🇬🇧
NotCool
2026-09-12 07:46:33
(2 hours ago)
[7200] (GITPROBE,DOTENVPROBE,CRAWLDELAY) Login failure/trigger from 34.52.157.65 (BE/Belgium/65.157. ...
show more
[7200] (GITPROBE,DOTENVPROBE,CRAWLDELAY) Login failure/trigger from 34.52.157.65 (BE/Belgium/65.157.52.34.bc.googleusercontent.com): 50 in the last 3600 secs
show less
Brute-Force
🇺🇸
IndigoRidge
2026-09-12 07:04:04
(2 hours ago)
[Sat Sep 12 03:04:00.621567 2026] [authz_core:error] [pid 516276:tid 139968734201600] [client 34.52. ...
show more
[Sat Sep 12 03:04:00.621567 2026] [authz_core:error] [pid 516276:tid 139968734201600] [client 34.52.157.65:0] AH01630: client denied by server configuration: /usr/share/psa-roundcube/.env.old
[Sat Sep 12 03:04:01.207979 2026] [authz_core:error] [pid 183352:tid 139968633489152] [client 34.52.157.65:0] AH01630: client denied by server configuration: /usr/share/psa-roundcube/@fs
[Sat Sep 12 03:04:01.580635 2026] [authz_core:error] [pid 516276:tid 139968717416192] [client 34.52.157.65:0] AH01630: client denied by server configuration: /usr/share/psa-roundcube/manifest.webmanifest
[Sat Sep 12 03:04:02.016974 2026] [authz_core:error] [pid 516276:tid 139968219444992] [client 34.52.157.65:0] AH01630: client denied by server configuration: /usr/share/psa-roundcube/api
[Sat Sep 12 03:04:03.741974 2026] [authz_core:error] [pid 516276:tid 139968759379712] [client 34.52.157.65:0] AH01630: client denied by server configuration: /usr/share/psa-roundcube/ngsw.json
...
show less
Web App Attack
🇲🇽
octageeks.com
2026-09-12 04:19:03
(5 hours ago)
Wordpress malicious attack:[octablocked]
Web App Attack
🇿🇦
conure.sh
2026-09-12 00:45:11
(9 hours ago)
csagent: score 20.8: 404 noise floor x3, secrets grab x2; 1 domain(s) in 0s
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 00:42:47
(9 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.52.157.65 (65.157.52.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.52.157.65 (65.157.52.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 20:42:40.791753 2026] [security2:error] [pid 22203:tid 22203] [client 34.52.157.65:37070] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.theoriginrocks.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.theoriginrocks.com"] [uri "/rclone.conf"] [unique_id "aqSgAM82ThGoFjY9DiwpTAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 17:20:06
(16 hours ago)
(mod_security) mod_security (id:210580) triggered by 34.52.157.65 (65.157.52.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210580) triggered by 34.52.157.65 (65.157.52.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 13:19:55.777689 2026] [security2:error] [pid 10720:tid 10720] [client 34.52.157.65:45316] ModSecurity: Access denied with code 403 (phase 2). Matched phrase ".ssh/id_rsa" at ARGS:filename. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||therhclan.com|F|2"] [data "Matched Data: .ssh/id_rsa found within ARGS:filename: file:/root/.ssh/id_rsa"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "therhclan.com"] [uri "/__vite_rsc_findSourceMapURL"] [unique_id "aqQ4O4nqHWm5Hc0_V8uUKgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 16:46:40
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.52.157.65 (65.157.52.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.52.157.65 (65.157.52.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 12:46:32.876584 2026] [security2:error] [pid 27430:tid 27430] [client 34.52.157.65:50218] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "theradarshop.com"] [uri "/.env.old"] [unique_id "aqQwaHdAXt3hDmhndjeiwQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 16:25:05
(17 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.52.157.65 (65.157.52.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.52.157.65 (65.157.52.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 12:24:57.884391 2026] [security2:error] [pid 26301:tid 26301] [client 34.52.157.65:54698] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||thepotteriesmesilla.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "thepotteriesmesilla.com"] [uri "/rclone.conf"] [unique_id "aqQrWaWEyCLkQ6AzngZ-TgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
NotCool
2026-09-11 15:53:39
(18 hours ago)
(CRAWLDELAY) Generic Bot Crawl-delay Violation 34.52.157.65 (BE/Belgium/65.157.52.34.bc.googleuserco ...
show more
(CRAWLDELAY) Generic Bot Crawl-delay Violation 34.52.157.65 (BE/Belgium/65.157.52.34.bc.googleusercontent.com): 50 in the last 3600 secs
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-11 15:43:18
(18 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.52.157.65 (65.157.52.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.52.157.65 (65.157.52.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 11:43:11.283776 2026] [security2:error] [pid 29308:tid 29308] [client 34.52.157.65:42808] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||theoriginclinickc.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "theoriginclinickc.com"] [uri "/z9x8c7v6b5-debug-trigger-theoriginclinickc.com"] [unique_id "aqQhj5B3jVJC6rEMvUcBOgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack