🇺🇸
TPI-Abuse
2026-09-07 00:03:26
(12 minutes ago)
(mod_security) mod_security (id:210730) triggered by 34.78.55.164 (164.55.78.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.78.55.164 (164.55.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 20:03:20.523115 2026] [security2:error] [pid 31091:tid 31091] [client 34.78.55.164:35560] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||willowbrookins.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "willowbrookins.com"] [uri "/z9x8c7v6b5-debug-trigger-willowbrookins.com"] [unique_id "ap3_SGL42K2-iiNFaJrqYAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
ConsulHosting
2026-09-06 23:14:01
(1 hour ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
🇩🇪
sprobst76
2026-09-06 22:37:06
(1 hour ago)
Blocked by Traefik Dashboard. Reason: Auto-blocked: AbuseIPDB: 89% score, 17 reports
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-06 22:30:36
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 34.78.55.164 (164.55.78.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.78.55.164 (164.55.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 18:30:30.502666 2026] [security2:error] [pid 5323:tid 5323] [client 34.78.55.164:36804] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.styxfreeworld.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.styxfreeworld.com"] [uri "/rclone.conf"] [unique_id "ap3phn3AwzbGw0Adz_lXiQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
paissangroup
2026-09-06 22:11:56
(2 hours ago)
Multiple WAF Violations
Web App Attack
🇩🇪
LRob
2026-09-06 22:00:34
(2 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /backend/.env (+3 more) | 2026-09-06 22:00 UTC
show less
Hacking
Web App Attack
Anonymous
2026-09-06 21:26:13
(2 hours ago)
34.78.55.164 - - [06/Sep/2026:23:26:10 +0200] "GET / HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Windows NT ...
show more
34.78.55.164 - - [06/Sep/2026:23:26:10 +0200] "GET / HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36"
34.78.55.164 - - [06/Sep/2026:23:26:11 +0200] "GET /rclone.conf HTTP/1.1" 403 124 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )"
34.78.55.164 - - [06/Sep/2026:23:26:11 +0200] "GET /.boto HTTP/1.1" 403 124 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1)"
34.78.55.164 - - [06/Sep/2026:23:26:12 +0200] "GET /reset-password HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36"
34.78.55.164 - - [06/Sep/2026:23:26:12 +0200] "GET /login HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36"
34.78
...
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 20:47:39
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.78.55.164 (164.55.78.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.78.55.164 (164.55.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 16:47:32.113543 2026] [security2:error] [pid 16383:tid 16383] [client 34.78.55.164:42628] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||psicologos-omega.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "psicologos-omega.com"] [uri "/z9x8c7v6b5-debug-trigger-psicologos-omega.com"] [unique_id "ap3RZOQyGOGS0Y_BB6UxeQAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
NewGastroline
2026-09-06 20:30:49
(3 hours ago)
Malicious request blocked by CrowdSec on gastro-prod1.boreus.de
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-06 20:17:12
(3 hours ago)
Multiple WAF Violations
Web App Attack
🇳🇱
debestelapp
2026-09-06 20:15:11
(4 hours ago)
Web App Attack
🇩🇪
gadix
2026-09-06 19:47:47
(4 hours ago)
[06/Sep/2026:21:47:45.498357 +0200] ap3DYaBY728kOPcBAqCkRgAAAFA 34.78.55.164 58868 127.0.0.1 7081
[0 ...
show more
[06/Sep/2026:21:47:45.498357 +0200] ap3DYaBY728kOPcBAqCkRgAAAFA 34.78.55.164 58868 127.0.0.1 7081
[06/Sep/2026:21:47:45.499183 +0200] ap3DYaBY728kOPcBAqCkRwAAAFI 34.78.55.164 58880 127.0.0.1 7081
[06/Sep/2026:21:47:45.502411 +0200] ap3DYaBY728kOPcBAqCkSQAAAEU 34.78.55.164 58870 127.0.0.1 7081
...
show less
Web App Attack
Anonymous
2026-09-06 18:58:30
(5 hours ago)
34.78.55.164 - - [06/Sep/2026:20:58:29 +0200] "GET /.?import&raw HTTP/2.0" 301 169 "-" "Mozilla/5.0 ...
show more
34.78.55.164 - - [06/Sep/2026:20:58:29 +0200] "GET /.?import&raw HTTP/2.0" 301 169 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https:///)"
show less
Web App Attack
🇳🇱
Savvii
2026-09-06 18:18:36
(5 hours ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Blexyel
2026-09-06 17:14:03
(7 hours ago)
34.78.55.164 - - [06/Sep/2026:19:14:03 +0200] "GET /.git/config HTTP/1.1" 404 435 "-" "Mozilla/5.0 ( ...
show more
34.78.55.164 - - [06/Sep/2026:19:14:03 +0200] "GET /.git/config HTTP/1.1" 404 435 "-" "Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)" "share.fomx.gay"
...
show less
Brute-Force
Web App Attack