🇺🇸
TPI-Abuse
2026-09-12 13:28:45
(5 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.28.62.29 (29.62.28.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.28.62.29 (29.62.28.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 09:28:40.684647 2026] [security2:error] [pid 28173:tid 28173] [client 34.28.62.29:53112] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.socalcomedyclub.com|F|2"] [data ".socalcomedyclub.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.socalcomedyclub.com"] [uri "/z9x8c7v6b5-debug-trigger-mail.socalcomedyclub.com"] [unique_id "aqVTiLJA17jmzO31jK-LeQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-12 00:51:49
(18 hours ago)
Excessive multi-domain requests
Brute-Force
Anonymous
2026-09-11 20:14:15
(22 hours ago)
Portscan: TCP/8080 (2x), TCP/8443 (2x), TCP/80, TCP/443
Port Scan
🇮🇩
Burayot
2026-09-11 20:08:02
(22 hours ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 34.28.62.29 (US/United States/29.62 ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 34.28.62.29 (US/United States/29.62.28.34.bc.googleusercontent.com): 1 in the last 3600 secs
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 19:30:04
(23 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.28.62.29 (29.62.28.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.28.62.29 (29.62.28.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 15:29:58.885183 2026] [security2:error] [pid 507601:tid 507601] [client 34.28.62.29:58704] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||socconstruction.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "socconstruction.com"] [uri "/z9x8c7v6b5-debug-trigger-socconstruction.com"] [unique_id "aqRWtggHx9GtVXRy8vbtEAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
noise.agency
2026-09-11 19:26:57
(23 hours ago)
34.28.62.29 (US/United States/29.62.28.34.bc.googleusercontent.com), more than 10 Apache 403 hits
Hacking
🇬🇧
Aetherweb Ark
2026-09-11 18:36:37
(1 day ago)
(mod_security) mod_security (id:949110) triggered by 34.28.62.29 (US/United States/29.62.28.34.bc.go ...
show more
(mod_security) mod_security (id:949110) triggered by 34.28.62.29 (US/United States/29.62.28.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 18:26:54
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.28.62.29 (29.62.28.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.28.62.29 (29.62.28.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 14:26:50.178872 2026] [security2:error] [pid 6316:tid 6316] [client 34.28.62.29:50572] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "snowflakechristmascards.com"] [uri "/.git/config"] [unique_id "aqRH6o8ZRhluS-ne8jKhPQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-11 18:16:13
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
🇵🇱
sefinek.net
2026-09-11 18:08:06
(1 day ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action: BLOCK | Protocol: HTTP/2 (GET) | Endpoin ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action: BLOCK | Protocol: HTTP/2 (GET) | Endpoint: /@fs/var/run/secrets/kubernetes.io/serviceaccount/token | UA: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] ) • Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
🇪🇸
pipeline.es
2026-09-11 17:24:03
(1 day ago)
Web scanning / probing for vulnerable paths | URL: /wp/.env | Evidence: smviagens.com 34.28.62.29 - ...
show more
Web scanning / probing for vulnerable paths | URL: /wp/.env | Evidence: smviagens.com 34.28.62.29 - - [11/Sep/2026:19:23:06 +0200] \"GET /wp/.env HTTP/2.0\" 404 20449 \"-\" \"CCBot/2.0 (https://commoncrawl.org/faq/)\" GEOIP_COUNTRY_CODE=US | ASN: GOOGLE-CLOUD-PLATFORM | Country: US
show less
Port Scan
Web App Attack
🇩🇪
BlueWire Hosting
2026-09-11 17:14:57
(1 day ago)
Aggressive scanning resulting into 404
Bad Web Bot
Anonymous
2026-09-11 17:14:53
(1 day ago)
2026/09/11 17:14:51 [error] 199231#199231: *469604 [client 34.28.62.29] ModSecurity: Access denied w ...
show more
2026/09/11 17:14:51 [error] 199231#199231: *469604 [client 34.28.62.29] ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Ge' with parameter `5' against variable `TX:BLOCKING_INBOUND_ANOMALY_SCORE' (Value: `15' ) [file "/usr/local/owasp-modsecurity-crs-4.11.0/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "222"] [id "949110"] [rev ""] [msg "Inbound Anomaly Score Exceeded (Total Score: 15)"] [data ""] [severity "0"] [ver "OWASP_CRS/4.29.0"] [maturity "0"] [accuracy "0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "smscoregh.com"] [uri "/api/w/default/jobs_u/get_log_file/../../../../proc/self/environ"] [unique_id "178914689172.282502"] [ref ""], client: 34.28.62.29, server: smscoregh.com, request: "GET /api/w/default/jobs_u/get_log_file/../../../../proc/self/environ HTTP/2.0", host: "smscoregh.com"
2026/09/11 17:14:51 [error] 199231#199231: *469604 [client 34.28.62.29] ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Ge' with parameter
...
show less
Brute-Force
🇺🇸
TPI-Abuse
2026-09-11 17:05:42
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.28.62.29 (29.62.28.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.28.62.29 (29.62.28.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 13:05:35.283648 2026] [security2:error] [pid 13787:tid 13787] [client 34.28.62.29:42902] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "smore-and-more.com"] [uri "/@fs/.env"] [unique_id "aqQ0331Gxz139W4czgw7-AAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-09-11 17:05:35
(1 day ago)
Scanning/Probing (13)
Brute-Force
Web App Attack