๐บ๐ธ
TPI-Abuse
2026-09-22 00:36:58
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.67.70.128 (128.70.67.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.67.70.128 (128.70.67.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 20:36:56.322489 2026] [security2:error] [pid 18693:tid 18693] [client 34.67.70.128:54140] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.vabq.com"] [uri "/server/.env"] [unique_id "arHNqC5yKZKtnGKOade4vQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 22:28:30
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.67.70.128 (128.70.67.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.67.70.128 (128.70.67.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 18:28:23.055452 2026] [security2:error] [pid 9034:tid 9034] [client 34.67.70.128:41908] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.arsenaultartistmanagement.com"] [uri "/.git/config"] [unique_id "arGvh96QwYaOcEWcMpeVVwAAAGY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 21:27:08
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.67.70.128 (128.70.67.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.67.70.128 (128.70.67.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 17:27:04.041502 2026] [security2:error] [pid 2935:tid 2935] [client 34.67.70.128:47884] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.agrollum.com"] [uri "/ml/.env"] [unique_id "arGhKGvi2RMXHC4epY_4PQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 20:02:40
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.67.70.128 (128.70.67.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.67.70.128 (128.70.67.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 16:02:35.031535 2026] [security2:error] [pid 12934:tid 12934] [client 34.67.70.128:50822] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.advanced-ventures.com|F|2"] [data ".advanced-ventures.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.advanced-ventures.com"] [uri "/z9x8c7v6b5-debug-trigger-mail.advanced-ventures.com"] [unique_id "arGNW8glDgBTaAjKrbcVJgAAADo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 17:32:29
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.67.70.128 (128.70.67.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.67.70.128 (128.70.67.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 13:32:24.068464 2026] [security2:error] [pid 25748:tid 25748] [client 34.67.70.128:52384] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||agenticapocalypse.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "agenticapocalypse.com"] [uri "/z9x8c7v6b5-debug-trigger-agenticapocalypse.com"] [unique_id "arFqKMrzky4LMUsk1ydsWgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-21 15:32:58
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
mnsf
2026-09-21 15:05:41
(1 day ago)
Scanning/Probing (15)
Brute-Force
Web App Attack
๐ฉ๐ช
LRob
2026-09-21 14:59:59
(1 day ago)
This address swept through a list of pages that do not exist on our site within seconds โ a scanner ...
show more
This address swept through a list of pages that do not exist on our site within seconds โ a scanner working through its wordlist of exploitable paths. Blocked; please check the machine behind it for a scanner or malware. | method: GET | path: /up036bcf0kry4ilmurku (+10 more) | 2026-09-21 14:59 UTC
show less
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 14:36:31
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.67.70.128 (128.70.67.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.67.70.128 (128.70.67.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 10:36:25.230975 2026] [security2:error] [pid 24224:tid 24224] [client 34.67.70.128:59302] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||test.aiamur.com|F|2"] [data ".aiamur.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "test.aiamur.com"] [uri "/z9x8c7v6b5-debug-trigger-test.aiamur.com"] [unique_id "arFA6abxvthvjfb6RZwD6QAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-21 14:29:42
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/grafana-cve-2021-43798
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-21 14:09:11
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.67.70.128 (128.70.67.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.67.70.128 (128.70.67.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 10:09:04.971048 2026] [security2:error] [pid 22619:tid 22619] [client 34.67.70.128:38426] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||news.advantstudio.com|F|2"] [data ".advantstudio.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "news.advantstudio.com"] [uri "/z9x8c7v6b5-debug-trigger-news.advantstudio.com"] [unique_id "arE6gEdRvs9w5hMFgywtqwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-09-21 13:50:04
(2 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
Anonymous
2026-09-21 13:47:44
(2 days ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-21 13:41:11
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.67.70.128 (128.70.67.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.67.70.128 (128.70.67.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 09:41:05.343834 2026] [security2:error] [pid 24361:tid 24361] [client 34.67.70.128:38362] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.alitcogroup.com"] [uri "/.env.production"] [unique_id "arEz8fq61yFqON-itHo-mwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-21 13:40:27
(2 days ago)
Wordpress vulnerability scanning
...
Web App Attack