๐บ๐ธ
TPI-Abuse
2026-09-24 07:31:10
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 34.38.86.202 (202.86.38.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.38.86.202 (202.86.38.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 03:31:06.521125 2026] [security2:error] [pid 8521:tid 8521] [client 34.38.86.202:47764] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||businessvaluationapp.com|F|2"] [data ".json.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "businessvaluationapp.com"] [uri "/.codex/auth.json.bak"] [unique_id "arTRuhkiyE8YP6U6K3mq_wAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 05:56:56
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 34.38.86.202 (202.86.38.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.38.86.202 (202.86.38.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 01:56:52.618151 2026] [security2:error] [pid 9557:tid 9557] [client 34.38.86.202:50400] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||boyt.org|F|2"] [data ".json.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "boyt.org"] [uri "/.codex/auth.json.bak"] [unique_id "arS7pDeq4DBwWumBvosqZAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
0x44
2026-09-23 18:35:32
(3 days ago)
TCP SYN Discovery - Flooding
DDoS Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 17:48:34
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 34.38.86.202 (202.86.38.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.38.86.202 (202.86.38.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 13:48:29.276321 2026] [security2:error] [pid 7318:tid 7318] [client 34.38.86.202:49652] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.acraloc.com|F|2"] [data ".json.old"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.acraloc.com"] [uri "/.codex/auth.json.old"] [unique_id "arQQ7V6EBXpazddDRw4AywAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
factor1
2026-09-23 16:26:43
(3 days ago)
CrowdSec at athena Reports Abuse
Web App Attack
๐ซ๐ท
COMAITE
2026-09-23 15:32:32
(3 days ago)
Suspicious URL access.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 14:35:07
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 34.38.86.202 (202.86.38.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.38.86.202 (202.86.38.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 10:34:59.060557 2026] [security2:error] [pid 25690:tid 25690] [client 34.38.86.202:59460] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||architech.com|F|2"] [data ".json.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "architech.com"] [uri "/.codex/auth.json.bak"] [unique_id "arPjk0ZGCGwRryMtae7J0QAAADg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 12:13:33
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 34.38.86.202 (202.86.38.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.38.86.202 (202.86.38.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 08:13:27.573077 2026] [security2:error] [pid 26066:tid 26066] [client 34.38.86.202:46370] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||apothecarydc.swampoodlegrounds.com|F|2"] [data ".json.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "apothecarydc.swampoodlegrounds.com"] [uri "/.codex/auth.json.bak"] [unique_id "arPCZ7zowiZNQA2H4UqfUAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 07:23:56
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 34.38.86.202 (202.86.38.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.38.86.202 (202.86.38.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 03:23:48.339745 2026] [security2:error] [pid 2296:tid 2296] [client 34.38.86.202:56692] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||alphaplanning.com|F|2"] [data ".json.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "alphaplanning.com"] [uri "/.codex/auth.json.bak"] [unique_id "arN-hDxC28gLK2_W3ygzDAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-23 03:47:16
(4 days ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐ฎ๐น
VHosting
2026-09-22 08:00:07
(5 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ซ๐ท
masterguru
2026-09-22 07:27:04
(5 days ago)
Restricted File Access Attempt. Matched phrase "/auth.json" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack