πΊπΈ
TPI-Abuse
2026-10-01 16:08:19
(41 minutes ago)
(mod_security) mod_security (id:210730) triggered by 34.39.197.211 (211.197.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.39.197.211 (211.197.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 12:08:15.235129 2026] [security2:error] [pid 23378:tid 23378] [client 34.39.197.211:57024] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||wellness-mastery.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "wellness-mastery.com"] [uri "/z9x8c7v6b5-debug-trigger-wellness-mastery.com"] [unique_id "ar6Fb3Modn6m-P5EskzZhQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-01 15:34:49
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.39.197.211 (211.197.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.197.211 (211.197.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 11:34:41.953856 2026] [security2:error] [pid 8988:tid 8988] [client 34.39.197.211:33254] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.vpatech.com"] [uri "/.htpasswd"] [unique_id "ar59kZf4sGM3eFOVAEcMFAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΏπ¦
vanderhost
2026-10-01 14:54:54
(1 hour ago)
[Laravel HoneypotPlus] Automated report - Honeypot access detected on path: /config/gcp-credentials. ...
show more
[Laravel HoneypotPlus] Automated report - Honeypot access detected on path: /config/gcp-credentials.json via rule: /config
show less
Web App Attack
Bad Web Bot
π³π±
Site.eu
2026-10-01 13:35:14
(3 hours ago)
Excessive 404/403 errors
Brute-Force
πΊπΈ
TPI-Abuse
2026-10-01 13:23:08
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.39.197.211 (211.197.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.197.211 (211.197.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 09:23:04.725713 2026] [security2:error] [pid 15359:tid 15359] [client 34.39.197.211:52350] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.uraniumjewelry.com"] [uri "/.git/HEAD"] [unique_id "ar5euPAv6rwcB-bXvgiXJwAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-01 12:19:27
(4 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.39.197.211 (211.197.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:949110) triggered by 34.39.197.211 (211.197.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 08:19:19.721687 2026] [security2:error] [pid 27564:tid 27564] [client 34.39.197.211:35396] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.trophiesetc.us"] [uri "/.env"] [unique_id "ar5Px1hxFJBqOBJQ4Hhu-QAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π§π·
noconex
2026-10-01 11:51:38
(4 hours ago)
Wazuh Alert | Rule ID: 110100 | Desc: Suricata: Exploit (ET WEB_SERVER Next.js Middleware Authorizat ...
show more
Wazuh Alert | Rule ID: 110100 | Desc: Suricata: Exploit (ET WEB_SERVER Next.js Middleware Authorization Bypass (CVE-2025-29927)) 34.39.197.211
show less
Port Scan
Brute-Force
SSH
πΊπΈ
TPI-Abuse
2026-10-01 11:36:45
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.39.197.211 (211.197.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.197.211 (211.197.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 07:36:38.324731 2026] [security2:error] [pid 28447:tid 28447] [client 34.39.197.211:53722] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.zackfranz.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "ar5FxrtxVQOE82CQ7UXTpwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-01 10:47:15
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.39.197.211 (211.197.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.197.211 (211.197.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 06:47:09.220705 2026] [security2:error] [pid 28811:tid 28811] [client 34.39.197.211:53754] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/Web.config" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.wildcomaui.com"] [uri "/web.config"] [unique_id "ar46LSEuWsDZSRB2JofgygAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΏπ¦
hostsec_za
2026-10-01 10:34:01
(6 hours ago)
cPanel/cPDAVd Auth Attack. 95 failed logins in 1 hour.
Brute-Force
πΊπΈ
TPI-Abuse
2026-10-01 10:22:38
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.39.197.211 (211.197.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.197.211 (211.197.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 06:22:33.284934 2026] [security2:error] [pid 9763:tid 9763] [client 34.39.197.211:50112] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/Web.config" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.tinseltownartificials.com"] [uri "/web.config"] [unique_id "ar40aZvK7TvvPT370ISSHwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-01 10:05:59
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.39.197.211 (211.197.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.197.211 (211.197.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 06:05:53.754306 2026] [security2:error] [pid 11885:tid 11885] [client 34.39.197.211:37294] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "valuechains4poor.net"] [uri "/@fs/src/.env"] [unique_id "ar4wgXqrg2PkhcIE1iUJhAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Alt255
2026-10-01 10:02:43
(6 hours ago)
[ti-11al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apac ...
show more
[ti-11al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apache-404. Example: 34.39.197.211 - - [01/Oct/2026:12:02:22 +0200] "GET /z9x8c7v6b5-debug-trigger-devops.uzk.nl HTTP/2.0" 404 1879 "-" "Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)"
34.39.197.211 - - [01/Oct/2026:12:02:22 +0200] "GET /k1503zcyifrhkoqdozd5 HTTP/2.0" 404 1856 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)"
34.39.197.211 - - [01/Oct/2026:12:02:22 +0200] "GET /model/info HTTP/2.0" 404 1856 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)"
34.39.197.211 - - [01/Oct/2026:12:02:22 +0200] "GET /joasnexktri0a0wmm72o HTTP/2.0" 404 1856 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)"
34.39.197.211 - - [01/Oct/2026:12:02:22 +0200] "POST /login HTTP/2.0" 404 1856 "-" "Mozilla/5.0 (compatible; Qwenb
...
show less
Bad Web Bot
Web App Attack
π²πΎ
Rizzy
2026-10-01 09:34:08
(7 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-01 09:32:02
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.39.197.211 (211.197.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.197.211 (211.197.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 05:31:56.952946 2026] [security2:error] [pid 26397:tid 26397] [client 34.39.197.211:37668] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.uniquelimo.org"] [uri "/.env.local"] [unique_id "ar4ojOWJgBchQg4BtgDX8AAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack