๐จ๐ฆ
polycoda
2026-09-30 21:52:15
(2 days ago)
๐ฅ VERY AGGRESSIVE SCANNER probed over 600 inexistent files and PHP scripts in less than an hour.
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 16:28:21
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.74.60.105 (105.60.74.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.74.60.105 (105.60.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 12:28:15.398954 2026] [security2:error] [pid 2311:tid 2311] [client 34.74.60.105:56956] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.hollyndlaw.com"] [uri "/.git/HEAD"] [unique_id "ar04n8YqSkaq0i9z53xMGgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 16:09:01
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.74.60.105 (105.60.74.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.74.60.105 (105.60.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 12:08:56.510326 2026] [security2:error] [pid 15776:tid 15906] [client 34.74.60.105:55404] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.kcscomputer.com"] [uri "/.htpasswd"] [unique_id "ar00GF9UFye6bEn-OQjRLAAAAgk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐พ
Rizzy
2026-09-30 15:54:11
(3 days ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 15:50:13
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 34.74.60.105 (105.60.74.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.74.60.105 (105.60.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 11:49:56.821564 2026] [security2:error] [pid 9376:tid 9376] [client 34.74.60.105:36742] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.independentmusicconference.com|F|2"] [data ".independentmusicconference.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.independentmusicconference.com"] [uri "/z9x8c7v6b5-debug-trigger-www.independentmusicconference.com"] [unique_id "ar0vpKgLmux7P0wjQ5khyQAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 15:00:23
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 34.74.60.105 (105.60.74.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.74.60.105 (105.60.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 11:00:19.652678 2026] [security2:error] [pid 2384:tid 2412] [client 34.74.60.105:33478] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||getairborne.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "getairborne.com"] [uri "/z9x8c7v6b5-debug-trigger-getairborne.com"] [unique_id "ar0kA34ySs98-d2MmCGj7wAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 14:32:32
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.74.60.105 (105.60.74.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.74.60.105 (105.60.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 10:32:25.998915 2026] [security2:error] [pid 17935:tid 17935] [client 34.74.60.105:46986] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.jkperis.com"] [uri "/.htpasswd"] [unique_id "ar0deXNxFIx8NpqdNi5nHAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 14:11:24
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.74.60.105 (105.60.74.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.74.60.105 (105.60.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 10:11:17.163710 2026] [security2:error] [pid 30913:tid 30913] [client 34.74.60.105:57038] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.ic1surplus.com"] [uri "/build../.env"] [unique_id "ar0YhUKU1b0b2njHZmcdCgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 13:47:16
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 34.74.60.105 (105.60.74.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.74.60.105 (105.60.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 09:47:11.520024 2026] [security2:error] [pid 20086:tid 20086] [client 34.74.60.105:45004] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.hardlucktattoo.com|F|2"] [data ".hardlucktattoo.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.hardlucktattoo.com"] [uri "/z9x8c7v6b5-debug-trigger-www.hardlucktattoo.com"] [unique_id "ar0S35D3pmeTkVks7VjV9AAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 13:19:00
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 34.74.60.105 (105.60.74.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.74.60.105 (105.60.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 09:18:55.822874 2026] [security2:error] [pid 19850:tid 19850] [client 34.74.60.105:56030] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||platform.iconbizpromo.com|F|2"] [data ".iconbizpromo.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "platform.iconbizpromo.com"] [uri "/z9x8c7v6b5-debug-trigger-platform.iconbizpromo.com"] [unique_id "ar0MP0nUdO1lG_nUwMlu9wAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 13:00:38
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.74.60.105 (105.60.74.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.74.60.105 (105.60.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 09:00:15.884101 2026] [security2:error] [pid 15768:tid 15768] [client 34.74.60.105:55644] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.gdg1.com"] [uri "/.env.dev"] [unique_id "ar0H3xvPhcnWeVtX7qefyAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 12:37:04
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.74.60.105 (105.60.74.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.74.60.105 (105.60.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 08:36:58.068471 2026] [security2:error] [pid 24465:tid 24465] [client 34.74.60.105:45604] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.jbernsteinpc.com"] [uri "/.env.js"] [unique_id "ar0CagnG6WxCslZNcFzRmAAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
Zdenฤk Svancar
2026-09-30 12:19:28
(3 days ago)
34.74.60.105 - - [30/Sep/2026:12:19:26 +0000] "GET /actuator HTTP/1.1" 404 118 "-" "Mozilla/5.0 Appl ...
show more
34.74.60.105 - - [30/Sep/2026:12:19:26 +0000] "GET /actuator HTTP/1.1" 404 118 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot"
34.74.60.105 - - [30/Sep/2026:12:19:27 +0000] "GET /test.php HTTP/1.1" 404 118 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)"
...
show less
Port Scan
Bad Web Bot
Web App Attack
๐จ๐ฆ
polycoda
2026-09-30 12:18:25
(3 days ago)
AutoBlock: ๐ก Port Scan (Non Decay-Based) - โ Excessive 40X Errors (Decay-Based) - โช๏ธ Excessive 30X E ...
show more
AutoBlock: ๐ก Port Scan (Non Decay-Based) - โ Excessive 40X Errors (Decay-Based) - โช๏ธ Excessive 30X Errors (Decay-Based)
show less
Port Scan
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-30 12:16:34
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 34.74.60.105 (105.60.74.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.74.60.105 (105.60.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 08:16:25.952783 2026] [security2:error] [pid 26929:tid 26929] [client 34.74.60.105:41896] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||haerringer.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "haerringer.com"] [uri "/z9x8c7v6b5-debug-trigger-haerringer.com"] [unique_id "arz9mYuTs4JaumIDi6KsPAAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack