Anonymous
2026-09-11 18:08:03
(5 hours ago)
34.21.50.215 - - [11/Sep/2026:20:08:02 +0200] "GET / HTTP/1.1" 403 183 "-" "Mozilla/5.0 (X11; Linux ...
show more
34.21.50.215 - - [11/Sep/2026:20:08:02 +0200] "GET / HTTP/1.1" 403 183 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36"
34.21.50.215 - - [11/Sep/2026:20:08:02 +0200] "GET /rclone.conf HTTP/1.1" 403 124 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36"
34.21.50.215 - - [11/Sep/2026:20:08:02 +0200] "GET /z9x8c7v6b5-debug-trigger-neomilmarfisheriesaquaculture.com HTTP/1.1" 403 124 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
34.21.50.215 - - [11/Sep/2026:20:08:02 +0200] "GET /secure HTTP/1.1" 403 183 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36"
34.21.50.215 - - [11/Sep/2026:20:08:02 +0200] "GET /signin HTTP/1.1" 403 183 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36"
34.21.50.215 - - [11/Sep/2026:20:08:02 +0200] "GET /account/login HT
...
show less
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-09-11 18:05:31
(5 hours ago)
Too many Status 40X (12)
Scanning/Probing (13)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 17:49:31
(5 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.21.50.215 (215.50.21.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.21.50.215 (215.50.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 13:49:27.924031 2026] [security2:error] [pid 20990:tid 20990] [client 34.21.50.215:48326] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||nekstlevel.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "nekstlevel.com"] [uri "/z9x8c7v6b5-debug-trigger-nekstlevel.com"] [unique_id "aqQ_J1G_hw6xlyBeddibywAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 17:27:42
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.21.50.215 (215.50.21.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.21.50.215 (215.50.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 13:27:37.947849 2026] [security2:error] [pid 24442:tid 24442] [client 34.21.50.215:45492] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "neh-media.com"] [uri "/.github/.env"] [unique_id "aqQ6CYknyuApc4AKZcPiIwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-11 17:27:23
(5 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇫🇷
masterguru
2026-09-11 17:25:19
(5 hours ago)
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encod ...
show more
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encoding/ /proxy/ /lock-token/ /content-range/ /if/ /x-http-method-override/ /x-http-method/ /x-method-override/ /x-middleware-subrequest/ /expect/" at TX:header_name_920450_x-middleware-subrequest. (920450-197)
show less
Bad Web Bot
Anonymous
2026-09-11 17:21:55
(5 hours ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
🇳🇱
Savvii
2026-09-11 17:13:29
(6 hours ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
LoneRider
2026-09-11 17:12:51
(6 hours ago)
[11/Sep/2026:19:12:47.800332 +0200] aqQ2jzhV4S0OMmnpwNeC_AAAAAQ 34.21.50.215 33026 127.0.0.1 7081
[1 ...
show more
[11/Sep/2026:19:12:47.800332 +0200] aqQ2jzhV4S0OMmnpwNeC_AAAAAQ 34.21.50.215 33026 127.0.0.1 7081
[11/Sep/2026:19:12:47.969111 +0200] aqQ2j_SvrwBT1kMuA-30iQAAAAM 34.21.50.215 33060 127.0.0.1 7081
[11/Sep/2026:19:12:50.214436 +0200] aqQ2knKCdazgva73ecIQpQAAAAA 34.21.50.215 42018 127.0.0.1 7081
...
show less
Hacking
🇺🇸
TPI-Abuse
2026-09-11 17:10:59
(6 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.21.50.215 (215.50.21.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.21.50.215 (215.50.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 13:10:52.323309 2026] [security2:error] [pid 16314:tid 16314] [client 34.21.50.215:48558] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||neconebooks.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "neconebooks.com"] [uri "/rclone.conf"] [unique_id "aqQ2HLyCeC3KoDZ5TEk2uwAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 16:47:04
(6 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.21.50.215 (215.50.21.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.21.50.215 (215.50.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 12:46:57.922921 2026] [security2:error] [pid 4827:tid 4827] [client 34.21.50.215:53932] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||ncparanormalresearch.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ncparanormalresearch.com"] [uri "/rclone.conf"] [unique_id "aqQwgWrePDVEvkdZloApxQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 16:27:00
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.21.50.215 (215.50.21.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.21.50.215 (215.50.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 12:26:54.446749 2026] [security2:error] [pid 13365:tid 13365] [client 34.21.50.215:35270] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nbcnewsradio.com"] [uri "/files../.env"] [unique_id "aqQrzv5J4uVU5lH9x5dW5QAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-09-11 16:00:05
(7 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
Anonymous
2026-09-11 15:54:23
(7 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇳🇱
e.fierstra
2026-09-11 15:53:44
(7 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack