๐บ๐ธ
TPI-Abuse
2026-09-23 17:48:18
(39 minutes ago)
(mod_security) mod_security (id:210730) triggered by 34.47.10.68 (68.10.47.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.47.10.68 (68.10.47.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 13:48:13.909982 2026] [security2:error] [pid 28915:tid 28915] [client 34.47.10.68:44650] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||banis-associates.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "banis-associates.com"] [uri "/z9x8c7v6b5-debug-trigger-banis-associates.com"] [unique_id "arQQ3eauTvec6z06txio0AAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
IRISIO
2026-09-23 17:30:44
(56 minutes ago)
scans/SQL injection/spam posts : 225 queries
Web App Attack
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-09-23 17:30:17
(57 minutes ago)
(mod_security) mod_security (id:210730) triggered by 34.47.10.68 (68.10.47.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.47.10.68 (68.10.47.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 13:30:10.326236 2026] [security2:error] [pid 15072:tid 15072] [client 34.47.10.68:41598] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||calvinavalos.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "calvinavalos.com"] [uri "/z9x8c7v6b5-debug-trigger-calvinavalos.com"] [unique_id "arQMol_2xMKOro_OBFiSEAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-23 17:30:03
(57 minutes ago)
CrowdSec decision: crowdsecurity/http-sensitive-files (origin: crowdsec)
Web App Attack
๐ซ๐ท
COMAITE
2026-09-23 17:16:05
(1 hour ago)
Suspicious URL access.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 17:04:53
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 34.47.10.68 (68.10.47.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.47.10.68 (68.10.47.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 13:04:50.184763 2026] [security2:error] [pid 2204:tid 2204] [client 34.47.10.68:59764] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||deafinitely.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "deafinitely.com"] [uri "/z9x8c7v6b5-debug-trigger-deafinitely.com"] [unique_id "arQGsgXZrW_zWztSnofV6AAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
kosada.com
2026-09-23 16:45:20
(1 hour ago)
Repeated requests for suspicious nonexistent URLs, for example: /account/login (HTTP/2.0 port 443, u ...
show more
Repeated requests for suspicious nonexistent URLs, for example: /account/login (HTTP/2.0 port 443, user agent: "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36")
show less
Web App Attack
๐ฉ๐ช
TheDjRider
2026-09-23 16:44:01
(1 hour ago)
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban tri ...
show more
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban triggered. Detection time (UTC): 2026-09-23T16:43:59.357350775Z. Context: http_status=302
show less
Web App Attack
๐ฉ๐ช
FD-IX
2026-09-23 16:36:26
(1 hour ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-23 16:04:50
(2 hours ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 15:57:38
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.47.10.68 (68.10.47.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.47.10.68 (68.10.47.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 11:57:33.137750 2026] [security2:error] [pid 14870:tid 14870] [client 34.47.10.68:41778] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||hatfulofrain.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "hatfulofrain.com"] [uri "/z9x8c7v6b5-debug-trigger-hatfulofrain.com"] [unique_id "arP27ZC83PIGUBKWZ4m_pQAAAFg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
interbiznw.com
2026-09-23 15:40:16
(2 hours ago)
malicious-web-requests-vulnerability-scanning
Hacking
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 14:57:50
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.47.10.68 (68.10.47.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.47.10.68 (68.10.47.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 10:57:44.581287 2026] [security2:error] [pid 25720:tid 25720] [client 34.47.10.68:59746] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mainescentsecrets.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mainescentsecrets.com"] [uri "/z9x8c7v6b5-debug-trigger-mainescentsecrets.com"] [unique_id "arPo6J9curfyO00DKk_FqAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
voormedia
2026-09-23 14:27:05
(4 hours ago)
Accessed trap at '/.env'
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 14:26:17
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.47.10.68 (68.10.47.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.47.10.68 (68.10.47.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 10:26:12.102339 2026] [security2:error] [pid 18985:tid 18985] [client 34.47.10.68:53816] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||onlyincanada-eh.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "onlyincanada-eh.com"] [uri "/z9x8c7v6b5-debug-trigger-onlyincanada-eh.com"] [unique_id "arPhhIvceqktyRGNNW72EAAAACo"]
show less
Brute-Force
Bad Web Bot
Web App Attack