๐บ๐ธ
TPI-Abuse
2026-10-11 03:30:05
(42 minutes ago)
(mod_security) mod_security (id:210730) triggered by 34.75.13.182 (182.13.75.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.75.13.182 (182.13.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 23:29:58.787300 2026] [security2:error] [pid 2227:tid 2227] [client 34.75.13.182:53642] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||webdryer.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "webdryer.com"] [uri "/z9x8c7v6b5-debug-trigger-webdryer.com"] [unique_id "assCtpHdEnOXdsGY5YMO6wAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ฌ
Cloudkul Cloudkul
2026-10-11 02:24:25
(1 hour ago)
Attempted Brute Force on our application
Brute-Force
Web App Attack
๐บ๐ธ
masterguru
2026-10-11 02:23:14
(1 hour ago)
BAD BOT - Detected and Blocked.. Matched phrase "claudebot" at REQUEST_HEADERS:user-agent. (1100000- ...
show more
BAD BOT - Detected and Blocked.. Matched phrase "claudebot" at REQUEST_HEADERS:user-agent. (1100000-169)
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-11 02:23:10
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 34.75.13.182 (182.13.75.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.75.13.182 (182.13.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 22:23:04.770751 2026] [security2:error] [pid 7442:tid 7442] [client 34.75.13.182:58478] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||vaghyst.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "vaghyst.com"] [uri "/z9x8c7v6b5-debug-trigger-vaghyst.com"] [unique_id "asrzCFy8FwEOzXA0IOkDrwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
iwle
2026-10-11 01:57:01
(2 hours ago)
[Sat Oct 10 21:57:00.168016 2026] [:error] [pid 2678240:tid 2678271] [client 34.75.13.182:0] [client ...
show more
[Sat Oct 10 21:57:00.168016 2026] [:error] [pid 2678240:tid 2678271] [client 34.75.13.182:0] [client 34.75.13.182] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "125"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /core/.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "ufscards.com"] [uri "/core/.env"] [unique_id "asrs7ARmZ3-2-bBFrFUNFAAAAQM"]
[Sat Oct 10 21:57:00.173666 2026] [:error] [pid 1477:tid 1602] [client 34.75.13.182:0] [client 34.75.13.182] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "125"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-11 01:53:22
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.75.13.182 (182.13.75.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.75.13.182 (182.13.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 21:53:18.475502 2026] [security2:error] [pid 27842:tid 27842] [client 34.75.13.182:49780] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||tyllo.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "tyllo.com"] [uri "/z9x8c7v6b5-debug-trigger-tyllo.com"] [unique_id "asrsDqQy8jeU3ssbkJBxugAAADo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
bazter.pro
2026-10-11 01:51:03
(2 hours ago)
Fail2Ban: plesk-bot-aggressive - 15 failures
Port Scan
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-11 01:31:35
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.75.13.182 (182.13.75.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.75.13.182 (182.13.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 21:31:27.641457 2026] [security2:error] [pid 21400:tid 21400] [client 34.75.13.182:36550] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||trigonom.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "trigonom.com"] [uri "/z9x8c7v6b5-debug-trigger-trigonom.com"] [unique_id "asrm721LxSk9NLTshMmQ0wAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
dot.mg
2026-10-11 00:57:02
(3 hours ago)
Bad behaviour
Web Spam
๐ธ๐ฌ
anotherwatcher
2026-10-11 00:40:25
(3 hours ago)
bad bot
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-11 00:18:54
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.75.13.182 (182.13.75.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.75.13.182 (182.13.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 20:18:50.136393 2026] [security2:error] [pid 15078:tid 15078] [client 34.75.13.182:49564] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||thendco.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "thendco.com"] [uri "/z9x8c7v6b5-debug-trigger-thendco.com"] [unique_id "asrV6mvIu-6tG3hERRRjOgAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-10 23:24:31
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.75.13.182 (182.13.75.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.75.13.182 (182.13.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 19:24:23.103110 2026] [security2:error] [pid 26231:tid 26231] [client 34.75.13.182:57098] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||technesa.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "technesa.com"] [uri "/z9x8c7v6b5-debug-trigger-technesa.com"] [unique_id "asrJJ2V8ceGt0jThTKi1TQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-10 23:02:23
(5 hours ago)
High entropy root path probe detected: /5y0tb9lbxhu2u9v17x4o on path: /5y0tb9lbxhu2u9v17x4o
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-10 22:56:39
(5 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.75.13.182 (182.13.75.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.75.13.182 (182.13.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 18:56:32.535257 2026] [security2:error] [pid 2512:tid 2548] [client 34.75.13.182:43806] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||sylvestconsulting.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "sylvestconsulting.com"] [uri "/z9x8c7v6b5-debug-trigger-sylvestconsulting.com"] [unique_id "asrCoAK6ZoFmnuOVand_HgAAAIU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-10 22:33:21
(5 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.75.13.182 (182.13.75.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.75.13.182 (182.13.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 18:33:16.815619 2026] [security2:error] [pid 30950:tid 30950] [client 34.75.13.182:45892] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||summithost.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "summithost.com"] [uri "/z9x8c7v6b5-debug-trigger-summithost.com"] [unique_id "asq9LJ9H2QzP9bu-j9rclgAAADA"]
show less
Brute-Force
Bad Web Bot
Web App Attack