πΊπΈ
TPI-Abuse
2026-10-01 06:30:54
(20 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.7.138.169 (169.138.7.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.7.138.169 (169.138.7.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 02:30:46.785800 2026] [security2:error] [pid 30970:tid 30970] [client 34.7.138.169:46024] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.medenseden.com|F|2"] [data ".medenseden.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.medenseden.com"] [uri "/z9x8c7v6b5-debug-trigger-www.medenseden.com"] [unique_id "ar3-FqgsY3cRPecCUutEWwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-01 05:50:19
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.7.138.169 (169.138.7.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.7.138.169 (169.138.7.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 01:50:12.782375 2026] [security2:error] [pid 27080:tid 27080] [client 34.7.138.169:37026] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.hacertests.com"] [uri "/static../.env"] [unique_id "ar30lPP0vx_KerBwyV1VLgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΈπ¬
simpeg-adm.bandung.go.id
2026-10-01 05:44:07
(21 hours ago)
01/Oct/2026:05:44:06 +0000;34.7.138.169;"/lib/terminal-xhr.php"
01/Oct/2026:05:44:06 +0000;34.7.138. ...
show more
01/Oct/2026:05:44:06 +0000;34.7.138.169;"/lib/terminal-xhr.php"
01/Oct/2026:05:44:06 +0000;34.7.138.169;"/oh28syxhqdjrelr2v45j"
01/Oct/2026:05:44:06 +0000;34.7.138.169;"/z9x8c7v6b5-debug-trigger-vendors.kanphotography.com"
01/Oct/2026:05:44:06 +0000;34.7.138.169;"/vax3j3uzgp346a0iil5s"
01/Oct/2026:05:44:06 +0000;34.7.138.169;"/dist/manifest.json"
01/Oct/2026:05:44:06 +0000;34.7.138.169;"/model/info"
01/Oct/2026:05:44:06 +0000;34.7.138.169;"/.vite/manifest.json"
...
show less
Web Spam
Brute-Force
Web App Attack
π¦πΊ
clapper
2026-10-01 05:37:00
(21 hours ago)
(cpanel) Failed cPanel login from 34.7.138.169 (169.138.7.34.bc.googleusercontent.com): 5 in the las ...
show more
(cpanel) Failed cPanel login from 34.7.138.169 (169.138.7.34.bc.googleusercontent.com): 5 in the last 3600 secs; ID: LUC
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-01 04:31:46
(22 hours ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
πΊπΈ
TPI-Abuse
2026-10-01 02:43:17
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.7.138.169 (169.138.7.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.7.138.169 (169.138.7.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 22:43:12.282091 2026] [security2:error] [pid 29469:tid 29469] [client 34.7.138.169:49752] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.hxctechllc.com|F|2"] [data ".hxctechllc.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.hxctechllc.com"] [uri "/z9x8c7v6b5-debug-trigger-www.hxctechllc.com"] [unique_id "ar3IwKCAGHKNYBn2LZwqTQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-01 01:56:18
(1 day ago)
Blocked by ModSec and CSF
Port Scan
π©πͺ
maxpower
2026-10-01 00:22:46
(1 day ago)
(junkbot) REGOLA 8 - Junk Bot Blocked 34.7.138.169 (169.138.7.34.bc.googleusercontent.com): 1 in the ...
show more
(junkbot) REGOLA 8 - Junk Bot Blocked 34.7.138.169 (169.138.7.34.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.7.138.169 - - [01/Oct/2026:02:22:42 +0200] "GET /xsfjzky4pqmyg2tant15 HTTP/2.0" 200 12116 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)" "-" host=www.grafica-x.com
show less
Port Scan
Anonymous
2026-10-01 00:17:14
(1 day ago)
34.7.138.169 - - [01/Oct/2026:08:17:13 +0800] "GET /2dqn5vpnity4wtjog6b2 HTTP/1.1" 404 30479 "-" "Mo ...
show more
34.7.138.169 - - [01/Oct/2026:08:17:13 +0800] "GET /2dqn5vpnity4wtjog6b2 HTTP/1.1" 404 30479 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36"
34.7.138.169 - - [01/Oct/2026:08:17:13 +0800] "GET /dist/manifest.json HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 Edg/153.0.0.0"
34.7.138.169 - - [01/Oct/2026:08:17:13 +0800] "GET /manifest.json HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 Edg/153.0.0.0"
34.7.138.169 - - [01/Oct/2026:08:17:13 +0800] "GET /assets/manifest.json HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 Edg/153.0.0.0"
34.7.138.169 - - [01/Oct/2026:08:17:13 +0800] "GET /asset-manifest.json HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.3
...
show less
Bad Web Bot
Web App Attack
πΏπ¦
conure.sh
2026-09-30 23:27:44
(1 day ago)
csagent: score 22.7: 404 noise floor x11, secrets grab x2; 1 domain(s) in 3s
Web App Attack
π¦πΊ
clapper
2026-09-30 20:39:05
(1 day ago)
(mod_security) mod_security (id:949110) triggered by 34.7.138.169 (169.138.7.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:949110) triggered by 34.7.138.169 (169.138.7.34.bc.googleusercontent.com): 3 in the last 3600 secs; ID: LUC
show less
Brute-Force
Bad Web Bot
π³π±
Site.eu
2026-09-30 19:08:39
(1 day ago)
Excessive multi-domain requests
Brute-Force
π©πͺ
bazter.pro
2026-09-30 17:23:28
(1 day ago)
Fail2Ban: plesk-bot-aggressive - 15 failures
Port Scan
Bad Web Bot
Web App Attack
π²πΎ
Rizzy
2026-09-30 16:45:58
(1 day ago)
Multiple WAF Violations
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-30 15:28:35
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.7.138.169 (169.138.7.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.7.138.169 (169.138.7.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 11:28:29.149622 2026] [security2:error] [pid 32288:tid 32288] [client 34.7.138.169:46434] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||michaelward.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "michaelward.com"] [uri "/z9x8c7v6b5-debug-trigger-michaelward.com"] [unique_id "ar0qnRn38l_q6t5IFTrK_gAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack