πΊπΈ
TPI-Abuse
2026-10-03 07:56:01
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.32.144.25 (25.144.32.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.32.144.25 (25.144.32.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 03 03:55:57.270620 2026] [security2:error] [pid 17567:tid 17567] [client 34.32.144.25:52694] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.jkperis.com|F|2"] [data ".jkperis.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.jkperis.com"] [uri "/z9x8c7v6b5-debug-trigger-www.jkperis.com"] [unique_id "asC1DUhXyEVjo4nLVBLFTAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-03 05:22:29
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.32.144.25 (25.144.32.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.32.144.25 (25.144.32.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 03 01:22:24.602489 2026] [security2:error] [pid 20387:tid 20387] [client 34.32.144.25:52764] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.earlyfordv8crrg10.com"] [uri "/wp-config.php.bak"] [unique_id "asCREDUvhiMOUmHEc9BYngAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-03 01:49:15
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.32.144.25 (25.144.32.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.32.144.25 (25.144.32.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 21:49:09.233215 2026] [security2:error] [pid 22002:tid 22002] [client 34.32.144.25:36458] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.francisfindings.com|F|2"] [data ".francisfindings.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.francisfindings.com"] [uri "/z9x8c7v6b5-debug-trigger-www.francisfindings.com"] [unique_id "asBfFXkgW0YGt1NB8r6jqwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-02 18:27:33
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.32.144.25 (25.144.32.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.32.144.25 (25.144.32.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 14:27:27.512023 2026] [security2:error] [pid 13279:tid 13279] [client 34.32.144.25:39130] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||davedoeswater.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "davedoeswater.com"] [uri "/z9x8c7v6b5-debug-trigger-davedoeswater.com"] [unique_id "ar_3j2o26-2RCELlwaqbmQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-02 17:10:32
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.32.144.25 (25.144.32.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.32.144.25 (25.144.32.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 13:10:25.274975 2026] [security2:error] [pid 6112:tid 6112] [client 34.32.144.25:48506] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.aangfl.com"] [uri "/core/.env"] [unique_id "ar_lgawdx2oJdd31OHw51AAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-02 14:47:03
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.32.144.25 (25.144.32.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.32.144.25 (25.144.32.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 10:46:52.109797 2026] [security2:error] [pid 30276:tid 30276] [client 34.32.144.25:49382] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.hellomdinc.com"] [uri "/uploads../.env"] [unique_id "ar_D3DglFhrGJr1l5Cg_OAAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-02 13:04:49
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.32.144.25 (25.144.32.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.32.144.25 (25.144.32.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 09:04:42.782408 2026] [security2:error] [pid 17953:tid 17953] [client 34.32.144.25:47672] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.pawzyapp.com"] [uri "/.env.js"] [unique_id "ar-r6s3E5PleOYchjQOeJgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-02 09:08:52
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 34.32.144.25 (25.144.32.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.32.144.25 (25.144.32.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 05:08:47.211529 2026] [security2:error] [pid 6361:tid 6361] [client 34.32.144.25:55544] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||syscoxlegends.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "syscoxlegends.com"] [uri "/z9x8c7v6b5-debug-trigger-syscoxlegends.com"] [unique_id "ar90n0WTXUhyEFokkBMvpQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-02 08:13:01
(3 days ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-02 07:41:03
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 34.32.144.25 (25.144.32.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.32.144.25 (25.144.32.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 03:40:59.442407 2026] [security2:error] [pid 1334:tid 1408] [client 34.32.144.25:52784] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||frontrangesanctuary.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "frontrangesanctuary.com"] [uri "/z9x8c7v6b5-debug-trigger-frontrangesanctuary.com"] [unique_id "ar9gC7jr4_gdnJ_jM-3mxAAAAc0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
j-tap
2026-10-02 06:12:43
(3 days ago)
WordPress honeypot: automated scanner (xmlrpc / installer / .env / direct login POST)
Web App Attack
π«π·
dynamix
2026-10-02 04:50:22
(3 days ago)
Multiple WAF Violations
Web App Attack