🇫🇷
dynamix
2026-09-12 23:18:01
(11 minutes ago)
Multiple WAF Violations
Web App Attack
🇺🇸
chronos
2026-09-12 13:41:50
(9 hours ago)
[AUTORAVALT][[12/09/2026 - 10:41:50 -03:00 UTC]
Attack from [Google LLC]
[34.45.27.181][181.27.45.34 ...
show more
[AUTORAVALT][[12/09/2026 - 10:41:50 -03:00 UTC]
Attack from [Google LLC]
[34.45.27.181][181.27.45.34.bc.googleusercontent.com]
Action: BLocKed
DDoS Attack -> Participating in distributed denial-of-service.
Phishing -> Phishing websites and/or email.
Web Spam -> Comment/forum spam, HTTP referer spam, or other CMS spam.
Blog Spam -> CMS blog comment spam.
Web A]
...
show less
DDoS Attack
Phishing
Web Spam
Blog Spam
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 13:29:16
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.45.27.181 (181.27.45.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.45.27.181 (181.27.45.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 09:29:09.762215 2026] [security2:error] [pid 3650:tid 3650] [client 34.45.27.181:55972] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.stodder.com"] [uri "/.env"] [unique_id "aqVTpQfV7GQYGOmkjkxTWgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
sdos.es
2026-09-12 01:25:11
(22 hours ago)
"Restricted File Access Attempt - Matched Data: /.env found within REQUEST_FILENAME: /backend/.env"
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 19:08:28
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.45.27.181 (181.27.45.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.45.27.181 (181.27.45.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 15:08:20.763199 2026] [security2:error] [pid 12055:tid 12055] [client 34.45.27.181:45600] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||streetfightfilm.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "streetfightfilm.com"] [uri "/z9x8c7v6b5-debug-trigger-streetfightfilm.com"] [unique_id "aqRRpEWO97TE_15cQe5u7wAAAHs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 18:51:20
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.45.27.181 (181.27.45.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.45.27.181 (181.27.45.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 14:51:15.366440 2026] [security2:error] [pid 12533:tid 12533] [client 34.45.27.181:54814] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||strawberryhillchristmas.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "strawberryhillchristmas.com"] [uri "/rclone.conf"] [unique_id "aqRNo65VSGZh5UQ5DHnuqAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇭
zynex
2026-09-11 18:49:20
(1 day ago)
URL Probing: /.env
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 18:15:27
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.45.27.181 (181.27.45.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.45.27.181 (181.27.45.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 14:15:19.797358 2026] [security2:error] [pid 15741:tid 15843] [client 34.45.27.181:58956] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||straight8inc.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "straight8inc.com"] [uri "/z9x8c7v6b5-debug-trigger-straight8inc.com"] [unique_id "aqRFN2nbH8m3pyXAgPOmoAAAAI0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-09-11 18:05:22
(1 day ago)
Too many Status 40X (20)
Scanning/Probing (18)
Brute-Force
Web App Attack
🇫🇷
dynamix
2026-09-11 18:02:59
(1 day ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 17:49:40
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.45.27.181 (181.27.45.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.45.27.181 (181.27.45.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 13:49:36.765667 2026] [security2:error] [pid 26732:tid 26732] [client 34.45.27.181:48106] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stormwlf.com"] [uri "/.env"] [unique_id "aqQ_MI4SF2bjQzymHshhhwAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
sdos.es
2026-09-11 17:49:06
(1 day ago)
"Restricted File Access Attempt - Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"
Web App Attack
Anonymous
2026-09-11 17:40:11
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted] 34.45.27.181 (US/United States/181.27.4 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.45.27.181 (US/United States/181.27.45.34.bc.googleusercontent.com)
show less
SQL Injection
🇺🇸
TPI-Abuse
2026-09-11 17:12:34
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.45.27.181 (181.27.45.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.45.27.181 (181.27.45.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 13:12:28.695609 2026] [security2:error] [pid 12043:tid 12043] [client 34.45.27.181:44926] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||stoneybluff.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "stoneybluff.com"] [uri "/rclone.conf"] [unique_id "aqQ2fOZA0LUFaEwTCY8pugAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Savvii
2026-09-11 16:36:42
(1 day ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack