π©πͺ
zUnlegit
2026-10-05 08:13:05
(24 minutes ago)
Automated web scanner requested sensitive path: /cache/original/../../.env
Web App Attack
π©πͺ
itsolon
2026-10-05 08:06:11
(31 minutes ago)
[05/Oct/2026:10:06:10 +0200] 179118757043.285989 34.79.218.222 49360 217.154.7.177 443
[05/Oct/2026: ...
show more
[05/Oct/2026:10:06:10 +0200] 179118757043.285989 34.79.218.222 49360 217.154.7.177 443
[05/Oct/2026:10:06:10 +0200] 179118757075.623888 34.79.218.222 49374 217.154.7.177 443
[05/Oct/2026:10:06:10 +0200] 179118757016.780428 34.79.218.222 49374 217.154.7.177 443
[05/Oct/2026:10:06:10 +0200] 17911875700.517076 34.79.218.222 49374 217.154.7.177 443
[05/Oct/2026:10:06:10 +0200] 179118757088.150816 34.79.218.222 49374 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
π¬π§
consul.to
2026-10-05 07:57:36
(39 minutes ago)
Web attack/malicious scanning detected
Web App Attack
Anonymous
2026-10-05 07:40:02
(57 minutes ago)
suspicious request in access.log
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-05 06:46:09
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.79.218.222 (222.218.79.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.79.218.222 (222.218.79.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 02:46:06.251643 2026] [security2:error] [pid 6293:tid 6355] [client 34.79.218.222:45326] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "btoelsalvador.com"] [uri "/.htpasswd"] [unique_id "asNHrjPrEyokjB_rH3DNoQAAAcI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Roderic
2026-10-05 06:21:34
(2 hours ago)
(apache-scanners) Failed apache-scanners trigger with match [redacted])
Port Scan
πΊπΈ
TPI-Abuse
2026-10-05 06:08:47
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.79.218.222 (222.218.79.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.79.218.222 (222.218.79.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 02:08:41.728417 2026] [security2:error] [pid 3897204:tid 3897253] [client 34.79.218.222:54970] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||brydansales.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "brydansales.com"] [uri "/z9x8c7v6b5-debug-trigger-brydansales.com"] [unique_id "asM-6dHbT6d53RTGC4WiJQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-05 05:47:02
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.79.218.222 (222.218.79.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.79.218.222 (222.218.79.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 01:46:56.669783 2026] [security2:error] [pid 1114:tid 1114] [client 34.79.218.222:60460] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||brucerohr.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "brucerohr.com"] [uri "/z9x8c7v6b5-debug-trigger-brucerohr.com"] [unique_id "asM50IXL6tMxu3j2LSrUZQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π―π΅
bokumin.org
2026-10-05 05:43:32
(2 hours ago)
[id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [uri "/"] [id "949110"] [msg " ...
show more
[id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [uri "/"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"]
show less
Web App Attack
π«π·
masterguru
2026-10-05 05:25:56
(3 hours ago)
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .backup/ ...
show more
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .compositefont/ .config/ .conf/ .crt/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dist/ .dll/ .dos/ .dpkg-dist/ .drv/ .gadget/ .hta/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .inf/ .ini/ .jse/ .key/ .licx/ .lnk/ .log/ .mdb/ .msc/ .ocx/ .old/ .pass/ .pdb/ .pfx/ .pif/ .pem/ .pol/ .prf/ .printer/ .pwd/ .rdb/ .rdp/ .reg/ .resources/ .resx/ .scr/ .sct/ .shs/ .sql/ .swp/ .sys/ .tlb/ .tmp/ .url/ .vb/ .vbe/ .vbs/ .vbproj/ .vsdisco/ .vxd/ .webinfo/ .ws/ .wsc/ .wsf/ .wsh/ .xsd/ .xsx/" at TX:extension. (920440-196)
show less
Hacking
πΊπΈ
TPI-Abuse
2026-10-05 05:17:15
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.79.218.222 (222.218.79.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.79.218.222 (222.218.79.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 01:17:05.680354 2026] [security2:error] [pid 7084:tid 7084] [client 34.79.218.222:39946] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||brookspowell.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "brookspowell.com"] [uri "/z9x8c7v6b5-debug-trigger-brookspowell.com"] [unique_id "asMy0duGlSOMOMC5Y2doywAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-05 04:32:38
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.79.218.222 (222.218.79.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.79.218.222 (222.218.79.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 00:32:30.983788 2026] [security2:error] [pid 29804:tid 29804] [client 34.79.218.222:48664] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||brodyworks.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "brodyworks.com"] [uri "/z9x8c7v6b5-debug-trigger-brodyworks.com"] [unique_id "asMoXhPssqXFqOcMbwCjJgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
LRob
2026-10-05 04:21:54
(4 hours ago)
Crawler ignoring refusals | ua: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; Chat ...
show more
Crawler ignoring refusals | ua: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot, Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/), Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html) (+8 more) | path: /static../.env, /assets../.env, /files../.env (+10 more)
show less
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-10-05 04:10:44
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.79.218.222 (222.218.79.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.79.218.222 (222.218.79.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 00:10:37.581787 2026] [security2:error] [pid 32555:tid 32578] [client 34.79.218.222:56270] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||broadmoordermatology.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "broadmoordermatology.com"] [uri "/z9x8c7v6b5-debug-trigger-broadmoordermatology.com"] [unique_id "asMjPWJSbcLSQqunmKjayAAAAVU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
n2nguyenn2nguyen
2026-10-05 03:52:44
(4 hours ago)
Blocked by YFC Security on https://brixzly.com β type: directory_scan_attempts
Web App Attack