๐บ๐ธ
TPI-Abuse
2026-08-15 22:34:21
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 34.74.29.27 (27.29.74.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.74.29.27 (27.29.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 15 18:34:14.844268 2026] [security2:error] [pid 1681:tid 1681] [client 34.74.29.27:38906] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||classic.iconbizpromo.com|F|2"] [data ".iconbizpromo.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "classic.iconbizpromo.com"] [uri "/z9x8c7v6b5-debug-trigger-classic.iconbizpromo.com"] [unique_id "aoDpZiqr7VrVCqXSS5qafAAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Nightreaver
2026-08-15 21:34:05
(1 week ago)
34.74.29.27 - - [15/Aug/2026:23:34:05 0200] "GET /auth/login HTTP/1.1" 404 5773 "-" "Mozilla/5.0 (W ...
show more
34.74.29.27 - - [15/Aug/2026:23:34:05 0200] "GET /auth/login HTTP/1.1" 404 5773 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36 Edg/152.0.0.0"
34.74.29.27 - - [15/Aug/2026:23:34:05 0200] "GET /firebase-config.json HTTP/1.1" 404 5773 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; Claude-SearchBot/1.0; mailto:[email protected] "
34.74.29.27 - - [15/Aug/2026:23:34:05 0200] "GET /wp-json HTTP/1.1" 404 5773 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; Claude-SearchBot/1.0; mailto:[email protected] "
34.74.29.27 - - [15/Aug/2026:23:34:05 0200] "GET /login HTTP/1.1" 404 5773 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36 Edg/152.0.0.0"
34.74.29.27 - - [15/Aug/2026:23:34:05 0200] "GET /assets/manifest.json HTTP/1.1" 404 5773 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome[...]
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2026-08-15 21:08:54
(1 week ago)
(modsecurity) srv101 ModSecurity 34.74.29.27 (US/United States/27.29.74.34.bc.googleusercontent.com) ...
show more
(modsecurity) srv101 ModSecurity 34.74.29.27 (US/United States/27.29.74.34.bc.googleusercontent.com): 30 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-15 19:58:15
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.74.29.27 (27.29.74.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.74.29.27 (27.29.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 15 15:58:10.127501 2026] [security2:error] [pid 1649:tid 1649] [client 34.74.29.27:55418] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "live.lexie.org"] [uri "/config/.env"] [unique_id "aoDE0n2dlZUwAhC7sOVt6AAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-15 18:22:45
(1 week ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐ซ๐ท
Octopuce
2026-08-15 17:43:16
(1 week ago)
Aggressive web search of vulnerable pages: /api/.env /.env /config/.env /backend/.env /admin/.env . ...
show more
Aggressive web search of vulnerable pages: /api/.env /.env /config/.env /backend/.env /admin/.env ...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-15 17:21:57
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.74.29.27 (27.29.74.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.74.29.27 (27.29.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 15 13:21:52.680818 2026] [security2:error] [pid 19217:tid 19217] [client 34.74.29.27:41968] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "legacy.unwaved.com"] [uri "/.htpasswd"] [unique_id "aoCgMLPYXRpBfxtLlBJpLAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Hazzard
2026-08-15 17:19:56
(1 week ago)
(PERMBLOCK) 34.74.29.27 (US/United States/South Carolina/North Charleston/27.29.74.34.bc.googleuserc ...
show more
(PERMBLOCK) 34.74.29.27 (US/United States/South Carolina/North Charleston/27.29.74.34.bc.googleusercontent.com/[redacted]) has had more than 4 temp blocks
show less
Hacking
๐ต๐ฑ
wHosts
2026-08-15 16:48:22
(1 week ago)
Blocked by Fail2Ban
Web App Attack
๐ฉ๐ช
Hazzard
2026-08-15 16:27:38
(1 week ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
๐ฌ๐ง
Aetherweb Ark
2026-08-15 16:25:20
(1 week ago)
(mod_security) mod_security (id:949110) triggered by 34.74.29.27 (US/United States/27.29.74.34.bc.go ...
show more
(mod_security) mod_security (id:949110) triggered by 34.74.29.27 (US/United States/27.29.74.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
Anonymous
2026-08-15 16:05:13
(1 week ago)
WAF repeated trigger detected by Fail2Ban
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-08-15 15:57:30
(1 week ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ฉ๐ช
Marc
2026-08-15 15:57:26
(1 week ago)
34.74.29.27 - - [15/Aug/2026:17:57:26 +0200] "GET /wp-json HTTP/2.0" 404 269 "-" "Mozilla/5.0 AppleW ...
show more
34.74.29.27 - - [15/Aug/2026:17:57:26 +0200] "GET /wp-json HTTP/2.0" 404 269 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ClaudeBot/1.0; +mailto:[email protected] " 34.74.29.27 - - [15/Aug/2026:17:57:26 +0200] "GET /.git/config HTTP/2.0" 404 269 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ClaudeBot/1.0; +mailto:[email protected] " 34.74.29.27 - - [15/Aug/2026:17:57:26 +0200] "GET /.git/HEAD HTTP/2.0" 404 269 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ClaudeBot/1.0; +mailto:[email protected] "
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-15 15:50:51
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 34.74.29.27 (27.29.74.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.74.29.27 (27.29.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 15 11:50:45.304287 2026] [security2:error] [pid 20902:tid 20902] [client 34.74.29.27:35070] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||prod.philipma.com|F|2"] [data ".philipma.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "prod.philipma.com"] [uri "/z9x8c7v6b5-debug-trigger-prod.philipma.com"] [unique_id "aoCK1UOEyn3WDmL2xcF7GwAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack