๐ฟ๐ฆ
conure.sh
2026-09-30 12:16:30
(2 days ago)
csagent: score 19.9: secrets grab x2; 1 domain(s) in 8s
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 04:34:09
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.78.240.155 (155.240.78.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.78.240.155 (155.240.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 00:34:04.193364 2026] [security2:error] [pid 21123:tid 21123] [client 34.78.240.155:41364] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wmodradio.com"] [uri "/userfiles"] [unique_id "aryRPOzgc--U3wmgYvgzYQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 03:26:38
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.78.240.155 (155.240.78.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.78.240.155 (155.240.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 23:26:34.736322 2026] [security2:error] [pid 30520:tid 30520] [client 34.78.240.155:50024] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.z-mgmt.com"] [uri "/static/../../../a/../../../../.env"] [unique_id "aryBavvs-zTWLR0aUoCpRQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
clapper
2026-09-30 03:25:43
(3 days ago)
(mod_security) mod_security (id:980001) triggered by 34.78.240.155 (BE/Belgium/155.240.78.34.bc.goog ...
show more
(mod_security) mod_security (id:980001) triggered by 34.78.240.155 (BE/Belgium/155.240.78.34.bc.googleusercontent.com): 5 in the last 3600 secs; ID: Clar
show less
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-30 03:09:48
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.78.240.155 (155.240.78.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.78.240.155 (155.240.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 23:09:44.757539 2026] [security2:error] [pid 16435:tid 16435] [client 34.78.240.155:51060] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.zunosaki.com"] [uri "/userfiles/x"] [unique_id "arx9eOaspFVimdg1EA-YiQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 02:43:04
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.78.240.155 (155.240.78.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.78.240.155 (155.240.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 22:42:58.388447 2026] [security2:error] [pid 22721:tid 22721] [client 34.78.240.155:53670] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.zoesaadeh.com"] [uri "/config/.env"] [unique_id "arx3MlgdO37oZiFNgiPFawAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 02:10:35
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.78.240.155 (155.240.78.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.78.240.155 (155.240.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 22:10:27.347734 2026] [security2:error] [pid 26112:tid 26112] [client 34.78.240.155:43742] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.yakski.com"] [uri "/wp-config.php~"] [unique_id "arxvk9CbWRWvFEplrvMF0gAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Aetherweb Ark
2026-09-30 01:30:49
(3 days ago)
(mod_security) mod_security (id:949110) triggered by 34.78.240.155 (BE/Belgium/155.240.78.34.bc.goog ...
show more
(mod_security) mod_security (id:949110) triggered by 34.78.240.155 (BE/Belgium/155.240.78.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 01:01:08
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 34.78.240.155 (155.240.78.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.78.240.155 (155.240.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 21:01:01.344624 2026] [security2:error] [pid 23439:tid 23439] [client 34.78.240.155:35170] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||wildpete.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "wildpete.com"] [uri "/z9x8c7v6b5-debug-trigger-wildpete.com"] [unique_id "arxfTYhqFhTbpYgwmg90rQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 00:29:28
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.78.240.155 (155.240.78.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.78.240.155 (155.240.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 20:29:20.885023 2026] [security2:error] [pid 27675:tid 27675] [client 34.78.240.155:38928] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/Web.config" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.xcengineering.xyz"] [uri "/web.config"] [unique_id "arxX4N0m_f7B6c2EhYdVogAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 23:38:44
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 34.78.240.155 (155.240.78.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.78.240.155 (155.240.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 19:38:37.451564 2026] [security2:error] [pid 14082:tid 14082] [client 34.78.240.155:33014] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||yongmeihu.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "yongmeihu.com"] [uri "/z9x8c7v6b5-debug-trigger-yongmeihu.com"] [unique_id "arxL_Zn6-6Xu2DJ5YugCVAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 23:15:09
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.78.240.155 (155.240.78.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.78.240.155 (155.240.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 19:15:06.151703 2026] [security2:error] [pid 29168:tid 29168] [client 34.78.240.155:39916] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.whipchecks.com.au"] [uri "/userfiles"] [unique_id "arxGeieyPmMCODOKReJzVgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 22:54:23
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.78.240.155 (155.240.78.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.78.240.155 (155.240.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 18:54:16.149003 2026] [security2:error] [pid 3861:tid 3861] [client 34.78.240.155:38226] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.xtrl.com"] [uri "/.git/config"] [unique_id "arxBmEFi6-0vzWHMu2-ZngAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 22:33:03
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.78.240.155 (155.240.78.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.78.240.155 (155.240.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 18:32:55.420201 2026] [security2:error] [pid 15245:tid 15245] [client 34.78.240.155:34796] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.writebetweenthelines.com"] [uri "/.next/.env"] [unique_id "arw8l3c0awiONQLGhSQW3QAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-29 22:29:31
(3 days ago)
Excessive multi-domain requests
Brute-Force