Anonymous
2026-09-11 18:33:55
(2 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-11 18:24:21
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.181.249.31 (31.249.181.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.181.249.31 (31.249.181.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 14:24:15.844671 2026] [security2:error] [pid 10433:tid 10433] [client 34.181.249.31:56054] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||jonathanfriend.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "jonathanfriend.com"] [uri "/z9x8c7v6b5-debug-trigger-jonathanfriend.com"] [unique_id "aqRHT5sGvDyTK-dqqLD2zgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
COMAITE
2026-09-11 18:01:00
(2 hours ago)
Suspicious URL access.
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-09-11 17:50:06
(2 hours ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ช๐ธ
masterguru
2026-09-11 17:29:51
(3 hours ago)
Inbound Anomaly Score Exceeded (Total Score: 5). Operator GE matched 5 at TX:anomaly_score. (949110- ...
show more
Inbound Anomaly Score Exceeded (Total Score: 5). Operator GE matched 5 at TX:anomaly_score. (949110-122)
show less
Hacking
๐ซ๐ท
dynamix
2026-09-11 17:22:14
(3 hours ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
netclix.gr
2026-09-11 17:21:09
(3 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.181.249.31 (US/United States/31.249. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.181.249.31 (US/United States/31.249.181.34.bc.googleusercontent.com): (CF_ENABLE)
show less
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-09-11 17:13:35
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.181.249.31 (31.249.181.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.181.249.31 (31.249.181.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 13:13:30.852108 2026] [security2:error] [pid 13272:tid 13272] [client 34.181.249.31:53044] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "johnedwardsconsulting.com"] [uri "/static../.env"] [unique_id "aqQ2uifrzwAQCXPZ7TywyQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-11 16:57:38
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.181.249.31 (31.249.181.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.181.249.31 (31.249.181.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 12:57:32.301246 2026] [security2:error] [pid 1818784:tid 1819541] [client 34.181.249.31:59652] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||jofdt.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "jofdt.com"] [uri "/rclone.conf"] [unique_id "aqQy_GLPhJgtVadW5skAbQAAAM0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-11 16:41:05
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.181.249.31 (31.249.181.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.181.249.31 (31.249.181.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 12:41:00.359974 2026] [security2:error] [pid 3836:tid 3836] [client 34.181.249.31:59850] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||joebankx.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "joebankx.com"] [uri "/z9x8c7v6b5-debug-trigger-joebankx.com"] [unique_id "aqQvHCBc_qOUq56T5ZBAYQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-11 16:21:42
(4 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
jmr777
2026-09-11 16:17:00
(4 hours ago)
IM360 WAF: Direct access to sensitive file or dotfile||MV:/.env||RSV:8.58||T:APACHE||
Sensor:
mods ...
show more
IM360 WAF: Direct access to sensitive file or dotfile||MV:/.env||RSV:8.58||T:APACHE||
Sensor:
modsec
Rule:
77045402
Abuser:
34.181.249.31
show less
Web App Attack
๐ซ๐ท
masterguru
2026-09-11 16:15:47
(4 hours ago)
Restricted File Access Attempt. Matched phrase ".ssh/" at REQUEST_FILENAME. (930130-196)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-11 16:07:20
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.181.249.31 (31.249.181.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.181.249.31 (31.249.181.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 12:07:13.149305 2026] [security2:error] [pid 23100:tid 23100] [client 34.181.249.31:41290] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||jnpmarinesolutions.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "jnpmarinesolutions.com"] [uri "/rclone.conf"] [unique_id "aqQnMW45ijztrSyCY02kUAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-11 16:00:28
(4 hours ago)
Excessive 404/403 errors
Brute-Force