๐บ๐ธ
Tom USA
2026-06-08 17:47:00
(1 week ago)
Denial of Service (DoS) attack was discovered from 34.40.10.241: 250 connections per 30 seconds to 4 ...
show more
Denial of Service (DoS) attack was discovered from 34.40.10.241: 250 connections per 30 seconds to 443 port.
show less
DDoS Attack
Brute-Force
Hacking
Anonymous
2026-06-08 16:05:36
(1 week ago)
Multiple web server 400 error codes from same source ip
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 14:35:03
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 34.40.10.241 (241.10.40.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.40.10.241 (241.10.40.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 10:34:56.470027 2026] [security2:error] [pid 26111:tid 26111] [client 34.40.10.241:58740] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||asociacioncopan.org|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "asociacioncopan.org"] [uri "/.config/gcloud/credentials.db"] [unique_id "aibTEHgzV62vV1rCmXpiEwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Octopuce
2026-06-08 13:30:20
(1 week ago)
Aggressive web search of vulnerable pages: /admin/phpinfo.php /phpinfo.php /phptest.php /php.php /te ...
show more
Aggressive web search of vulnerable pages: /admin/phpinfo.php /phpinfo.php /phptest.php /php.php /test.php /api/phpinfo.php /info.php /debug.ph ...
show less
Web App Attack
๐จ๐ญ
4server
2026-06-08 11:19:52
(1 week ago)
[MonJun0813:19:49.8323622026][security2:error][pid3923833:tid3924728][client34.40.10.241:0]ModSecuri ...
show more
[MonJun0813:19:49.8323622026][security2:error][pid3923833:tid3924728][client34.40.10.241:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.9\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"motogiro.com\"][uri\"/actuator/heapdump\"][unique_id\"aialVVufXO9Um7IBOqe5FAAAAMc\"]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 10:42:37
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 34.40.10.241 (241.10.40.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.40.10.241 (241.10.40.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 06:42:31.609992 2026] [security2:error] [pid 22975:tid 22975] [client 34.40.10.241:35342] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bobbyunser.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bobbyunser.com"] [uri "/.config/gcloud/credentials.db"] [unique_id "aiacl_X_ukB4kWGXwFQVoQAAAD8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
pm33
2026-06-08 09:48:28
(1 week ago)
Excessive crawling HTTP 404
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 09:42:35
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 34.40.10.241 (241.10.40.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.40.10.241 (241.10.40.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 05:42:27.752808 2026] [security2:error] [pid 13235:tid 13235] [client 34.40.10.241:35332] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||danzadance.org|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "danzadance.org"] [uri "/backup.sql"] [unique_id "aiaOgzDcA6VzSZb0IWFcMwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-08 09:34:12
(1 week ago)
Bot / seems abusive / Apache connections: 118
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-06-08 07:45:37
(1 week ago)
Excessive multi-domain requests
Brute-Force
๐ณ๐ฑ
Savvii
2026-06-08 07:45:30
(1 week ago)
20 attempts against mh-misbehave-ban on orcus
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Hazzard
2026-06-08 07:00:31
(1 week ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-06-08 04:12:26
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 34.40.10.241 (241.10.40.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.40.10.241 (241.10.40.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 00:12:20.944331 2026] [security2:error] [pid 2138:tid 2138] [client 34.40.10.241:58804] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||littlebiglebanon.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "littlebiglebanon.com"] [uri "/.config/gcloud/credentials.db"] [unique_id "aiZBJDpdpY-jfca7UWq2LwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-06-08 01:55:03
(1 week ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐ซ๐ท
masterguru
2026-06-08 01:53:07
(1 week ago)
Restricted File Access Attempt. Matched phrase "config.php" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack