🇳🇱
Site.eu
2026-09-15 15:04:15
(29 seconds ago)
Excessive 404/403 errors
Brute-Force
🇺🇸
TPI-Abuse
2026-09-15 14:51:28
(13 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.24.135.166 (166.135.24.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.24.135.166 (166.135.24.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 10:51:22.466067 2026] [security2:error] [pid 31296:tid 31296] [client 34.24.135.166:49032] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cressyvideo.com"] [uri "/.htpasswd"] [unique_id "aqlbaqgOEB0vzj0lngk3xAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-15 14:33:23
(31 minutes ago)
(mod_security) mod_security (id:210730) triggered by 34.24.135.166 (166.135.24.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.24.135.166 (166.135.24.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 10:33:18.014820 2026] [security2:error] [pid 10719:tid 10719] [client 34.24.135.166:58846] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||cpking.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "cpking.com"] [uri "/rclone.conf"] [unique_id "aqlXLnjaInmnY3m3mTu02QAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-15 14:18:00
(46 minutes ago)
(mod_security) mod_security (id:210730) triggered by 34.24.135.166 (166.135.24.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.24.135.166 (166.135.24.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 10:17:56.441897 2026] [security2:error] [pid 27717:tid 27717] [client 34.24.135.166:49208] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||cosentient.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "cosentient.com"] [uri "/z9x8c7v6b5-debug-trigger-cosentient.com"] [unique_id "aqlTlCK0aQTGb8mQVYGbaAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇮
paissangroup
2026-09-15 14:14:23
(50 minutes ago)
Multiple WAF Violations
Web App Attack
🇺🇸
nyt
2026-09-15 14:05:18
(59 minutes ago)
Path Traversal, Sensitive File Probe, Empty UA + error
Web App Attack
🇺🇸
TPI-Abuse
2026-09-15 14:00:37
(1 hour ago)
(mod_security) mod_security (id:210580) triggered by 34.24.135.166 (166.135.24.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210580) triggered by 34.24.135.166 (166.135.24.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 10:00:22.595325 2026] [security2:error] [pid 19774:tid 19774] [client 34.24.135.166:60078] ModSecurity: Access denied with code 403 (phase 2). Matched phrase ".ssh/id_rsa" at ARGS:filename. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||convtek.com|F|2"] [data "Matched Data: .ssh/id_rsa found within ARGS:filename: file:/root/.ssh/id_rsa"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "convtek.com"] [uri "/__vite_rsc_findSourceMapURL"] [unique_id "aqlPdm_MIQ72GE1BupDwOwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-15 13:45:01
(1 hour ago)
suspicious request in access.log
Web App Attack
🇺🇸
TPI-Abuse
2026-09-15 13:39:12
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.24.135.166 (166.135.24.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.24.135.166 (166.135.24.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 09:39:06.658884 2026] [security2:error] [pid 5139:tid 5139] [client 34.24.135.166:34620] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "compupackinc.com"] [uri "/appearance/../../.env"] [unique_id "aqlKeqnlPXwHWR8zrPdsjgAAAC0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇲🇾
Rizzy
2026-09-15 13:27:16
(1 hour ago)
Multiple WAF Violations
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-15 13:16:16
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.24.135.166 (166.135.24.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.24.135.166 (166.135.24.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 09:16:11.504790 2026] [security2:error] [pid 996890:tid 996890] [client 34.24.135.166:49356] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cofias.net"] [uri "/@fs/.env"] [unique_id "aqlFG5wygJhrWtl4hKG9PQAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-09-15 13:10:04
(1 hour ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack