πΏπ¦
conure.sh
2026-09-30 18:19:34
(5 hours ago)
csagent: score 20.0: 404 noise floor x40, secrets grab x1; 1 domain(s) in 2s
Web App Attack
π¦πΊ
paulshipley.com.au
2026-09-30 17:26:27
(6 hours ago)
[Thu Oct 01 03:26:26.861473 2026] [security2:error] [pid 378518] [client 34.73.87.54:51224] [client ...
show more
[Thu Oct 01 03:26:26.861473 2026] [security2:error] [pid 378518] [client 34.73.87.54:51224] [client 34.73.87.54] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "dlcarterauthor.com"] [uri "/z9x8c7v6b5-debug-trigger-dlcarterauthor.com"] [unique_id "ar1GQvioD9fTeUsKS58EtAAAAAE"]
...
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-30 16:25:44
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.73.87.54 (54.87.73.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.73.87.54 (54.87.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 12:25:36.796718 2026] [security2:error] [pid 14297:tid 14297] [client 34.73.87.54:35830] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.clustershow.com"] [uri "/static../.env"] [unique_id "ar04AK7YZCxKc_KArGMb5gAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-30 15:52:59
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.73.87.54 (54.87.73.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.73.87.54 (54.87.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 11:52:55.298873 2026] [security2:error] [pid 7563:tid 7563] [client 34.73.87.54:49370] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.bosdkbook.com"] [uri "/cache/original/%2e%2e/%2e%2e/.env"] [unique_id "ar0wV6dNQvkaJHLYvVx_GwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-30 15:30:57
(8 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.73.87.54 (54.87.73.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.73.87.54 (54.87.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 11:30:50.059848 2026] [security2:error] [pid 6603:tid 6603] [client 34.73.87.54:43514] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||constructiondomex.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "constructiondomex.com"] [uri "/z9x8c7v6b5-debug-trigger-constructiondomex.com"] [unique_id "ar0rKvjECcUg2ORlcE5dDgAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-30 15:08:39
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.73.87.54 (54.87.73.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.73.87.54 (54.87.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 11:08:31.922388 2026] [security2:error] [pid 13410:tid 13410] [client 34.73.87.54:41992] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.equityvestor.com"] [uri "/media../.env"] [unique_id "ar0l71M6jFqIapNFoKXTawAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-30 14:47:47
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.73.87.54 (54.87.73.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.73.87.54 (54.87.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 10:47:39.305270 2026] [security2:error] [pid 30251:tid 30251] [client 34.73.87.54:39314] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.compupackinc.com"] [uri "/images../.env"] [unique_id "ar0hC3cK5Tolyb4E6dMevwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-30 14:32:38
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.73.87.54 (54.87.73.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.73.87.54 (54.87.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 10:32:33.077157 2026] [security2:error] [pid 3279:tid 3279] [client 34.73.87.54:59678] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.drwolberg.com"] [uri "/frontend/.env"] [unique_id "ar0dgZNSvkQeCo_oFGSNzAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-30 14:10:07
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.73.87.54 (54.87.73.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.73.87.54 (54.87.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 10:09:57.707162 2026] [security2:error] [pid 15081:tid 15081] [client 34.73.87.54:48204] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.btccasting.com"] [uri "/.htpasswd"] [unique_id "ar0YNUpzK12c4FfaNKvtLQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
dynamix
2026-09-30 13:50:53
(10 hours ago)
Multiple WAF Violations
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-30 13:34:00
(10 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.73.87.54 (54.87.73.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.73.87.54 (54.87.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 09:33:53.525326 2026] [security2:error] [pid 7299:tid 7299] [client 34.73.87.54:42444] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||electric-meat-grinder.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "electric-meat-grinder.com"] [uri "/z9x8c7v6b5-debug-trigger-electric-meat-grinder.com"] [unique_id "ar0PwWBKU4LV2ocJhraRkAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
robotstxt
2026-09-30 13:10:52
(11 hours ago)
34.73.87.54 - - [30/Sep/2026:13:09:45 +0000] "GET /.vite/manifest.json HTTP/2.0" 403 36419 "-" "Mozi ...
show more
34.73.87.54 - - [30/Sep/2026:13:09:45 +0000] "GET /.vite/manifest.json HTTP/2.0" 403 36419 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "34.73.87.54" edge="162.159.106.183"
34.73.87.54 - - [30/Sep/2026:13:09:46 +0000] "GET /.env.js HTTP/2.0" 403 2 "-" "Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)" "34.73.87.54" edge="104.22.148.30"
34.73.87.54 - - [30/Sep/2026:13:09:47 +0000] "GET /.git-credentials HTTP/2.0" 403 2 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)" "34.73.87.54" edge="172.68.70.212"
34.73.87.54 - - [30/Sep/2026:13:09:48 +0000] "GET /.dockerenv HTTP/2.0" 403 2 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )" "34.73.87.54" edge="172.68.70.212"
34.73.87.54 - - [30/Sep/2026:13:09:52 +0000] "GET /.gitlab-ci.yml HTTP/2.0" 403 2 "-" "Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)"
...
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-30 12:59:26
(11 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.73.87.54 (54.87.73.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.73.87.54 (54.87.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 08:59:19.703421 2026] [security2:error] [pid 32275:tid 32275] [client 34.73.87.54:38856] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||erp.diarrheawolves.com|F|2"] [data ".diarrheawolves.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "erp.diarrheawolves.com"] [uri "/z9x8c7v6b5-debug-trigger-erp.diarrheawolves.com"] [unique_id "ar0Hpz52UIE_IgdWC9MEcAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-30 12:09:50
(12 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.73.87.54 (54.87.73.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.73.87.54 (54.87.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 08:09:43.084743 2026] [security2:error] [pid 13693:tid 13693] [client 34.73.87.54:45908] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.davesastro.com|F|2"] [data ".davesastro.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.davesastro.com"] [uri "/z9x8c7v6b5-debug-trigger-www.davesastro.com"] [unique_id "arz8B43QBzv0vVWOLTNL6gAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-30 11:25:05
(12 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.73.87.54 (54.87.73.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.73.87.54 (54.87.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 07:24:56.916394 2026] [security2:error] [pid 15179:tid 15179] [client 34.73.87.54:56094] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||disneylawsuit.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "disneylawsuit.com"] [uri "/z9x8c7v6b5-debug-trigger-disneylawsuit.com"] [unique_id "arzxiKIq7qX2feRHKDgRAQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack