🇬🇧
consul.to
2026-09-15 18:57:37
(7 minutes ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-09-15 18:19:37
(45 minutes ago)
(mod_security) mod_security (id:210730) triggered by 34.73.125.2 (2.125.73.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.73.125.2 (2.125.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 14:19:30.888195 2026] [security2:error] [pid 22647:tid 22647] [client 34.73.125.2:41920] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||mtalame.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mtalame.com"] [uri "/z9x8c7v6b5-debug-trigger-mtalame.com"] [unique_id "aqmMMixrwMU6_0pYp5bidwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-15 17:56:00
(1 hour ago)
34.73.125.2 - - [15/Sep/2026:19:55:59 +0200] "GET /.git-credentials HTTP/2.0" 301 169 "-" "CCBot/2.0 ...
show more
34.73.125.2 - - [15/Sep/2026:19:55:59 +0200] "GET /.git-credentials HTTP/2.0" 301 169 "-" "CCBot/2.0 (https:///faq/)"
show less
Bad Web Bot
Anonymous
2026-09-15 17:55:20
(1 hour ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-15 16:27:26
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.73.125.2 (2.125.73.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.73.125.2 (2.125.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 12:27:19.526280 2026] [security2:error] [pid 12481:tid 12481] [client 34.73.125.2:35756] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mrsreclamation.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mrsreclamation.com"] [uri "/z9x8c7v6b5-debug-trigger-mrsreclamation.com"] [unique_id "aqlx53wmQ9ICcMH9lw6YfgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-09-15 16:05:54
(2 hours ago)
Too many Status 40X (11)
Brute-Force
Web App Attack
🇳🇱
debestelapp
2026-09-15 16:05:12
(2 hours ago)
Web App Attack
🇺🇸
TPI-Abuse
2026-09-15 16:00:43
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.73.125.2 (2.125.73.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.73.125.2 (2.125.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 12:00:27.104187 2026] [security2:error] [pid 5570:tid 5570] [client 34.73.125.2:56220] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mroxygen.org|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mroxygen.org"] [uri "/rclone.conf"] [unique_id "aqlrm7xyqJpyoCoyyg80IQAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇮
oh.mg
2026-09-15 15:50:58
(3 hours ago)
34.73.125.2 - - [15/Sep/2026:17:50:52 +0200] "GET /.well-known/jwks.json HTTP/1.1" 403 498 "-" "Mozi ...
show more
34.73.125.2 - - [15/Sep/2026:17:50:52 +0200] "GET /.well-known/jwks.json HTTP/1.1" 403 498 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
34.73.125.2 - - [15/Sep/2026:17:50:53 +0200] "GET /environment.js HTTP/1.1" 403 498 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; OAI-SearchBot/1.0; +https://openai.com/searchbot)"
34.73.125.2 - - [15/Sep/2026:17:50:56 +0200] "GET /localhost.key HTTP/1.1" 403 498 "-" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)"
34.73.125.2 - - [15/Sep/2026:17:50:56 +0200] "GET /sw.js HTTP/1.1" 403 498 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; OAI-SearchBot/1.0; +https://openai.com/searchbot)"
34.73.125.2 - - [15/Sep/2026:17:50:58 +0200] "GET /runtime.js HTTP/1.1" 403 498 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
...
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-15 15:30:34
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.73.125.2 (2.125.73.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.73.125.2 (2.125.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 11:30:28.740971 2026] [security2:error] [pid 19555:tid 19555] [client 34.73.125.2:33388] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mrgutierrezshow.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mrgutierrezshow.com"] [uri "/z9x8c7v6b5-debug-trigger-mrgutierrezshow.com"] [unique_id "aqlklCfxJ5wKmeWDgY85JQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-15 14:53:46
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.73.125.2 (2.125.73.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.73.125.2 (2.125.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 10:53:39.459596 2026] [security2:error] [pid 31390:tid 31390] [client 34.73.125.2:54510] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mrappliancefl.com"] [uri "/@fs/.env"] [unique_id "aqlb83vtrp4Kzb7Bm_sPiwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-15 14:42:48
(4 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/grafana-cve-2021-43798
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-15 14:18:57
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.73.125.2 (2.125.73.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.73.125.2 (2.125.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 10:18:54.395931 2026] [security2:error] [pid 26661:tid 26661] [client 34.73.125.2:49992] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mprise.com"] [uri "/appearance/../../.env"] [unique_id "aqlTzllVZr9uPs2i4xbk2gAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇦
Mediashaker
2026-09-15 14:17:43
(4 hours ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 34.73.125.2 (US/Unit ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 34.73.125.2 (US/United States/2.125.73.34.bc.googleusercontent.com)
show less
Bad Web Bot
Anonymous
2026-09-15 14:06:25
(4 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking