πΊπΈ
TPI-Abuse
2026-08-20 22:04:27
(16 minutes ago)
(mod_security) mod_security (id:210730) triggered by 34.24.148.162 (162.148.24.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.24.148.162 (162.148.24.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 18:04:23.098588 2026] [security2:error] [pid 6641:tid 6641] [client 34.24.148.162:43952] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||xmlprotocol.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "xmlprotocol.com"] [uri "/z9x8c7v6b5-debug-trigger-xmlprotocol.com"] [unique_id "aod559tzp09abtSzPpk8sgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©π°
ScamAware
2026-08-20 21:52:27
(28 minutes ago)
Detected by Cloudflare Security Events via WordPress automation. Detection: sensitive_files (Sensiti ...
show more
Detected by Cloudflare Security Events via WordPress automation. Detection: sensitive_files (Sensitive files, source control, config, and backups). Hits from same IP in last 60 minutes: 4. Unique request paths counted internally: 4. Cloudflare action: block. Cloudflare source: firewallCustom.
show less
Web App Attack
Anonymous
2026-08-20 21:21:47
(58 minutes ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
π¦πΉ
penguin-solutions.at
2026-08-20 20:43:02
(1 hour ago)
Excessive 403/404 errors
...
Brute-Force
Web App Attack
π©πͺ
Grossmann-Gruppe
2026-08-20 20:42:56
(1 hour ago)
Plesk Fail2Ban: plesk-modsecurity
Hacking
Brute-Force
π©πͺ
ger-stg-sifi1
2026-08-20 20:38:39
(1 hour ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
πΊπΈ
mnsf
2026-08-20 20:05:16
(2 hours ago)
Scanning/Probing (19)
Brute-Force
Web App Attack
πΈπͺ
vaia.cloud
2026-08-20 19:40:02
(2 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
Anonymous
2026-08-20 19:13:04
(3 hours ago)
Web App Attack
π¨π
zynex
2026-08-20 19:06:21
(3 hours ago)
URL Probing: /.env
Web App Attack
π¬π§
consul.to
2026-08-20 19:03:38
(3 hours ago)
Web attack/malicious scanning detected
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-20 02:45:05
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.24.148.162 (162.148.24.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.24.148.162 (162.148.24.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 22:44:59.777614 2026] [security2:error] [pid 15672:tid 15672] [client 34.24.148.162:51618] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "galvez.cc"] [uri "/.env.js"] [unique_id "aoZqK9WbgGhd5sgw1URsLwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
tmiland
2026-08-20 01:48:28
(20 hours ago)
(nginx_444) Nginx 444 34.24.148.162 (US/United States/162.148.24.34.bc.googleusercontent.com): 5 in ...
show more
(nginx_444) Nginx 444 34.24.148.162 (US/United States/162.148.24.34.bc.googleusercontent.com): 5 in the last 3600 secs; IP: 34.24.148.162; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.24.148.162 - - [20/Aug/2026:03:48:26 +0200] "GET /__/firebase/init.json HTTP/1.1" 444 0 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ClaudeBot/1.0; +mailto:[email protected] " 34.24.148.162 - - [20/Aug/2026:03:48:26 +0200] "GET /env.json HTTP/1.1" 444 0 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ClaudeBot/1.0; +mailto:[email protected] " 34.24.148.162 - - [20/Aug/2026:03:48:26 +0200] "GET /config.json HTTP/1.1" 444 0 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ClaudeBot/1.0; +mailto:[email protected] " 34.24.148.162 - - [20/Aug/2026:03:48:26 +0200] "GET /firebase-config.json HTTP/1.1" 444 0 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ClaudeBot/1.0; +mailto:[email protected] " 34.24.148.162 - - [20/Au
show less
Brute-Force
πΊπΈ
TPI-Abuse
2026-08-19 22:51:01
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.24.148.162 (162.148.24.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.24.148.162 (162.148.24.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 18:50:54.837448 2026] [security2:error] [pid 9864:tid 9864] [client 34.24.148.162:40208] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vanmeter.cc"] [uri "/backend/.env"] [unique_id "aoYzTlO9WvgP9fkKhguu_QAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-19 22:05:52
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.24.148.162 (162.148.24.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.24.148.162 (162.148.24.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 18:05:46.018608 2026] [security2:error] [pid 18082:tid 18082] [client 34.24.148.162:48984] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bikestickers.cc|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bikestickers.cc"] [uri "/config.php.bak"] [unique_id "aoYoujBUMUTRd-CUQO7rZQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack