๐ฌ๐ง
WebNiraj
2026-07-29 23:14:18
(1 day ago)
(mod_security) mod_security (id:949110) triggered by 34.23.127.224 (US/United States/224.127.23.34.b ...
show more
(mod_security) mod_security (id:949110) triggered by 34.23.127.224 (US/United States/224.127.23.34.bc.googleusercontent.com): 5 in the last 3600 secs [SIGMA]
show less
Brute-Force
๐ฒ๐พ
Rizzy
2026-07-29 22:58:46
(1 day ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-29 21:46:48
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.23.127.224 (224.127.23.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.23.127.224 (224.127.23.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 17:46:40.691671 2026] [security2:error] [pid 322818:tid 322818] [client 34.23.127.224:60762] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||crm.kircali.net|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "crm.kircali.net"] [uri "/rclone.conf"] [unique_id "amp0wOp20LyQizqdkNEDGQAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-29 18:18:04
(1 day ago)
Multiple web server 400 error codes from same source ip
Web App Attack
๐ซ๐ท
dynamix
2026-07-29 17:55:08
(1 day ago)
Multiple WAF Violations
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-07-29 16:50:28
(1 day ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-29 16:23:31
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.23.127.224 (224.127.23.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.23.127.224 (224.127.23.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 12:23:22.701462 2026] [security2:error] [pid 811800:tid 811825] [client 34.23.127.224:49098] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "signin.priyom.us"] [uri "/.github/.env"] [unique_id "amoo-hqjlVF-5z1kTrH68wAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Octopuce
2026-07-29 15:34:49
(1 day ago)
Aggressive web search of vulnerable pages: /.env /.env.local /api/.env /admin/.env /backend/.env .. ...
show more
Aggressive web search of vulnerable pages: /.env /.env.local /api/.env /admin/.env /backend/.env ...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-29 15:29:39
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.23.127.224 (224.127.23.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.23.127.224 (224.127.23.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 11:29:31.943087 2026] [security2:error] [pid 584168:tid 584168] [client 34.23.127.224:42768] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||studio.kemela.com|F|2"] [data ".kemela.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "studio.kemela.com"] [uri "/z9x8c7v6b5-debug-trigger-studio.kemela.com"] [unique_id "amocWzjX0rr67TXb1f_DfgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-07-29 15:15:03
(1 day ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-29 15:07:58
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.23.127.224 (224.127.23.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.23.127.224 (224.127.23.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 11:07:53.945438 2026] [security2:error] [pid 17680:tid 17680] [client 34.23.127.224:59668] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||studio.nutandboltguy.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "studio.nutandboltguy.com"] [uri "/rclone.conf"] [unique_id "amoXSUmr-fgAlHes97Gz0QAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack