๐บ๐ธ
TPI-Abuse
2026-09-30 15:22:41
(30 minutes ago)
(mod_security) mod_security (id:210730) triggered by 34.75.62.76 (76.62.75.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.75.62.76 (76.62.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 11:22:37.011806 2026] [security2:error] [pid 31132:tid 31132] [client 34.75.62.76:47376] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||client.jamesallenwalker.com|F|2"] [data ".jamesallenwalker.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "client.jamesallenwalker.com"] [uri "/z9x8c7v6b5-debug-trigger-client.jamesallenwalker.com"] [unique_id "ar0pPYrJQneg5SiFR3NaUAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
robotstxt
2026-09-30 14:20:47
(1 hour ago)
34.75.62.76 - - [30/Sep/2026:14:20:44 +0000] "GET /%2e%2e/.env HTTP/1.1" 400 193 "-" "-" "-" edge="3 ...
show more
34.75.62.76 - - [30/Sep/2026:14:20:44 +0000] "GET /%2e%2e/.env HTTP/1.1" 400 193 "-" "-" "-" edge="34.75.62.76"
34.75.62.76 - - [30/Sep/2026:14:20:44 +0000] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2fproc/self/environ HTTP/1.1" 400 193 "-" "-" "-" edge="34.75.62.76"
34.75.62.76 - - [30/Sep/2026:14:20:44 +0000] "GET /..%2f..%2f.env HTTP/1.1" 400 193 "-" "-" "-" edge="34.75.62.76"
34.75.62.76 - - [30/Sep/2026:14:20:44 +0000] "GET /%2E%2E/%2E%2E/%2E%2E/%2E%2E/proc/self/environ HTTP/1.1" 400 193 "-" "-" "-" edge="34.75.62.76"
34.75.62.76 - - [30/Sep/2026:14:20:45 +0000] "GET /api/attachments/img/avatar/..%2F..%2F..%2F..%2F..%2Fproc%2Fself%2Fenviron HTTP/1.1" 400 193 "-" "-" "-" edge="34.75.62.76"
...
show less
Web Spam
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 13:54:59
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 34.75.62.76 (76.62.75.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.75.62.76 (76.62.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 09:54:52.021028 2026] [security2:error] [pid 28595:tid 28595] [client 34.75.62.76:57870] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||curryfirm.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "curryfirm.com"] [uri "/z9x8c7v6b5-debug-trigger-curryfirm.com"] [unique_id "ar0UrO2RBkLqpUIjBvKPCgAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-30 13:52:55
(2 hours ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
๐ฌ๐ง
Swiptly
2026-09-30 12:50:23
(3 hours ago)
Bot scanning for environment files .env .env/\*
...
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 12:11:14
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.75.62.76 (76.62.75.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.75.62.76 (76.62.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 08:11:10.883135 2026] [security2:error] [pid 6207:tid 6207] [client 34.75.62.76:59314] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||cvtheory.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "cvtheory.com"] [uri "/z9x8c7v6b5-debug-trigger-cvtheory.com"] [unique_id "arz8XgAhJRaUKftJB5T8SAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-30 11:36:26
(4 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 10:32:39
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.75.62.76 (76.62.75.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.75.62.76 (76.62.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 06:32:34.849118 2026] [security2:error] [pid 26518:tid 26518] [client 34.75.62.76:50272] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.cuetzpalin.com"] [uri "/.htpasswd"] [unique_id "arzlQnfvNHuH7NX3EGRbAwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-30 10:26:32
(5 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
๐ฉ๐ช
updown.io
2026-09-30 10:25:57
(5 hours ago)
{"level":"info","ts":1790763954.9588296,"logger":"http.log.access.log1","msg":"handled request","req ...
show more
{"level":"info","ts":1790763954.9588296,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.75.62.76","remote_port":"45554","client_ip":"34.75.62.76","proto":"HTTP/2.0","method":"GET","host":"d2jsp-status.own3r.com","uri":"/userfiles?path=../../.env","headers":{"X-Nextjs-Data":["1"],"User-Agent":["Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)"],"Accept-Encoding":["gzip"],"Accept":["*/*"],"Cookie":["REDACTED"],"X-Middleware-Subrequest":["src/middleware:nowaf:src/middleware:src/middleware:src/middleware:src/middleware:middleware:middleware:nowaf:middleware:middleware:middleware:pages/_middleware"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"h2","server_name":"d2jsp-status.own3r.com","ech":false}},"bytes_read":0,"user_id":"","duration":0.000192698,"size":0,"status":429,"resp_headers":{"Server":["Caddy"],"Alt-Svc":["h3=\":443\"; ma=2592000"],"Retry-After":["1"]}}
{"lev
...
show less
DDoS Attack
Web App Attack
๐บ๐ธ
NXTwoThou
2026-09-30 10:15:10
(5 hours ago)
/.env%3Fraw
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 10:03:16
(5 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.75.62.76 (76.62.75.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.75.62.76 (76.62.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 06:03:09.861100 2026] [security2:error] [pid 12595:tid 12595] [client 34.75.62.76:49374] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||old.kemela.com|F|2"] [data ".kemela.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "old.kemela.com"] [uri "/z9x8c7v6b5-debug-trigger-old.kemela.com"] [unique_id "arzeXd-SVNNXDaL5I3G31AAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-30 09:48:44
(6 hours ago)
Multiple WAF Violations
Web App Attack
๐ง๐ช
madeit
2026-09-30 09:43:42
(6 hours ago)
Web App Attack
๐ฌ๐ง
wiredalter
2026-09-30 09:08:57
(6 hours ago)
Blocked by fail2ban on gVPS [8443/tcp]
Source Port: 57958
TTL: 57
Packet Length: 60
TOS: 0x00
Analy ...
show more
Blocked by fail2ban on gVPS [8443/tcp]
Source Port: 57958
TTL: 57
Packet Length: 60
TOS: 0x00
Analyzed by https://ip.wiredalter.com
show less
Brute-Force
SSH