Anonymous
2026-10-03 14:09:02
(4 days ago)
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: CA, Attack patterns: Word ...
show more
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: CA, Attack patterns: WordPress scanning, Backup file probing, Cloud secrets probing
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-03 06:49:54
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 34.19.168.20 (20.168.19.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.19.168.20 (20.168.19.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 03 02:49:48.666748 2026] [security2:error] [pid 20758:tid 20758] [client 34.19.168.20:55062] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||jimgrenier.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "jimgrenier.com"] [uri "/z9x8c7v6b5-debug-trigger-jimgrenier.com"] [unique_id "asCljCB9aXQLHaP4UKQ0kgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-03 05:49:58
(4 days ago)
(mod_security) mod_security (id:210580) triggered by 34.19.168.20 (20.168.19.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210580) triggered by 34.19.168.20 (20.168.19.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 03 01:49:53.720767 2026] [security2:error] [pid 13766:tid 13766] [client 34.19.168.20:34294] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at ARGS:filename. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||www.revelatorium.com|F|2"] [data "Matched Data: proc/self/environ found within ARGS:filename: file:/proc/self/environ"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "www.revelatorium.com"] [uri "/__vite_rsc_findSourceMapURL"] [unique_id "asCXgcCDI_XwdTQXYKO6SAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-03 05:33:53
(4 days ago)
Blocked by ModSec and CSF
Port Scan
๐ง๐ช
cmbplf
2026-10-03 04:36:49
(4 days ago)
301 requests with url.path *.env
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-03 02:52:47
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 34.19.168.20 (20.168.19.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.19.168.20 (20.168.19.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 22:52:42.640501 2026] [security2:error] [pid 13672:tid 13672] [client 34.19.168.20:50730] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.primemanagementmn.com|F|2"] [data ".primemanagementmn.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.primemanagementmn.com"] [uri "/z9x8c7v6b5-debug-trigger-www.primemanagementmn.com"] [unique_id "asBt-oDTIt0Ki9PiItsf2QAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-03 00:06:53
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 34.19.168.20 (20.168.19.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.19.168.20 (20.168.19.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 20:06:46.872117 2026] [security2:error] [pid 31244:tid 31268] [client 34.19.168.20:38610] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||jtjservices.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "jtjservices.com"] [uri "/z9x8c7v6b5-debug-trigger-jtjservices.com"] [unique_id "asBHFiPNlJIFs_r-GXRKCgAAAEk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Eric
2026-10-02 23:26:24
(4 days ago)
[Fri Oct 02 23:26:19.947943 2026] [security2:error] [pid 2038402:tid 2038402] [client 34.19.168.20:0 ...
show more
[Fri Oct 02 23:26:19.947943 2026] [security2:error] [pid 2038402:tid 2038402] [client 34.19.168.20:0] [client 34.19.168.20] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.pop-the-slots.com"] [uri "/z9x8c7v6b5-debug-trigger-www.pop-the-slots.com"] [unique_id "asA9m2JHEUjIt_89DJWA7AAAAAc"]
[Fri Oct 02 23:26:23.986890 2026] [security2:error] [pid 2038430:tid 2038430] [client 34.19.168.20:0] [client 34.19.168.20] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly
...
show less
Hacking
Web App Attack
๐ช๐ธ
masterguru
2026-10-02 19:17:09
(5 days ago)
BAD BOT - Detected and Blocked.. Matched phrase "applebot" at REQUEST_HEADERS:user-agent. (1100000-1 ...
show more
BAD BOT - Detected and Blocked.. Matched phrase "applebot" at REQUEST_HEADERS:user-agent. (1100000-122)
show less
Bad Web Bot
๐ฉ๐ช
updown.io
2026-10-02 18:39:09
(5 days ago)
{"level":"info","ts":1790966347.211137,"logger":"http.log.access.log1","msg":"handled request","requ ...
show more
{"level":"info","ts":1790966347.211137,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.19.168.20","remote_port":"56592","client_ip":"34.19.168.20","proto":"HTTP/2.0","method":"GET","host":"status.poedit.com","uri":"/asset-manifest.json","headers":{"Sec-Fetch-Site":["none"],"Sec-Fetch-User":["?1"],"Sec-Ch-Ua":["\"Chromium\";v=\"153\", \"Brave\";v=\"153\", \"Not_A Brand\";v=\"8\""],"Sec-Ch-Ua-Mobile":["?0"],"X-Middleware-Subrequest":["src/middleware:nowaf:src/middleware:src/middleware:src/middleware:src/middleware:middleware:middleware:nowaf:middleware:middleware:middleware:pages/_middleware"],"Priority":["u=0, i"],"Upgrade-Insecure-Requests":["1"],"Sec-Ch-Ua-Platform":["\"macOS\""],"Accept-Language":["en-US,en;q=0.9"],"User-Agent":["Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"],"Accept":["text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8"],"Sec
...
show less
DDoS Attack
Web App Attack
๐ฉ๐ช
svr
2026-10-02 18:29:16
(5 days ago)
Abusive Automated Web Scanner
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 18:20:59
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.19.168.20 (20.168.19.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.19.168.20 (20.168.19.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 14:20:54.004860 2026] [security2:error] [pid 1405770:tid 1405770] [client 34.19.168.20:39362] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.internet-brochures.com"] [uri "/css../.env"] [unique_id "ar_2Bsvndjn8G9aHY2jP5AAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-10-02 16:20:39
(5 days ago)
BAD BOT - Detected and Blocked.. Matched phrase "baidu" at REQUEST_HEADERS:User-Agent. (1100000-193)
Bad Web Bot
๐ท๐ด
clauss
2026-10-02 15:46:52
(5 days ago)
34.19.168.20 - - [02/Oct/2026:18:46:50 +0300] "GET /config.json HTTP/2.0" 403 207 "-" "Mozilla/5.0 A ...
show more
34.19.168.20 - - [02/Oct/2026:18:46:50 +0300] "GET /config.json HTTP/2.0" 403 207 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] )"
34.19.168.20 - - [02/Oct/2026:18:46:51 +0300] "GET /config.json.js HTTP/2.0" 403 207 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] )"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 13:43:09
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.19.168.20 (20.168.19.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.19.168.20 (20.168.19.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 09:43:02.158475 2026] [security2:error] [pid 23450:tid 23450] [client 34.19.168.20:40888] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.powerastronomy.powerastronomy.com"] [uri "/.env.staging"] [unique_id "ar-05rymI0NvFaBASx8-EgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack