πΊπΈ
TPI-Abuse
2026-10-06 12:06:34
(26 minutes ago)
(mod_security) mod_security (id:210730) triggered by 34.19.163.242 (242.163.19.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.19.163.242 (242.163.19.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 08:06:30.686413 2026] [security2:error] [pid 30537:tid 30537] [client 34.19.163.242:36862] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||desertrosedoves.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "desertrosedoves.com"] [uri "/z9x8c7v6b5-debug-trigger-desertrosedoves.com"] [unique_id "asTkRjBJgoxQ2ffGzrIfwQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-06 11:38:44
(54 minutes ago)
(mod_security) mod_security (id:210730) triggered by 34.19.163.242 (242.163.19.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.19.163.242 (242.163.19.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 07:38:41.225993 2026] [security2:error] [pid 28658:tid 28658] [client 34.19.163.242:51274] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||derek-stites.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "derek-stites.com"] [uri "/z9x8c7v6b5-debug-trigger-derek-stites.com"] [unique_id "asTdwVK4SoCE7S0OVLyf5gAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-06 11:17:53
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.19.163.242 (242.163.19.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.19.163.242 (242.163.19.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 07:17:50.745054 2026] [security2:error] [pid 7404:tid 7404] [client 34.19.163.242:37958] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "denvercitymotorparts.com"] [uri "/.htpasswd"] [unique_id "asTY3gxBCFkE3lUIZiJ01wAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-06 11:07:35
(1 hour ago)
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: CA, Attack patterns: Clou ...
show more
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: CA, Attack patterns: Cloud secrets probing, Directory traversal
show less
Bad Web Bot
Web App Attack
π«π·
Stara
2026-10-06 11:04:55
(1 hour ago)
ModSecurity detected web attack - .env/config probing or SQLi/Code injection (Rule 949110)
Brute-Force
Hacking
Web App Attack
π©πͺ
LRob
2026-10-06 10:52:26
(1 hour ago)
Wordlist path sweep | method: POST, GET | path: /lib/terminal-xhr.php, /mthyatyxxavbo3z3tnwr, /3pii0 ...
show more
Wordlist path sweep | method: POST, GET | path: /lib/terminal-xhr.php, /mthyatyxxavbo3z3tnwr, /3pii04p71f47qfnccwf8 (+3 more) | ua: Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html), Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/), Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] ) (+1 more)
show less
Port Scan
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-06 10:52:12
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 34.19.163.242 (242.163.19.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.19.163.242 (242.163.19.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 06:52:07.234902 2026] [security2:error] [pid 7921:tid 7921] [client 34.19.163.242:60816] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||dennisdsmith.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "dennisdsmith.com"] [uri "/z9x8c7v6b5-debug-trigger-dennisdsmith.com"] [unique_id "asTS16aIYdzX2uHoWbQ17AAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
demomodule
2026-10-06 10:34:27
(1 hour ago)
PrestaShop Security Module: suspicious probe path detected (/.env)
Web App Attack
π«π·
masterguru
2026-10-06 10:22:46
(2 hours ago)
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .backup/ ...
show more
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .compositefont/ .config/ .conf/ .crt/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dist/ .dll/ .dos/ .dpkg-dist/ .drv/ .gadget/ .hta/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .inf/ .ini/ .jse/ .key/ .licx/ .lnk/ .log/ .mdb/ .msc/ .ocx/ .old/ .pass/ .pdb/ .pfx/ .pif/ .pem/ .pol/ .prf/ .printer/ .pwd/ .rdb/ .rdp/ .reg/ .resources/ .resx/ .scr/ .sct/ .shs/ .sql/ .swp/ .sys/ .tlb/ .tmp/ .url/ .vb/ .vbe/ .vbs/ .vbproj/ .vsdisco/ .vxd/ .webinfo/ .ws/ .wsc/ .wsf/ .wsh/ .xsd/ .xsx/" at TX:extension. (920440-196)
show less
Hacking
πΊπΈ
TPI-Abuse
2026-10-06 10:09:48
(2 hours ago)
(mod_security) mod_security (id:210580) triggered by 34.19.163.242 (242.163.19.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210580) triggered by 34.19.163.242 (242.163.19.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 06:09:45.024754 2026] [security2:error] [pid 14527:tid 14527] [client 34.19.163.242:48872] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at ARGS:filename. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||delstarr.com|F|2"] [data "Matched Data: proc/self/environ found within ARGS:filename: file:/proc/self/environ"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "delstarr.com"] [uri "/__vite_rsc_findSourceMapURL"] [unique_id "asTI6cA3vwzi98aabBFQuQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Site.eu
2026-10-06 10:03:09
(2 hours ago)
Excessive 404/403 errors
Brute-Force
π³π±
WeCloudit-Anti-Abuse
2026-10-06 09:32:26
(3 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/grafana-cve-2021-43798
Web App Attack
Hacking
π³π±
Savvii
2026-10-06 09:31:17
(3 hours ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-06 09:31:09
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.19.163.242 (242.163.19.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.19.163.242 (242.163.19.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 05:31:02.081801 2026] [security2:error] [pid 31217:tid 31330] [client 34.19.163.242:41432] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||degreesoflove.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "degreesoflove.com"] [uri "/z9x8c7v6b5-debug-trigger-degreesoflove.com"] [unique_id "asS_1jwg1A_4a6lmLFQdswAAAlA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
ipblock.com
2026-10-06 09:27:00
(3 hours ago)
IPBlock protected site ID [1438-do].
Exploit request, vulnerability scanner.
Hacking
Bad Web Bot
Web App Attack