🇳🇱
Site.eu
2026-09-07 00:11:04
(16 hours ago)
Excessive multi-domain requests
Brute-Force
🇺🇸
TPI-Abuse
2026-09-06 22:57:14
(18 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.78.197.13 (13.197.78.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.78.197.13 (13.197.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 18:57:07.667260 2026] [security2:error] [pid 25325:tid 25325] [client 34.78.197.13:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||goalsnet.net|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "goalsnet.net"] [uri "/rclone.conf"] [unique_id "ap3vwwNqtM7Je7D7u_I2qwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 18:28:25
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.78.197.13 (13.197.78.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.78.197.13 (13.197.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 14:28:18.658266 2026] [security2:error] [pid 1640:tid 1640] [client 34.78.197.13:55880] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fritsknuf.com"] [uri "/.env.local"] [unique_id "ap2wwl861f9FkkT1xjEPnAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 18:00:48
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.78.197.13 (13.197.78.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.78.197.13 (13.197.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 14:00:40.528935 2026] [security2:error] [pid 3665:tid 3665] [client 34.78.197.13:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "earscript.net"] [uri "/api/fs/read"] [unique_id "ap2qSFDdIhD0XZs6HHNqgwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 16:06:03
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
🇺🇸
TPI-Abuse
2026-09-06 15:49:02
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.78.197.13 (13.197.78.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.78.197.13 (13.197.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 11:48:56.593688 2026] [security2:error] [pid 30108:tid 30108] [client 34.78.197.13:51976] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.eventsetcinc.com"] [uri "/%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env"] [unique_id "ap2LaJPTfsbx_rHLdOGovQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇷🇴
clauss
2026-09-06 15:26:40
(1 day ago)
34.78.197.13 - - [06/Sep/2026:18:26:29 +0300] "GET /rclone.conf HTTP/2.0" 403 146 "-" "Mozilla/5.0 ( ...
show more
34.78.197.13 - - [06/Sep/2026:18:26:29 +0300] "GET /rclone.conf HTTP/2.0" 403 146 "-" "Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)"
34.78.197.13 - - [06/Sep/2026:18:26:39 +0300] "GET /storage/logs/laravel.log HTTP/2.0" 403 146 "-" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)"
...
show less
Web App Attack
🇩🇪
bazter.pro
2026-09-06 14:38:32
(1 day ago)
Fail2Ban: plesk-bot-aggressive - 15 failures
Port Scan
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 14:12:22
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.78.197.13 (13.197.78.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.78.197.13 (13.197.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 10:12:18.863370 2026] [security2:error] [pid 14679:tid 14679] [client 34.78.197.13:55232] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||fancycleaners.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "fancycleaners.com"] [uri "/z9x8c7v6b5-debug-trigger-fancycleaners.com"] [unique_id "ap10ws0_4W1aemF2HOYiTAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-06 13:53:30
(1 day ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 13:52:21
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.78.197.13 (13.197.78.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.78.197.13 (13.197.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 09:52:15.577328 2026] [security2:error] [pid 14787:tid 14787] [client 34.78.197.13:45556] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.ccancun.co"] [uri "/assets../.env"] [unique_id "ap1wDwrAvqmb4QMO6arNNQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 13:23:33
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.78.197.13 (13.197.78.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.78.197.13 (13.197.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 09:23:30.213975 2026] [security2:error] [pid 28802:tid 28802] [client 34.78.197.13:55404] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||garthp.com|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "garthp.com"] [uri "/privatekey.key"] [unique_id "ap1pUlpVRFlrauSAZFVVOAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 10:44:35
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.78.197.13 (13.197.78.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.78.197.13 (13.197.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 06:44:29.984133 2026] [security2:error] [pid 25143:tid 25143] [client 34.78.197.13:42872] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||gisresults.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "gisresults.com"] [uri "/z9x8c7v6b5-debug-trigger-gisresults.com"] [unique_id "ap1EDeE7uDp3siHgfhVYCAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-06 10:26:54
(1 day ago)
Excessive 404/403 errors
Brute-Force
🇧🇾
lns.bz
2026-09-06 10:22:56
(1 day ago)
.env scanning [BY]
Web App Attack