🇹🇭
thaizone.com
2026-09-12 06:58:33
(10 hours ago)
Brute Force Attack on a Web Resources (repeated 404) #1
DDoS Attack
Web Spam
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 06:12:09
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.48.216.245 (245.216.48.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.48.216.245 (245.216.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 02:12:04.910942 2026] [security2:error] [pid 29775:tid 29775] [client 34.48.216.245:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.theabstractpress.com"] [uri "/@fs/.env"] [unique_id "aqTtNK4YBPR3qjkKcvx23gAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇿🇦
conure.sh
2026-09-12 00:12:36
(17 hours ago)
csagent: score 15.2: 404 noise floor x21, secrets grab x1; 1 domain(s) in 1s
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 00:12:16
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.48.216.245 (245.216.48.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.48.216.245 (245.216.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 20:12:08.217532 2026] [security2:error] [pid 32369:tid 32369] [client 34.48.216.245:41134] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.theamarals.com"] [uri "/.git/config"] [unique_id "aqSY2B_DNiW5ZAmhVnW0ZAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 17:56:52
(23 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.48.216.245 (245.216.48.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.48.216.245 (245.216.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 13:56:46.524407 2026] [security2:error] [pid 2815:tid 2815] [client 34.48.216.245:36594] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||theateroobleck.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "theateroobleck.com"] [uri "/rclone.conf"] [unique_id "aqRA3pOdO5dfVg4vF61C0gAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-09-11 17:05:33
(1 day ago)
Too many Status 40X (15)
Brute-Force
Web App Attack
🇩🇪
stinpriza
2026-09-11 16:51:26
(1 day ago)
Web App Attack
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 16:46:34
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.48.216.245 (245.216.48.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.48.216.245 (245.216.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 12:46:28.530650 2026] [security2:error] [pid 17957:tid 17957] [client 34.48.216.245:49364] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||the-practical-pionus.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "the-practical-pionus.com"] [uri "/z9x8c7v6b5-debug-trigger-the-practical-pionus.com"] [unique_id "aqQwZDZAWNP8_PP74ZTsIgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-11 16:42:14
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 16:31:02
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.48.216.245 (245.216.48.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.48.216.245 (245.216.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 12:30:54.972746 2026] [security2:error] [pid 15741:tid 15843] [client 34.48.216.245:38398] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||thatspecial.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "thatspecial.com"] [uri "/rclone.conf"] [unique_id "aqQsvmnbH8m3pyXAgPOZogAAAI0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
ElertSec
2026-09-11 16:14:02
(1 day ago)
Defender Auto-Report: Automated malicious activity detected (11 matched events, ban duration 4h)
Hacking
🇹🇭
thaizone.com
2026-09-11 16:10:44
(1 day ago)
Brute Force Attack on a Web Resources (probe) #1
DDoS Attack
Web Spam
Brute-Force
Web App Attack
🇳🇱
Site.eu
2026-09-11 16:09:25
(1 day ago)
Excessive 404/403 errors
Brute-Force
🇺🇸
TPI-Abuse
2026-09-11 15:50:52
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.48.216.245 (245.216.48.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.48.216.245 (245.216.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 11:50:45.083787 2026] [security2:error] [pid 19476:tid 19476] [client 34.48.216.245:43430] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||tgcindustrial.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "tgcindustrial.com"] [uri "/rclone.conf"] [unique_id "aqQjVctB6CA0tvR3PebytAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Skyrider
2026-09-11 15:42:16
(1 day ago)
Nginx: HTTP 4xx probe/scan attempts. Automated fail2ban report.
Bad Web Bot
Web App Attack