🇺🇸
TPI-Abuse
2026-09-12 13:12:34
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.26.255.123 (123.255.26.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.26.255.123 (123.255.26.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 09:12:29.207423 2026] [security2:error] [pid 7673:tid 7673] [client 34.26.255.123:42674] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.sawted.com"] [uri "/.env"] [unique_id "aqVPvTOli_X_Zrl-qYhFoQAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-12 06:09:30
(13 hours ago)
excessive HTTP 404 errors
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-11 18:47:10
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.26.255.123 (123.255.26.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.26.255.123 (123.255.26.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 14:47:02.923678 2026] [security2:error] [pid 7203:tid 7203] [client 34.26.255.123:43352] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||scoretopicturenetwork.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "scoretopicturenetwork.com"] [uri "/rclone.conf"] [unique_id "aqRMpqidYQQPK7ZKexoregAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 18:26:03
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.26.255.123 (123.255.26.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.26.255.123 (123.255.26.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 14:25:59.894307 2026] [security2:error] [pid 17060:tid 17060] [client 34.26.255.123:32956] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||scifitimeline.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "scifitimeline.com"] [uri "/z9x8c7v6b5-debug-trigger-scifitimeline.com"] [unique_id "aqRHt-sXZekcJZHEs55qqgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-11 18:03:35
(1 day ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 17:53:41
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.26.255.123 (123.255.26.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.26.255.123 (123.255.26.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 13:53:35.599394 2026] [security2:error] [pid 10170:tid 10170] [client 34.26.255.123:38192] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||schonar.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "schonar.com"] [uri "/rclone.conf"] [unique_id "aqRAH8jG3zE-9klX25XaaQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-11 17:37:56
(1 day ago)
Excessive 404/403 errors
Brute-Force
🇳🇱
Savvii
2026-09-11 17:27:31
(1 day ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-11 17:12:00
(1 day ago)
Multiple WAF Violations
Web App Attack
🇺🇸
mnsf
2026-09-11 17:05:19
(1 day ago)
Scanning/Probing (15)
Brute-Force
Web App Attack
🇬🇧
consul.to
2026-09-11 17:03:02
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
🇮🇹
VHosting
2026-09-11 17:00:05
(1 day ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 16:31:26
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.26.255.123 (123.255.26.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.26.255.123 (123.255.26.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 12:31:18.545249 2026] [security2:error] [pid 25363:tid 25363] [client 34.26.255.123:34774] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||scadainthecloud.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "scadainthecloud.com"] [uri "/z9x8c7v6b5-debug-trigger-scadainthecloud.com"] [unique_id "aqQs1nw5y6CXB4v4JKrG5wAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
IndigoRidge
2026-09-11 16:22:47
(1 day ago)
34.26.255.123 - - [11/Sep/2026:12:22:44 -0400] "GET /@fs/.env?raw&url?? HTTP/1.1" 404 38673 "https:/ ...
show more
34.26.255.123 - - [11/Sep/2026:12:22:44 -0400] "GET /@fs/.env?raw&url?? HTTP/1.1" 404 38673 "https://sbpediatricdentists.com/@fs/.env?raw&url??" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)"
34.26.255.123 - - [11/Sep/2026:12:22:44 -0400] "GET /@fs/.env?import&?raw?? HTTP/1.1" 404 38673 "https://sbpediatricdentists.com/@fs/.env?import&?raw??" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)"
34.26.255.123 - - [11/Sep/2026:12:22:46 -0400] "GET /.env?import&raw HTTP/1.1" 403 4984 "https://sbpediatricdentists.com/.env?import&raw" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)"
...
show less
Web App Attack
🇸🇪
vaia.cloud
2026-09-11 16:20:02
(1 day ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack