๐บ๐ธ
TPI-Abuse
2026-07-30 07:53:20
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.187.104.89 (89.104.187.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.187.104.89 (89.104.187.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 30 03:53:14.000117 2026] [security2:error] [pid 1107654:tid 1107654] [client 34.187.104.89:47588] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "crm.kircali.net"] [uri "/.env.local"] [unique_id "amsC6QqsJJmP3ohbSlnTagAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-30 05:52:49
(4 weeks ago)
Multiple web server 400 error codes from same source ip
Web App Attack
๐ณ๐ฟ
Antinson
2026-07-30 05:43:30
(4 weeks ago)
High error rate and elevated request volume targeting cPanel servers
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-07-30 02:28:13
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.187.104.89 (89.104.187.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.187.104.89 (89.104.187.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 22:28:06.299331 2026] [security2:error] [pid 4741:tid 4741] [client 34.187.104.89:55100] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "admin.marisetravel.com"] [uri "/.env.production"] [unique_id "amq2ttVzeMifA5u5VhOr_QAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
rafli
2026-07-29 19:12:04
(4 weeks ago)
{"level":"info","ts":1785352322.9584072,"logger":"http.log.access.log9","msg":"handled request","req ...
show more
{"level":"info","ts":1785352322.9584072,"logger":"http.log.access.log9","msg":"handled request","request":{"remote_ip":"34.187.104.89","remote_port":"57638","client_ip":"34.187.104.89","proto":"HTTP/2.0","method":"GET","host":"auth.oncall.id","uri":"/","headers":{"User-Agent":["Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36"],"Sec-Ch-Ua":["\"Google Chrome\";v=\"149\", \"Chromium\";v=\"149\", \"Not)A;Brand\";v=\"24\""],"Accept":["text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8"],"Upgrade-Insecure-Requests":["1"],"Sec-Ch-Ua-Mobile":["?0"],"Accept-Encoding":["gzip, deflate, br, zstd"],"Sec-Fetch-Mode":["navigate"],"Accept-Language":["en-US,en;q=0.9"],"Sec-Fetch-Site":["none"],"Sec-Ch-Ua-Platform":["\"Windows\""],"Priority":["u=0, i"],"Sec-Fetch-User":["?1"],"Sec-Fetch-Dest":["document"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"h2","server_name":"auth.oncall.id",
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-29 19:11:49
(4 weeks ago)
(mod_security) mod_security (id:210730) triggered by 34.187.104.89 (89.104.187.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.187.104.89 (89.104.187.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 15:11:45.912707 2026] [security2:error] [pid 657107:tid 657107] [client 34.187.104.89:46802] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||signin.markgiffin.com|F|2"] [data ".markgiffin.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "signin.markgiffin.com"] [uri "/z9x8c7v6b5-debug-trigger-signin.markgiffin.com"] [unique_id "ampQcR6zI8mdPYtXEslPKgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Octopuce
2026-07-29 18:37:10
(4 weeks ago)
Aggressive web search of vulnerable pages: /info.php /web/.env /pi.php /test.php /i.php /app_dev.php ...
show more
Aggressive web search of vulnerable pages: /info.php /web/.env /pi.php /test.php /i.php /app_dev.php /application.yml /phpinfo.php /laravel/.en ...
show less
Web App Attack
๐ฉ๐ช
YF
2026-07-29 18:00:13
(4 weeks ago)
Distributed subnet attack โ coordinated scanning from multiple IPs in the same /24
DDoS Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-29 17:42:11
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.187.104.89 (89.104.187.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.187.104.89 (89.104.187.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 13:42:07.095799 2026] [security2:error] [pid 755385:tid 755385] [client 34.187.104.89:54814] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "login.kemela.com"] [uri "/.git/config"] [unique_id "amo7bzPx1OAonfnIwl6ckgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-29 17:18:08
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.187.104.89 (89.104.187.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.187.104.89 (89.104.187.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 13:18:02.955407 2026] [security2:error] [pid 417080:tid 417080] [client 34.187.104.89:59788] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "console.philipma.com"] [uri "/.git/config"] [unique_id "amo1ykICnXchF-VEEMIaWwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-07-29 16:35:00
(4 weeks ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-29 16:30:40
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.187.104.89 (89.104.187.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.187.104.89 (89.104.187.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 12:30:33.346465 2026] [security2:error] [pid 3156187:tid 3156187] [client 34.187.104.89:51218] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "members.londongroup.info"] [uri "/.git/HEAD"] [unique_id "amoqqeAP04oCjosIkG-EIAAAACs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-07-29 16:10:03
(4 weeks ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐ซ๐ท
dynamix
2026-07-29 16:03:58
(4 weeks ago)
Multiple WAF Violations
Web App Attack