π«π·
Octopuce
2026-09-30 19:21:52
(3 days ago)
Aggressive web search of vulnerable pages: /openapi.json /api/openapi.json /api/v1/config/ /swagger. ...
show more
Aggressive web search of vulnerable pages: /openapi.json /api/openapi.json /api/v1/config/ /swagger.json /__debug__/ /userfiles/x?path=../../.e ...
show less
Web App Attack
π¬π§
Apache
2026-09-30 17:34:41
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.6.90.21 (21.90.6.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.6.90.21 (21.90.6.34.bc.googleusercontent.com): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
π³π±
WeCloudit-Anti-Abuse
2026-09-30 16:49:23
(3 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
πΊπΈ
thieuleu
2026-09-30 16:21:23
(3 days ago)
Unauthorized connection attempt blocked by firewall policy. Web application hardening active.
Brute-Force
Exploited Host
πΊπΈ
TPI-Abuse
2026-09-30 16:20:47
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 34.6.90.21 (21.90.6.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210730) triggered by 34.6.90.21 (21.90.6.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 12:20:39.939799 2026] [security2:error] [pid 12305:tid 12305] [client 34.6.90.21:57360] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.produktives.com|F|2"] [data ".produktives.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.produktives.com"] [uri "/z9x8c7v6b5-debug-trigger-autodiscover.produktives.com"] [unique_id "ar02182wrA__TiJRRiYJXAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-30 15:54:05
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 34.6.90.21 (21.90.6.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210730) triggered by 34.6.90.21 (21.90.6.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 11:54:02.245737 2026] [security2:error] [pid 1433:tid 1433] [client 34.6.90.21:46238] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.raystransmission.com|F|2"] [data ".raystransmission.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.raystransmission.com"] [uri "/z9x8c7v6b5-debug-trigger-autodiscover.raystransmission.com"] [unique_id "ar0wmsfJive5Y8SoRHa2ZgAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
dynamix
2026-09-30 15:52:39
(3 days ago)
Multiple WAF Violations
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-30 15:38:40
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.6.90.21 (21.90.6.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.6.90.21 (21.90.6.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 11:38:36.762099 2026] [security2:error] [pid 24464:tid 24464] [client 34.6.90.21:45972] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.silsby.com"] [uri "/static../.env"] [unique_id "ar0s_M7aCHjiN3jH2s9ZBQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-30 15:16:54
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.6.90.21 (21.90.6.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.6.90.21 (21.90.6.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 11:16:46.476422 2026] [security2:error] [pid 4113:tid 4118] [client 34.6.90.21:37568] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.resort4pets.com"] [uri "/.env.js"] [unique_id "ar0n3qAgFLYPtxkaoUqrpAAAAIM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-30 14:55:39
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 34.6.90.21 (21.90.6.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210730) triggered by 34.6.90.21 (21.90.6.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 10:55:34.116273 2026] [security2:error] [pid 18507:tid 18507] [client 34.6.90.21:52670] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.randeen.com|F|2"] [data ".randeen.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.randeen.com"] [uri "/z9x8c7v6b5-debug-trigger-autodiscover.randeen.com"] [unique_id "ar0i5p9sERqeMSo04AJFxwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-30 14:34:54
(3 days ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-30 14:34:36
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 34.6.90.21 (21.90.6.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210730) triggered by 34.6.90.21 (21.90.6.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 10:34:29.138775 2026] [security2:error] [pid 19520:tid 19520] [client 34.6.90.21:48522] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||hub.semisysteme.com|F|2"] [data ".semisysteme.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "hub.semisysteme.com"] [uri "/z9x8c7v6b5-debug-trigger-hub.semisysteme.com"] [unique_id "ar0d9THfVO0mdlTyCxwLWwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-30 14:18:20
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 34.6.90.21 (21.90.6.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210730) triggered by 34.6.90.21 (21.90.6.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 10:18:17.268804 2026] [security2:error] [pid 19123:tid 19123] [client 34.6.90.21:51322] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.serranoscoffee.com|F|2"] [data ".serranoscoffee.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.serranoscoffee.com"] [uri "/z9x8c7v6b5-debug-trigger-autodiscover.serranoscoffee.com"] [unique_id "ar0aKTlXLoah5Rb9gIY8ZQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-30 13:45:45
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 34.6.90.21 (21.90.6.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210730) triggered by 34.6.90.21 (21.90.6.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 09:45:40.468182 2026] [security2:error] [pid 4129:tid 4129] [client 34.6.90.21:56294] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.openheartwellness.com|F|2"] [data ".openheartwellness.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.openheartwellness.com"] [uri "/z9x8c7v6b5-debug-trigger-autodiscover.openheartwellness.com"] [unique_id "ar0ShMWwKsjV5YPz646NJgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-30 12:51:14
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 34.6.90.21 (21.90.6.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210730) triggered by 34.6.90.21 (21.90.6.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 08:51:08.456440 2026] [security2:error] [pid 8667:tid 8667] [client 34.6.90.21:36988] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||serviciodepinturadecasas.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "serviciodepinturadecasas.com"] [uri "/z9x8c7v6b5-debug-trigger-serviciodepinturadecasas.com"] [unique_id "ar0FvESFMGfQ_WoJMqG3SwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack