-Based)
Port Scan
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-02 17:43:46
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.170.212.190 (190.212.170.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.170.212.190 (190.212.170.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 13:43:40.385887 2026] [security2:error] [pid 24352:tid 24352] [client 34.170.212.190:35546] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.nationalnova.com"] [uri "/static../.env"] [unique_id "ar_tTGVKS3jJjtlUtHXnsAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
WebNiraj
2026-10-02 16:58:15
(10 hours ago)
(cpanel,mod_security) Login failure/trigger from 34.170.212.190 (US/United States/190.212.170.34.bc. ...
show more
(cpanel,mod_security) Login failure/trigger from 34.170.212.190 (US/United States/190.212.170.34.bc.googleusercontent.com): 5 in the last 3600 secs [SIGMA]
show less
Brute-Force
Web App Attack
๐ช๐ธ
pipeline.es
2026-10-02 16:19:45
(11 hours ago)
Web scanning / probing for vulnerable paths | URL: /dist/.env | Evidence: 34.170.212.190 - - [02/Oct ...
show more
Web scanning / probing for vulnerable paths | URL: /dist/.env | Evidence: 34.170.212.190 - - [02/Oct/2026:18:17:25 +0200] \"GET /dist/.env HTTP/1.1\" 404 207 \"-\" \"Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email])\" | ASN: GOOGLE-CLOUD-PLATFORM | Country: US
show less
Port Scan
Web App Attack
๐ช๐ธ
masterguru
2026-10-02 15:58:36
(11 hours ago)
Inbound Anomaly Score Exceeded (Total Score: 5). Operator GE matched 5 at TX:anomaly_score. (949110- ...
show more
Inbound Anomaly Score Exceeded (Total Score: 5). Operator GE matched 5 at TX:anomaly_score. (949110-122)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-02 15:16:41
(12 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.170.212.190 (190.212.170.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.170.212.190 (190.212.170.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 11:16:35.214059 2026] [security2:error] [pid 15447:tid 15447] [client 34.170.212.190:47630] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ladymcollection.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ladymcollection.com"] [uri "/z9x8c7v6b5-debug-trigger-ladymcollection.com"] [unique_id "ar_K058UkF9P6SOmL2_STgAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 14:57:41
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.170.212.190 (190.212.170.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.170.212.190 (190.212.170.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 10:57:38.132880 2026] [security2:error] [pid 29642:tid 29642] [client 34.170.212.190:59138] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.littlestarbookspub.com"] [uri "/.//.env"] [unique_id "ar_GYr0l-cPrW7jLYtDgowAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
sibahota
2026-10-02 14:53:48
(12 hours ago)
34.170.212.190 - - [02/Oct/2026:14:53:44 +0000] www.nidandiagnostic.com "GET /build/manifest.json HT ...
show more
34.170.212.190 - - [02/Oct/2026:14:53:44 +0000] www.nidandiagnostic.com "GET /build/manifest.json HTTP/2.0" 404 6649 0.004 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36 EdgA/152.0.0.0" 172.17.0.1:3051 404 0.004 "http://www.nidandiagnostic.com/build/manifest.json"
34.170.212.190 - - [02/Oct/2026:14:53:45 +0000] www.nidandiagnostic.com "GET /fvs9qq18f1e2mwa5g8a1 HTTP/2.0" 404 6649 0.005 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36; compatible; OAI-SearchBot/1.4; +https://openai.com/searchbot" 172.17.0.1:3051 404 0.005 "http://www.nidandiagnostic.com/fvs9qq18f1e2mwa5g8a1"
34.170.212.190 - - [02/Oct/2026:14:53:45 +0000] www.nidandiagnostic.com "GET /model/info HTTP/2.0" 404 6649 0.005 "-" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)" 172.17.0.1:3051 404 0.004 "http://www.nidandiagnostic.com/model/info"
34.170.212.190 - - [02/Oct/2
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 13:09:42
(14 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.170.212.190 (190.212.170.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.170.212.190 (190.212.170.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 09:09:37.540651 2026] [security2:error] [pid 15154:tid 15154] [client 34.170.212.190:59344] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||nathsharmaandcompany.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "nathsharmaandcompany.com"] [uri "/z9x8c7v6b5-debug-trigger-nathsharmaandcompany.com"] [unique_id "ar-tEeidgTB1P0hNxMNrdwAAACo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 12:20:24
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.170.212.190 (190.212.170.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.170.212.190 (190.212.170.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 08:20:18.522808 2026] [security2:error] [pid 474:tid 474] [client 34.170.212.190:41252] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.mcclaincounseling.com"] [uri "/%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env"] [unique_id "ar-hglqBXqyoFYIuH5gP-wAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 11:54:06
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.170.212.190 (190.212.170.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.170.212.190 (190.212.170.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 07:53:58.591939 2026] [security2:error] [pid 15195:tid 15195] [client 34.170.212.190:51900] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mcacpas.com"] [uri "/assets../.env"] [unique_id "ar-bVvJL2dGkllZsxgoQIwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 11:34:25
(16 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.170.212.190 (190.212.170.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.170.212.190 (190.212.170.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 07:34:19.392120 2026] [security2:error] [pid 2066:tid 2066] [client 34.170.212.190:45502] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||michaelgardner.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "michaelgardner.com"] [uri "/z9x8c7v6b5-debug-trigger-michaelgardner.com"] [unique_id "ar-Wuy8iJrQR3CIpPOrdAAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack