๐บ๐ธ
TPI-Abuse
2026-10-02 15:20:45
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.40.29.240 (240.29.40.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.40.29.240 (240.29.40.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 11:20:39.741089 2026] [security2:error] [pid 5653:tid 5653] [client 34.40.29.240:48866] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/Web.config" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.hongkonger.org"] [uri "/web.config"] [unique_id "ar_LxyOxIsfpDzBXyno8cwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 14:54:39
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.40.29.240 (240.29.40.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.40.29.240 (240.29.40.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 10:54:33.809572 2026] [security2:error] [pid 24343:tid 24343] [client 34.40.29.240:59722] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||hamiltoncountyuca.org|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "hamiltoncountyuca.org"] [uri "/server.key"] [unique_id "ar_FqfFsvcdbooTqNcjOawAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
jormaster3k
2026-10-02 12:48:20
(1 day ago)
Attack against Apache (too many 404s)
Web App Attack
Anonymous
2026-10-02 12:43:57
(1 day ago)
34.40.29.240 - - [02/Oct/2026:14:43:56 +0200] "GET /model/info HTTP/2.0" 404 146 "-" "Mozilla/5.0 (c ...
show more
34.40.29.240 - - [02/Oct/2026:14:43:56 +0200] "GET /model/info HTTP/2.0" 404 146 "-" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)" "-"
34.40.29.240 - - [02/Oct/2026:14:43:56 +0200] "GET /e41k6e7zgoeqmekh8ydi HTTP/2.0" 404 146 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)" "-"
34.40.29.240 - - [02/Oct/2026:14:43:56 +0200] "POST / HTTP/2.0" 405 150 "-" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)" "-"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 12:42:05
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.40.29.240 (240.29.40.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.40.29.240 (240.29.40.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 08:41:59.862099 2026] [security2:error] [pid 806709:tid 806709] [client 34.40.29.240:34608] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.greenroomonline.org"] [uri "/.htpasswd"] [unique_id "ar-ml8L49UT1msV44O7nnwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-10-02 12:28:28
(1 day ago)
[FriOct0214:28:26.5104582026][security2:error][pid2339478:tid2339530][client34.40.29.240:0]ModSecuri ...
show more
[FriOct0214:28:26.5104582026][security2:error][pid2339478:tid2339530][client34.40.29.240:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"cpanel.hopitalprovidence.org\"][uri\"/storage/logs/laravel.log\"][unique_id\"ar-jah3WD5aZlSsTkn8YSQAAAFA\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 12:24:36
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.40.29.240 (240.29.40.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.40.29.240 (240.29.40.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 08:24:30.917674 2026] [security2:error] [pid 15070:tid 15070] [client 34.40.29.240:34156] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.intergalactichumans.com.mroxygen.org"] [uri "/.htpasswd"] [unique_id "ar-ifqyxK4k1UzhwKnd0rAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-02 12:03:35
(1 day ago)
[ti-04al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apac ...
show more
[ti-04al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apache-404. Example: 34.40.29.240 - - [02/Oct/2026:14:03:27 +0200] "GET /60rfto3yhar0zju0tdpd HTTP/2.0" 404 1878 "-" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)"
34.40.29.240 - - [02/Oct/2026:14:03:27 +0200] "GET /yxe1cxhg9bk6qq3r6tl1 HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)"
34.40.29.240 - - [02/Oct/2026:14:03:27 +0200] "GET /z9x8c7v6b5-debug-trigger-booking.mcbackup.org HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)"
34.40.29.240 - - [02/Oct/2026:14:03:27 +0200] "POST /graphql HTTP/2.0" 404 1855 "https://booking.mcbackup.org" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 11:46:41
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.40.29.240 (240.29.40.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.40.29.240 (240.29.40.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 07:46:34.696746 2026] [security2:error] [pid 9727:tid 9727] [client 34.40.29.240:55484] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.henning.org"] [uri "/.env.development"] [unique_id "ar-ZmvtoLM6iASBbaRMoUgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
Kotisivu.org
2026-10-02 11:30:29
(1 day ago)
Automated web scanner probe: GET /api/console/api_server?<redacted> on enterprise.kotisivu.org.
Brute-Force
Web App Attack
๐ฌ๐ง
Comberton
2026-10-02 11:08:15
(1 day ago)
Ban via by F2B apache-wordfence jail
Brute-Force
๐ฉ๐ช
yitzhaq
2026-10-02 11:05:20
(1 day ago)
34.40.29.240 - - [02/Oct/2026:13:05:17 +0200] "GET /.env.dev HTTP/2.0" 403 297 "-" "Mozilla/5.0 (com ...
show more
34.40.29.240 - - [02/Oct/2026:13:05:17 +0200] "GET /.env.dev HTTP/2.0" 403 297 "-" "Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)"
34.40.29.240 - - [02/Oct/2026:13:05:17 +0200] "GET /storage/.env HTTP/2.0" 403 297 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)"
34.40.29.240 - - [02/Oct/2026:13:05:16 +0200] "GET /storage/logs/laravel.log HTTP/2.0" 404 43270 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)"
34.40.29.240 - - [02/Oct/2026:13:05:17 +0200] "GET /configuration.php.bak HTTP/2.0" 404 43270 "-" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)"
34.40.29.240 - - [02/Oct/2026:13:05:17 +0200] "GET /.env.swp HTTP/2.0" 404 43261 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)"
34.40.29.240 - - [02/Oct/2026:13:05:17 +0200] "GET /wp/.env HTTP/2.0" 404 43270 "-" "CCBot/2.0
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-02 10:55:58
(1 day ago)
(mod_security) mod_security (id:949110) triggered by 34.40.29.240 (240.29.40.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:949110) triggered by 34.40.29.240 (240.29.40.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 06:55:54.125883 2026] [security2:error] [pid 24410:tid 24410] [client 34.40.29.240:57722] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.music.freedrm.org"] [uri "/.env.local"] [unique_id "ar-NunyVzBtCj5VL9_rNNgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-02 10:54:02
(1 day ago)
Fail2Ban apache-noscript
Bad Web Bot
Anonymous
2026-10-02 10:29:18
(1 day ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking