๐ณ๐ฑ
Savvii
2026-10-06 12:49:44
(16 minutes ago)
20 attempts against mh-misbehave-ban on rwl-noble-dev
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 12:43:40
(22 minutes ago)
(mod_security) mod_security (id:210730) triggered by 34.39.175.145 (145.175.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.39.175.145 (145.175.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 08:43:37.843433 2026] [security2:error] [pid 19768:tid 19768] [client 34.39.175.145:57508] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||lucitania.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "lucitania.com"] [uri "/z9x8c7v6b5-debug-trigger-lucitania.com"] [unique_id "asTs-Xx7H57qAOXuh6fy_wAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
chronos
2026-10-06 12:16:26
(49 minutes ago)
[AUTORAVALT][[06/10/2026 - 09:16:25 -03:00 UTC]
Attack from [Google LLC]
[34.39.175.145][145.175.39. ...
show more
[AUTORAVALT][[06/10/2026 - 09:16:25 -03:00 UTC]
Attack from [Google LLC]
[34.39.175.145][145.175.39.34.bc.googleusercontent.com]
Action: BLocKed
DDoS Attack -> Participating in distributed denial-of-service.
Phishing -> Phishing websites and/or email.
Web Spam -> Comment/forum spam, HTTP referer spam, or other CMS spam.
Blog Spam -> CMS blog comment spam.
Web]
...
show less
DDoS Attack
Phishing
Web Spam
Blog Spam
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 11:55:11
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 34.39.175.145 (145.175.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.39.175.145 (145.175.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 07:55:07.290905 2026] [security2:error] [pid 8805:tid 8805] [client 34.39.175.145:33926] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||lsippell.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "lsippell.com"] [uri "/z9x8c7v6b5-debug-trigger-lsippell.com"] [unique_id "asThm61T6PcRcWuxKtvmHAAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-10-06 11:28:06
(1 hour ago)
Excessive multi-domain requests
Brute-Force
Anonymous
2026-10-06 11:08:29
(1 hour ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 10:37:11
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.39.175.145 (145.175.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.39.175.145 (145.175.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 06:37:08.386469 2026] [security2:error] [pid 19733:tid 19733] [client 34.39.175.145:41896] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||lovebuilds.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "lovebuilds.com"] [uri "/z9x8c7v6b5-debug-trigger-lovebuilds.com"] [unique_id "asTPVGoTqVUp_Gr2qrvy-gAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-10-06 10:26:05
(2 hours ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 10:18:44
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.39.175.145 (145.175.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.39.175.145 (145.175.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 06:18:40.626835 2026] [security2:error] [pid 9562:tid 9562] [client 34.39.175.145:59888] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||louiemobilemixology.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "louiemobilemixology.com"] [uri "/z9x8c7v6b5-debug-trigger-louiemobilemixology.com"] [unique_id "asTLALd7U1BTYOgtfWIqawAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ด
Bots.go.to.hell
2026-10-06 10:02:16
(3 hours ago)
This IP was detected by CrowdSec triggering custom/http-bad-crawler-ban
Web App Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-06 09:59:13
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.39.175.145 (145.175.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.39.175.145 (145.175.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 05:59:10.426682 2026] [security2:error] [pid 31217:tid 31337] [client 34.39.175.145:33250] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||jd-web-designs.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "jd-web-designs.com"] [uri "/z9x8c7v6b5-debug-trigger-jd-web-designs.com"] [unique_id "asTGbjwg1A_4a6lmLFQsKAAAAlc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
itsolon
2026-10-06 09:57:40
(3 hours ago)
[06/Oct/2026:11:57:39 +0200] 179128065980.282191 34.39.175.145 40930 217.154.7.177 443
[06/Oct/2026: ...
show more
[06/Oct/2026:11:57:39 +0200] 179128065980.282191 34.39.175.145 40930 217.154.7.177 443
[06/Oct/2026:11:57:39 +0200] 179128065979.156163 34.39.175.145 40930 217.154.7.177 443
[06/Oct/2026:11:57:39 +0200] 179128065973.733588 34.39.175.145 40920 217.154.7.177 443
[06/Oct/2026:11:57:39 +0200] 17912806594.199982 34.39.175.145 40930 217.154.7.177 443
[06/Oct/2026:11:57:39 +0200] 179128065919.330199 34.39.175.145 40930 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
๐ฉ๐ช
Phenix Info
2026-10-06 09:56:25
(3 hours ago)
SmallGuard.fr - HoneyPot
Web App Attack
๐ฉ๐ช
svr
2026-10-06 09:50:47
(3 hours ago)
Abusive Automated Web Scanner
Web App Attack
๐ฌ๐ง
masterguru
2026-10-06 09:38:22
(3 hours ago)
Fake Claudebot fetcher UA from non-Claude IP. Match of "ipMatchFromFile /etc/modsecurity/crs/plugins ...
show more
Fake Claudebot fetcher UA from non-Claude IP. Match of "ipMatchFromFile /etc/modsecurity/crs/plugins/claudebot_fetchers.txt" against "REMOTE_ADDR" required. (200112-185)
show less
Hacking