🇫🇷
dynamix
2026-09-11 18:58:24
(6 hours ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 18:18:49
(6 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.20.163.72 (72.163.20.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.20.163.72 (72.163.20.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 14:18:46.051521 2026] [security2:error] [pid 6238:tid 6238] [client 34.20.163.72:45800] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mdp-interiors.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mdp-interiors.com"] [uri "/z9x8c7v6b5-debug-trigger-mdp-interiors.com"] [unique_id "aqRGBkB7qvbe9RKbR1POVgAAACw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 18:02:58
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.20.163.72 (72.163.20.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.20.163.72 (72.163.20.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 14:02:53.429524 2026] [security2:error] [pid 6189:tid 6189] [client 34.20.163.72:55422] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mcthorpe.com"] [uri "/%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env"] [unique_id "aqRCTUOXjT_4oLc1t7iPWgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
cwytech
2026-09-11 17:57:11
(7 hours ago)
Fleet-wide ban from the Ghostfleet 👻. Triggered by scenario: crowdsecurity/http-sensitive-files.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 17:37:44
(7 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.20.163.72 (72.163.20.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.20.163.72 (72.163.20.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 13:37:38.347448 2026] [security2:error] [pid 17393:tid 17393] [client 34.20.163.72:59748] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mcginleyclan.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mcginleyclan.com"] [uri "/z9x8c7v6b5-debug-trigger-mcginleyclan.com"] [unique_id "aqQ8YqiIl0w2yBBNjXZF2wAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 17:19:55
(7 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.20.163.72 (72.163.20.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.20.163.72 (72.163.20.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 13:19:47.651899 2026] [security2:error] [pid 4554:tid 4554] [client 34.20.163.72:53212] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mcarrollcommunications.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mcarrollcommunications.com"] [uri "/z9x8c7v6b5-debug-trigger-mcarrollcommunications.com"] [unique_id "aqQ4MzXL6aA6_N8CzMtLJwAAAD0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-09-11 17:05:38
(8 hours ago)
Too many Status 40X (12)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 17:01:21
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.20.163.72 (72.163.20.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.20.163.72 (72.163.20.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 13:01:13.204343 2026] [security2:error] [pid 10536:tid 10536] [client 34.20.163.72:34166] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mbehel.com"] [uri "/.env.local"] [unique_id "aqQz2epUYskM3TIC6vKbkQAAADg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-09-11 16:15:02
(8 hours ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
🇮🇹
VHosting
2026-09-11 16:10:04
(8 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇳🇱
Savvii
2026-09-11 16:03:40
(9 hours ago)
20 attempts against mh-misbehave-ban on pavo
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 15:59:32
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.20.163.72 (72.163.20.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.20.163.72 (72.163.20.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 11:59:28.984837 2026] [security2:error] [pid 22440:tid 22442] [client 34.20.163.72:41476] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "maxelon.com"] [uri "/.env"] [unique_id "aqQlYBGYvam6ITWnPjJBvwAAAQA"]
show less
Brute-Force
Bad Web Bot
Web App Attack