๐บ๐ธ
TPI-Abuse
2026-09-24 11:10:52
(39 minutes ago)
(mod_security) mod_security (id:210730) triggered by 34.62.199.37 (37.199.62.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.62.199.37 (37.199.62.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 07:10:49.116432 2026] [security2:error] [pid 398:tid 398] [client 34.62.199.37:34848] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.vaezi.com|F|2"] [data ".vaezi.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.vaezi.com"] [uri "/z9x8c7v6b5-debug-trigger-www.vaezi.com"] [unique_id "arUFOaTYW1XVCbV61GPjAQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 09:33:32
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.62.199.37 (37.199.62.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.62.199.37 (37.199.62.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 05:33:28.414654 2026] [security2:error] [pid 1907:tid 1907] [client 34.62.199.37:33180] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.thomasgardner.com"] [uri "/@fs/app/.env.production"] [unique_id "arTuaCPsVA1DLBfasXfyswAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
pipeline.es
2026-09-24 08:58:36
(2 hours ago)
Web scanning / probing for vulnerable paths
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 08:54:42
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.62.199.37 (37.199.62.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.62.199.37 (37.199.62.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 04:54:37.951834 2026] [security2:error] [pid 5748:tid 5748] [client 34.62.199.37:33062] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.thegrabbagshow.com"] [uri "/.env"] [unique_id "arTlTUYQLwFK45hHtuoQFwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 07:09:26
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.62.199.37 (37.199.62.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.62.199.37 (37.199.62.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 03:09:20.591222 2026] [security2:error] [pid 17764:tid 17764] [client 34.62.199.37:49438] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.studioarmanni.com|F|2"] [data ".studioarmanni.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.studioarmanni.com"] [uri "/z9x8c7v6b5-debug-trigger-www.studioarmanni.com"] [unique_id "arTMoEbZZfqQeTtRhTYgCgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-24 07:08:56
(4 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 06:36:42
(5 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.62.199.37 (37.199.62.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.62.199.37 (37.199.62.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 02:36:37.290378 2026] [security2:error] [pid 26556:tid 26556] [client 34.62.199.37:45534] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.spiht.com|F|2"] [data ".spiht.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.spiht.com"] [uri "/z9x8c7v6b5-debug-trigger-www.spiht.com"] [unique_id "arTE9VPfhsjcZbf8zoCdXAAAADY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 06:20:04
(5 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.62.199.37 (37.199.62.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.62.199.37 (37.199.62.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 02:19:58.079781 2026] [security2:error] [pid 17943:tid 17943] [client 34.62.199.37:46400] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.solutiongroove.com|F|2"] [data ".solutiongroove.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.solutiongroove.com"] [uri "/z9x8c7v6b5-debug-trigger-www.solutiongroove.com"] [unique_id "arTBDp3u5RRpRgfunBYhFQAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 05:52:22
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.62.199.37 (37.199.62.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.62.199.37 (37.199.62.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 01:52:17.086447 2026] [security2:error] [pid 351:tid 351] [client 34.62.199.37:34402] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/Web.config" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.sjjcox.com"] [uri "/web.config"] [unique_id "arS6kS9oPoOXflNsONhBeAAAAC4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 05:35:11
(6 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.62.199.37 (37.199.62.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.62.199.37 (37.199.62.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 01:35:07.428170 2026] [security2:error] [pid 22650:tid 22650] [client 34.62.199.37:35892] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.sicktracks.com|F|2"] [data ".sicktracks.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.sicktracks.com"] [uri "/z9x8c7v6b5-debug-trigger-www.sicktracks.com"] [unique_id "arS2i8UiUSDfLmaHavIaWgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 05:19:51
(6 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.62.199.37 (37.199.62.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.62.199.37 (37.199.62.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 01:19:46.530911 2026] [security2:error] [pid 31364:tid 31364] [client 34.62.199.37:42662] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.shannonraevocalstudio.com|F|2"] [data ".shannonraevocalstudio.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.shannonraevocalstudio.com"] [uri "/z9x8c7v6b5-debug-trigger-www.shannonraevocalstudio.com"] [unique_id "arSy8nG8k-YrVwgRm1-HOgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 05:00:01
(6 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.62.199.37 (37.199.62.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.62.199.37 (37.199.62.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 00:59:56.849527 2026] [security2:error] [pid 9306:tid 9306] [client 34.62.199.37:46316] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.securitymontana.com|F|2"] [data ".securitymontana.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.securitymontana.com"] [uri "/z9x8c7v6b5-debug-trigger-www.securitymontana.com"] [unique_id "arSuTJiTwe77O7mbj1oezAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 04:41:56
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.62.199.37 (37.199.62.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.62.199.37 (37.199.62.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 00:41:48.707206 2026] [security2:error] [pid 6156:tid 6156] [client 34.62.199.37:46840] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/Web.config" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.sarawatt.com"] [uri "/web.config"] [unique_id "arSqDHmH9TCb2nMKR8WEvQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
factor1
2026-09-24 04:16:40
(7 hours ago)
CrowdSec at sherman Reports Abuse
Web App Attack
๐ฉ๐ช
bazter.pro
2026-09-24 04:07:29
(7 hours ago)
Fail2Ban: plesk-bot-aggressive - 15 failures
Port Scan
Bad Web Bot
Web App Attack