๐ง๐ช
cmbplf
2026-06-15 05:23:16
(1 week ago)
115 requests with url.path *credentials.json
102 requests with url.path *config.json
Brute-Force
Bad Web Bot
๐ซ๐ท
dynamix
2026-06-15 03:24:03
(1 week ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 02:47:20
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 34.176.107.97 (97.107.176.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.176.107.97 (97.107.176.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 22:47:14.425540 2026] [security2:error] [pid 11313:tid 11313] [client 34.176.107.97:51880] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||strawusa.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "strawusa.com"] [uri "/backup.sql"] [unique_id "ai9nsnHhmeSz2yDQ0Tr06wAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐บ
OK
2026-06-14 17:16:01
(1 week ago)
HTTP/HTTPS
Hacking
Web App Attack
๐ฉ๐ช
langenkamp-media
2026-06-14 15:34:52
(1 week ago)
Fail2Ban: Banned from jail nginx-scan-critical on 3dausdu.de
Web App Attack
๐ณ๐ฑ
Savvii
2026-06-14 13:02:46
(1 week ago)
20 attempts against mh-misbehave-ban on ficus
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 07:00:14
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 34.176.107.97 (97.107.176.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.176.107.97 (97.107.176.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 03:00:08.762644 2026] [security2:error] [pid 8043:tid 8043] [client 34.176.107.97:58462] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||cashnowcarbuyers.com.specialtywebservice.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "cashnowcarbuyers.com.specialtywebservice.com"] [uri "/backup.sql"] [unique_id "ai5ReI3JWGW0ztx1ur24sQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 06:44:53
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 34.176.107.97 (97.107.176.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.176.107.97 (97.107.176.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 02:44:48.645614 2026] [security2:error] [pid 21571:tid 21571] [client 34.176.107.97:48780] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||insua.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "insua.com"] [uri "/.config/gcloud/credentials.db"] [unique_id "ai5N4KPc-sHZ36iclSYDDgAAADo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
ConsulHosting
2026-06-14 06:31:51
(1 week ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 06:08:18
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 34.176.107.97 (97.107.176.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.176.107.97 (97.107.176.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 02:08:11.355010 2026] [security2:error] [pid 32597:tid 32597] [client 34.176.107.97:47408] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.ene.gabosoftware.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.ene.gabosoftware.com"] [uri "/.config/gcloud/credentials.db"] [unique_id "ai5FS-crPrxSifYcncDAEAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-14 05:13:29
(1 week ago)
Multiple web server 400 error codes from same source ip
Web App Attack
๐ฌ๐ง
WebNiraj
2026-06-14 04:51:03
(1 week ago)
(mod_security) mod_security (id:949110) triggered by 34.176.107.97 (97.107.176.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:949110) triggered by 34.176.107.97 (97.107.176.34.bc.googleusercontent.com): 5 in the last 3600 secs [SIGMA]
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-14 04:24:20
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 34.176.107.97 (97.107.176.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.176.107.97 (97.107.176.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 00:24:12.990116 2026] [security2:error] [pid 4600:tid 4600] [client 34.176.107.97:51938] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.myouenji.ichi51e.net|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.myouenji.ichi51e.net"] [uri "/.config/gcloud/credentials.db"] [unique_id "ai4s7Dx8aZ0M6CayH9e8jQAAAEQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-06-14 04:05:03
(1 week ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack