๐ฉ๐ช
Skyrider
2026-09-21 03:20:35
(3 days ago)
crowdsecurity/http-probing
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 02:17:17
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 34.80.110.150 (150.110.80.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.80.110.150 (150.110.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 22:17:13.722574 2026] [security2:error] [pid 23594:tid 23594] [client 34.80.110.150:60016] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||aslproud.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "aslproud.com"] [uri "/z9x8c7v6b5-debug-trigger-aslproud.com"] [unique_id "arCTqdDzcNcOUdCvNEsCVgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
Burayot
2026-09-21 02:04:50
(3 days ago)
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 34.80.110.150 (TW/Taiwan/150.110.80. ...
show more
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 34.80.110.150 (TW/Taiwan/150.110.80.34.bc.googleusercontent.com): 2 in the last 3600 secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 01:34:09
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.80.110.150 (150.110.80.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.110.150 (150.110.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 21:34:05.874577 2026] [security2:error] [pid 14004:tid 14004] [client 34.80.110.150:34640] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "asurprisinglittletown.com"] [uri "/.git/config"] [unique_id "arCJjZnB6au403lDsIWcvAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 00:32:39
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.80.110.150 (150.110.80.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.110.150 (150.110.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 20:32:30.465557 2026] [security2:error] [pid 8154:tid 8154] [client 34.80.110.150:53072] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "asociacionmutualsanjose.com"] [uri "/@fs/app/.env"] [unique_id "arB7Hjy8n8Bxk0Rhb3ifBgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 00:07:10
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.80.110.150 (150.110.80.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.110.150 (150.110.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 20:07:04.776495 2026] [security2:error] [pid 9922:tid 9922] [client 34.80.110.150:37252] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.michaelpmcgrath.com"] [uri "/config/.env"] [unique_id "arB1KIAJ2pueJhKTycJffQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 23:00:31
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 34.80.110.150 (150.110.80.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.80.110.150 (150.110.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 19:00:25.441933 2026] [security2:error] [pid 5973:tid 5973] [client 34.80.110.150:48310] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||auditleverage.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "auditleverage.com"] [uri "/z9x8c7v6b5-debug-trigger-auditleverage.com"] [unique_id "arBliW2yZA6BjdG4sfPTcgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-09-20 21:40:04
(4 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
Anonymous
2026-09-20 21:30:05
(4 days ago)
CrowdSec decision: LePresidente/http-generic-401-bf (origin: crowdsec)
Port Scan
Anonymous
2026-09-20 20:30:05
(4 days ago)
CrowdSec decision: crowdsecurity/http-admin-interface-probing (origin: crowdsec)
Web App Attack
๐ซ๐ท
dynamix
2026-09-20 19:57:58
(4 days ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 19:53:52
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 34.80.110.150 (150.110.80.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.80.110.150 (150.110.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 15:53:44.517786 2026] [security2:error] [pid 29288:tid 29288] [client 34.80.110.150:33324] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.smogsandiego.com|F|2"] [data ".smogsandiego.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.smogsandiego.com"] [uri "/z9x8c7v6b5-debug-trigger-www.smogsandiego.com"] [unique_id "arA5yOV5YzONA6PnoU4IfAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
polycoda
2026-09-20 19:05:58
(4 days ago)
AutoBlock: ๐ก Port Scan (Non Decay-Based)
Port Scan