๐ฌ๐ง
consul.to
2026-10-04 22:03:18
(1 week ago)
Web attack/malicious scanning detected
Web App Attack
๐ซ๐ท
ap_ram
2026-10-04 22:01:18
(1 week ago)
mae-88 : Bloc AI bots=>/zgo4i6i1d217n0r2jjmu(.ai)
Hacking
๐บ๐ธ
Mainpine
2026-10-04 21:56:56
(1 week ago)
probing for vulnerable web apps
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-04 21:46:35
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 34.21.183.74 (74.183.21.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.21.183.74 (74.183.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 17:46:31.200697 2026] [security2:error] [pid 28610:tid 28610] [client 34.21.183.74:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail-pmg.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail-pmg.com"] [uri "/z9x8c7v6b5-debug-trigger-mail-pmg.com"] [unique_id "asLJN_XuGtk0eVd73WI5bwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-10-04 21:32:02
(1 week ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-04 21:29:56
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 34.21.183.74 (74.183.21.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.21.183.74 (74.183.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 17:29:51.964600 2026] [security2:error] [pid 13661:tid 13661] [client 34.21.183.74:44018] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||hisimengineering.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "hisimengineering.com"] [uri "/z9x8c7v6b5-debug-trigger-hisimengineering.com"] [unique_id "asLFT0ohrE2IsKiFGjz6xwAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
demomodule
2026-10-04 21:14:38
(1 week ago)
PrestaShop Security Module: suspicious probe path detected (/.env)
Web App Attack
๐บ๐ธ
factor1
2026-10-04 21:14:26
(1 week ago)
CrowdSec at apollo Reports Abuse
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-04 21:12:14
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 34.21.183.74 (74.183.21.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.21.183.74 (74.183.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 17:12:08.697462 2026] [security2:error] [pid 1402:tid 1402] [client 34.21.183.74:41348] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||cosentient.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "cosentient.com"] [uri "/z9x8c7v6b5-debug-trigger-cosentient.com"] [unique_id "asLBKFRWNRZHk7z7Z8zrYwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-10-04 21:08:03
(1 week ago)
Wordlist path sweep | method: GET, POST | path: /build/manifest.json, /lib/terminal-xhr.php, /dist/m ...
show more
Wordlist path sweep | method: GET, POST | path: /build/manifest.json, /lib/terminal-xhr.php, /dist/manifest.json (+3 more) | ua: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36, Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/), Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/) (+1 more)
show less
Port Scan
Web App Attack
๐ฌ๐ง
poundawebsiteltd
2026-10-04 21:07:46
(1 week ago)
Malicious activity in general-malicious. Evidence: (apache_probe) Failed Access (403/404) 34.21.183. ...
show more
Malicious activity in general-malicious. Evidence: (apache_probe) Failed Access (403/404) 34.21.183.74 (SG/Singapore/[REDACTED_DOMAIN]): 20 in the last 3600 secs | UA: (apache_probe) Failed Access (403/404) 34.21.183.74 (SG/Singapore/74.183.21.34.bc.googleusercontent.com): 20 in the last 3600 secs
show less
Brute-Force
Web App Attack
๐ฎ๐น
VHosting
2026-10-04 21:05:04
(1 week ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-04 20:55:34
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 34.21.183.74 (74.183.21.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.21.183.74 (74.183.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 16:55:28.681445 2026] [security2:error] [pid 17503:tid 17503] [client 34.21.183.74:39428] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||andrsn.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "andrsn.com"] [uri "/z9x8c7v6b5-debug-trigger-andrsn.com"] [unique_id "asK9QAY3YdzW5--mXVPmzgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack