🇺🇸
TPI-Abuse
2026-09-12 12:56:43
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 34.23.79.90 (90.79.23.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.23.79.90 (90.79.23.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 08:56:39.196500 2026] [security2:error] [pid 15807:tid 15807] [client 34.23.79.90:54732] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.petesplaza.com|F|2"] [data ".petesplaza.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.petesplaza.com"] [uri "/z9x8c7v6b5-debug-trigger-mail.petesplaza.com"] [unique_id "aqVMB7dWbSHP5621k-ERfwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 20:19:45
(17 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.23.79.90 (90.79.23.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.23.79.90 (90.79.23.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 16:19:40.997572 2026] [security2:error] [pid 15265:tid 15265] [client 34.23.79.90:39586] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||access.philipma.com|F|2"] [data ".philipma.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "access.philipma.com"] [uri "/z9x8c7v6b5-debug-trigger-access.philipma.com"] [unique_id "aqRiXOCaU0FR6NOlqoVcfgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-09-11 20:05:29
(18 hours ago)
Scanning/Probing (24)
Brute-Force
Web App Attack
🇩🇪
XICTRON
2026-09-11 19:50:17
(18 hours ago)
ModSecurity rule violation detected by Fail2Ban
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 19:15:50
(18 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.23.79.90 (90.79.23.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.23.79.90 (90.79.23.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 15:15:45.056297 2026] [security2:error] [pid 29567:tid 29567] [client 34.23.79.90:32864] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||phillatwood.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "phillatwood.com"] [uri "/z9x8c7v6b5-debug-trigger-phillatwood.com"] [unique_id "aqRTYdZA387CJjUHrx9dRQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
YF
2026-09-11 19:00:15
(19 hours ago)
Distributed subnet attack — coordinated scanning from multiple IPs in the same /24
DDoS Attack
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 18:57:46
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.23.79.90 (90.79.23.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.23.79.90 (90.79.23.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 14:57:39.728328 2026] [security2:error] [pid 4105:tid 4105] [client 34.23.79.90:54414] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "phenoxcaribbean.com"] [uri "/@fs/var/task/.env"] [unique_id "aqRPI5WUYMcbhVmFwmxI_gAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇷🇺
Mga Admin
2026-09-11 18:55:02
(19 hours ago)
34.23.79.90 - - [12/Sep/2026:01:55:01 +0700] "GET /z9x8c7v6b5-debug-trigger-phelige.com HTTP/1.1" 40 ...
show more
34.23.79.90 - - [12/Sep/2026:01:55:01 +0700] "GET /z9x8c7v6b5-debug-trigger-phelige.com HTTP/1.1" 404 69 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot)"
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 18:32:05
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.23.79.90 (90.79.23.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.23.79.90 (90.79.23.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 14:31:57.808637 2026] [security2:error] [pid 24869:tid 24869] [client 34.23.79.90:45712] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "phantomkennels.com"] [uri "/@fs/var/task/.env"] [unique_id "aqRJHTqvKJbDaTvM7w3CIQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 18:04:18
(20 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.23.79.90 (90.79.23.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.23.79.90 (90.79.23.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 14:04:14.531332 2026] [security2:error] [pid 26193:tid 26193] [client 34.23.79.90:45022] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||pghsea.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "pghsea.com"] [uri "/z9x8c7v6b5-debug-trigger-pghsea.com"] [unique_id "aqRCnves87f8-E3AUiPMRgAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Bedios GmbH
2026-09-11 17:33:09
(20 hours ago)
Login credentials theft attempt
Hacking
🇺🇸
TPI-Abuse
2026-09-11 17:12:46
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.23.79.90 (90.79.23.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.23.79.90 (90.79.23.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 13:12:38.579741 2026] [security2:error] [pid 1818776:tid 1819491] [client 34.23.79.90:42116] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "petrovicimagery.com"] [uri "/@fs/proc/self/cwd/.env"] [unique_id "aqQ2hmaOUKEQrjDJIf-9aAAAAI8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-11 16:56:04
(21 hours ago)
Multiple WAF Violations
Web App Attack
🇺🇸
ph
2026-09-11 16:50:29
(21 hours ago)
Bad web bot attempting to run wp-json on non-WP site
Hacking
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 16:36:08
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.23.79.90 (90.79.23.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.23.79.90 (90.79.23.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 12:36:03.179223 2026] [security2:error] [pid 25565:tid 25565] [client 34.23.79.90:46646] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "peteringrassia.com"] [uri "/.git/HEAD"] [unique_id "aqQt8_ylE1biE-eDvWmA4wAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack