๐บ๐ธ
TPI-Abuse
2026-10-01 17:09:26
(6 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.61.169.244 (244.169.61.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.61.169.244 (244.169.61.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 13:09:21.784224 2026] [security2:error] [pid 28228:tid 28228] [client 34.61.169.244:55204] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.livegoodherbs.com|F|2"] [data ".livegoodherbs.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.livegoodherbs.com"] [uri "/z9x8c7v6b5-debug-trigger-www.livegoodherbs.com"] [unique_id "ar6TwRGbaJU3gFdBwQUXPAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-01 17:04:04
(6 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
๐ณ๐ฑ
Site.eu
2026-10-01 16:52:05
(7 hours ago)
Excessive multi-domain requests
Brute-Force
๐ณ๐ฑ
Site.eu
2026-10-01 16:30:44
(7 hours ago)
Excessive 404/403 errors
Brute-Force
๐จ๐ฆ
polycoda
2026-10-01 15:49:57
(8 hours ago)
AutoBlock: ๐ก Port Scan (Non Decay-Based) - โ Excessive 40X Errors (Decay-Based)
Port Scan
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-01 15:44:14
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.61.169.244 (244.169.61.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.61.169.244 (244.169.61.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 11:44:07.481226 2026] [security2:error] [pid 17882:tid 17882] [client 34.61.169.244:56850] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.lawrencehale.com"] [uri "/.env.dev"] [unique_id "ar5_x3g7jVHaLopsVDVeGAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 15:19:04
(8 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.61.169.244 (244.169.61.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.61.169.244 (244.169.61.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 11:18:59.701272 2026] [security2:error] [pid 25946:tid 25946] [client 34.61.169.244:33098] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||crm.merlinaerospace.com|F|2"] [data ".merlinaerospace.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "crm.merlinaerospace.com"] [uri "/z9x8c7v6b5-debug-trigger-crm.merlinaerospace.com"] [unique_id "ar55448_CPjV8P8Ey9FYswAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 14:18:14
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.61.169.244 (244.169.61.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.61.169.244 (244.169.61.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 10:18:11.684214 2026] [security2:error] [pid 18683:tid 18683] [client 34.61.169.244:45124] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.paulpasquali.com"] [uri "/.env.js"] [unique_id "ar5ro6AENcQ4wuTX4AuWbwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
updown.io
2026-10-01 14:13:28
(9 hours ago)
{"level":"info","ts":1790864006.0948935,"logger":"http.log.access.log1","msg":"handled request","req ...
show more
{"level":"info","ts":1790864006.0948935,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.61.169.244","remote_port":"38606","client_ip":"34.61.169.244","proto":"HTTP/2.0","method":"GET","host":"status.phlow.com.au","uri":"/config.json","headers":{"Cookie":["REDACTED"],"X-Middleware-Subrequest":["src/middleware:nowaf:src/middleware:src/middleware:src/middleware:src/middleware:middleware:middleware:nowaf:middleware:middleware:middleware:pages/_middleware"],"X-Nextjs-Data":["1"],"User-Agent":["Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/)"],"Accept":["*/*"],"Accept-Encoding":["gzip"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"h2","server_name":"status.phlow.com.au","ech":false}},"bytes_read":0,"user_id":"","duration":0.000390195,"size":0,"status":429,"resp_headers":{"Server":["Caddy"],"Alt-Svc":["h3=\":443\"; ma=2592000"],"Retry-After":["1"]}}
{"level":"info","ts":1790864006.0962067,"logger":"http.log.access.log1","msg":"han
...
show less
DDoS Attack
Web App Attack
Anonymous
2026-10-01 13:40:02
(10 hours ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 13:19:34
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.61.169.244 (244.169.61.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.61.169.244 (244.169.61.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 09:19:30.909470 2026] [security2:error] [pid 11704:tid 11704] [client 34.61.169.244:51238] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.ppcspetsitting.com"] [uri "/laravel/.env"] [unique_id "ar5d4kDygKqPxo3iJJgY4AAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
sibahota
2026-10-01 13:13:06
(10 hours ago)
34.61.169.244 - - [01/Oct/2026:13:13:05 +0000] nidandiagnostic.com "GET /credentials.js HTTP/2.0" 40 ...
show more
34.61.169.244 - - [01/Oct/2026:13:13:05 +0000] nidandiagnostic.com "GET /credentials.js HTTP/2.0" 404 6649 0.005 "-" "Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)" 172.17.0.1:3051 404 0.005 "http://nidandiagnostic.com/credentials.js"
...
show less
Web App Attack
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-10-01 12:52:59
(11 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.61.169.244 (244.169.61.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:949110) triggered by 34.61.169.244 (244.169.61.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 08:52:56.194381 2026] [security2:error] [pid 10626:tid 10626] [client 34.61.169.244:54930] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "letahaabooking.com"] [uri "/z9x8c7v6b5-debug-trigger-letahaabooking.com"] [unique_id "ar5XqJFREL9_20yZ2CJtUgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 12:13:37
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.61.169.244 (244.169.61.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.61.169.244 (244.169.61.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 08:13:32.801717 2026] [security2:error] [pid 30297:tid 30382] [client 34.61.169.244:44488] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.leadingedgesupply.com"] [uri "/.env.dev"] [unique_id "ar5ObKe8fe_7LVluXsl52gAAAE4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 11:54:33
(12 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.61.169.244 (244.169.61.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.61.169.244 (244.169.61.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 07:54:28.448501 2026] [security2:error] [pid 6114:tid 6114] [client 34.61.169.244:41244] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||status.mumawvickers.com|F|2"] [data ".mumawvickers.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "status.mumawvickers.com"] [uri "/z9x8c7v6b5-debug-trigger-status.mumawvickers.com"] [unique_id "ar5J9LQXPn43O1TxK7R4YgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack