π«π·
masterguru
2026-09-24 02:36:18
(8 minutes ago)
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encod ...
show more
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encoding/ /proxy/ /lock-token/ /content-range/ /if/ /x-http-method-override/ /x-http-method/ /x-method-override/ /x-middleware-subrequest/ /expect/" at TX:header_name_920450_x-middleware-subrequest. (920450-201)
show less
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-09-24 02:07:27
(36 minutes ago)
(mod_security) mod_security (id:210730) triggered by 34.73.255.155 (155.255.73.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.73.255.155 (155.255.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 22:07:20.185078 2026] [security2:error] [pid 20940:tid 20940] [client 34.73.255.155:46786] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||drbolen.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "drbolen.com"] [uri "/z9x8c7v6b5-debug-trigger-drbolen.com"] [unique_id "arSF2C4MDqleG2qaY_CdGQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
regishoussin
2026-09-24 01:48:26
(55 minutes ago)
Automated web scanning detected by Wazuh (rule 100241): repeated 400/404 errors from mass probing of ...
show more
Automated web scanning detected by Wazuh (rule 100241): repeated 400/404 errors from mass probing of admin/backdoor paths (e.g. wp-login.php, known CMS shell filenames) on an Apache web server, on 2026-09-24 01:48 UTC.
show less
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-24 01:27:10
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 34.73.255.155 (155.255.73.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.73.255.155 (155.255.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 21:27:03.606016 2026] [security2:error] [pid 30047:tid 30047] [client 34.73.255.155:45352] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||dreamingofatlantis.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "dreamingofatlantis.com"] [uri "/z9x8c7v6b5-debug-trigger-dreamingofatlantis.com"] [unique_id "arR8Z2YYQb0K_neyPQ60eAAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
andypiper
2026-09-24 01:02:08
(1 hour ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
π§πͺ
cmbplf
2026-09-24 00:27:39
(2 hours ago)
5.580 requests from abuseipdb.com blacklisted IP (1yr9mos1d)
Brute-Force
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-09-24 00:12:15
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.73.255.155 (155.255.73.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.73.255.155 (155.255.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 20:12:10.167182 2026] [security2:error] [pid 4653:tid 4673] [client 34.73.255.155:35484] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||driftwoodblue.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "driftwoodblue.com"] [uri "/z9x8c7v6b5-debug-trigger-driftwoodblue.com"] [unique_id "arRq2jUbQETLfbvG5W0eHgAAAE8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-23 23:07:14
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.73.255.155 (155.255.73.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.73.255.155 (155.255.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 19:07:09.957455 2026] [security2:error] [pid 31698:tid 31698] [client 34.73.255.155:45562] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||drlwr.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "drlwr.com"] [uri "/z9x8c7v6b5-debug-trigger-drlwr.com"] [unique_id "arRbnd6iwFHK0nSzxy3TDQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Site.eu
2026-09-23 21:39:20
(5 hours ago)
Excessive multi-domain requests
Brute-Force
πΊπΈ
TPI-Abuse
2026-09-23 21:27:50
(5 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.73.255.155 (155.255.73.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.73.255.155 (155.255.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 17:27:46.753727 2026] [security2:error] [pid 574:tid 574] [client 34.73.255.155:58328] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||drwolberg.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "drwolberg.com"] [uri "/z9x8c7v6b5-debug-trigger-drwolberg.com"] [unique_id "arREUsb-Jvs6NQeSRo952gAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-23 20:52:22
(5 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.73.255.155 (155.255.73.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.73.255.155 (155.255.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 16:52:14.729289 2026] [security2:error] [pid 26555:tid 26555] [client 34.73.255.155:44288] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||dsjostrom.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "dsjostrom.com"] [uri "/z9x8c7v6b5-debug-trigger-dsjostrom.com"] [unique_id "arQ7_tH45VsripuCEvlmIAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-23 20:27:51
(6 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.73.255.155 (155.255.73.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.73.255.155 (155.255.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 16:27:46.430121 2026] [security2:error] [pid 14803:tid 14803] [client 34.73.255.155:46382] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||dtla2028.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "dtla2028.com"] [uri "/z9x8c7v6b5-debug-trigger-dtla2028.com"] [unique_id "arQ2QoHPd6djf4HAPCb46gAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
dtorrer
2026-09-23 20:26:15
(6 hours ago)
General vulnerability scan.
Port Scan
π©πͺ
yvoictra
2026-09-23 20:15:38
(6 hours ago)
Bloqueado automΓ‘ticamente por CrowdSec. Escenario: crowdsecurity/http-probing
Web App Attack
π¬π§
consul.to
2026-09-23 19:57:24
(6 hours ago)
Web attack/malicious scanning detected
Web App Attack