๐บ๐ธ
TPI-Abuse
2026-09-11 18:25:17
(19 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.182.226.0 (0.226.182.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.182.226.0 (0.226.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 14:25:13.544722 2026] [security2:error] [pid 24024:tid 24024] [client 34.182.226.0:46868] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kirbysmw.com"] [uri "/.git/config"] [unique_id "aqRHiUXt_FElQ0TlKqkmmQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
Mediashaker
2026-09-11 17:52:08
(52 minutes ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 34.182.226.0 (US/Uni ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 34.182.226.0 (US/United States/0.226.182.34.bc.googleusercontent.com)
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-11 17:48:19
(56 minutes ago)
(mod_security) mod_security (id:210730) triggered by 34.182.226.0 (0.226.182.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.182.226.0 (0.226.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 13:48:14.143035 2026] [security2:error] [pid 26940:tid 26940] [client 34.182.226.0:55700] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||kinkycouple4u.com|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kinkycouple4u.com"] [uri "/privatekey.key"] [unique_id "aqQ-3k6oswb62R5RJYvxQgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-11 17:44:23
(59 minutes ago)
BAD BOT - Detected and Blocked.. Matched phrase "baidu" at REQUEST_HEADERS:User-Agent. (1100000-196)
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-11 17:26:13
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 34.182.226.0 (0.226.182.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.182.226.0 (0.226.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 13:26:07.320853 2026] [security2:error] [pid 4758:tid 4758] [client 34.182.226.0:40150] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kingscruff.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kingscruff.com"] [uri "/z9x8c7v6b5-debug-trigger-kingscruff.com"] [unique_id "aqQ5r5KxzcOuiWgH4h5xBAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-11 17:11:09
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.182.226.0 (0.226.182.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.182.226.0 (0.226.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 13:11:02.423467 2026] [security2:error] [pid 8781:tid 8801] [client 34.182.226.0:54252] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kingdomofthefranks.com"] [uri "/.git/config"] [unique_id "aqQ2Jrx8ge20RWbi5xUK8wAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-09-11 17:05:37
(1 hour ago)
Too many Status 40X (16)
Scanning/Probing (16)
Brute-Force
Web App Attack
๐บ๐ธ
TAY
2026-09-11 16:56:59
(1 hour ago)
34.182.226.0 - - [12/Sep/2026:00:56:58 +0800] "GET /assets../.env HTTP/1.1" 404 2049 "-" "CCBot/2.0 ...
show more
34.182.226.0 - - [12/Sep/2026:00:56:58 +0800] "GET /assets../.env HTTP/1.1" 404 2049 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)"
34.182.226.0 - - [12/Sep/2026:00:56:58 +0800] "GET /img../.env HTTP/1.1" 404 2049 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; OAI-SearchBot/1.0; +https://openai.com/searchbot)"
34.182.226.0 - - [12/Sep/2026:00:56:58 +0800] "GET /images../.env HTTP/1.1" 404 2049 "-" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)"
34.182.226.0 - - [12/Sep/2026:00:56:58 +0800] "GET /uploads../.env HTTP/1.1" 404 2049 "-" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)"
34.182.226.0 - - [12/Sep/2026:00:56:58 +0800] "GET /public/plugins/alertlist/../../../../../../../../proc/self/environ HTTP/1.1" 400 2056 "-" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)"
34.182.226.0 - - [12/Sep/2026:00:56:59 +0800] "GET /api/w/admins/jobs_u/get_log_file/../../../../proc/self/environ HTTP/1.1" 404 2049 "-" "Mozilla/5.0 (compatible; Bravebot/1.
...
show less
Brute-Force
๐ณ๐ฑ
Savvii
2026-09-11 16:46:55
(1 hour ago)
21 attempts against mh-misbehave-ban on tin
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-11 16:44:57
(1 hour ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-11 16:41:36
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.182.226.0 (0.226.182.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.182.226.0 (0.226.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 12:41:28.464441 2026] [security2:error] [pid 28165:tid 28165] [client 34.182.226.0:49836] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kinaffanchufoods.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kinaffanchufoods.com"] [uri "/z9x8c7v6b5-debug-trigger-kinaffanchufoods.com"] [unique_id "aqQvOOxHwD-kyC5B2t70IwAAAIo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-11 15:58:17
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.182.226.0 (0.226.182.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.182.226.0 (0.226.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 11:58:13.526610 2026] [security2:error] [pid 26942:tid 26942] [client 34.182.226.0:41738] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||killeenbarrelsandtotes.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "killeenbarrelsandtotes.com"] [uri "/rclone.conf"] [unique_id "aqQlFS9ksYGOmSwEcOhWNQAAAF8"]
show less
Brute-Force
Bad Web Bot
Web App Attack