πΊπΈ
TPI-Abuse
2026-09-21 05:14:38
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.80.136.61 (61.136.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.136.61 (61.136.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 01:14:31.377245 2026] [security2:error] [pid 18762:tid 18762] [client 34.80.136.61:46552] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.mwrn.com"] [uri "/backend/.env"] [unique_id "arC9N3WcBkPGfbz1089xCwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 04:59:32
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.80.136.61 (61.136.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.136.61 (61.136.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 00:59:29.288496 2026] [security2:error] [pid 18133:tid 18133] [client 34.80.136.61:38038] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.skyfall-estate.com"] [uri "/admin/.env"] [unique_id "arC5sSJsnDqd3kmusro13QAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 03:48:11
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.80.136.61 (61.136.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.136.61 (61.136.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 23:48:07.843822 2026] [security2:error] [pid 14205:tid 14279] [client 34.80.136.61:47208] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.petsentiments.com"] [uri "/packages/.env"] [unique_id "arCo98rOIQOG4IaldDQPcwAAAY0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΏπ¦
hostsec_za
2026-09-21 03:35:02
(16 hours ago)
cPanel/Webmail Auth Attack. 331 failed logins in 6 hours.
Brute-Force
π²πΎ
Rizzy
2026-09-21 03:32:41
(16 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 03:21:55
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.80.136.61 (61.136.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.136.61 (61.136.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 23:21:51.119401 2026] [security2:error] [pid 5636:tid 5636] [client 34.80.136.61:41680] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.oakleighfarm.com"] [uri "/@fs/../.env"] [unique_id "arCizzIKOz_0CYubdV5jogAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 03:02:56
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.80.136.61 (61.136.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.136.61 (61.136.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 23:02:52.937879 2026] [security2:error] [pid 4960:tid 4960] [client 34.80.136.61:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.southernbroadcast.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "arCeXHz-dPSCRIzBwwfKgAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 02:18:36
(18 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.80.136.61 (61.136.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.80.136.61 (61.136.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 22:18:31.756460 2026] [security2:error] [pid 18777:tid 18777] [client 34.80.136.61:49652] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.rooksfamily.com|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.rooksfamily.com"] [uri "/host.key"] [unique_id "arCT9zP_MQ8hDnCycpVEoAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 02:01:25
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.80.136.61 (61.136.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.136.61 (61.136.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 22:01:18.457119 2026] [security2:error] [pid 18166:tid 18166] [client 34.80.136.61:57384] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.perlcreative.com"] [uri "/@fs/app/.env"] [unique_id "arCP7qVn8OrWz_KmVKW6NgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 01:37:47
(18 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.80.136.61 (61.136.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.80.136.61 (61.136.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 21:37:41.958350 2026] [security2:error] [pid 25868:tid 25868] [client 34.80.136.61:47306] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.northamericantrucking.com|F|2"] [data ".northamericantrucking.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.northamericantrucking.com"] [uri "/z9x8c7v6b5-debug-trigger-mail.northamericantrucking.com"] [unique_id "arCKZWS9-wTubZruP5rBLQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 01:18:55
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.80.136.61 (61.136.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.136.61 (61.136.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 21:18:49.149954 2026] [security2:error] [pid 3581333:tid 3581333] [client 34.80.136.61:55850] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.nathangoldsteinartist.com"] [uri "/packages/.env"] [unique_id "arCF-UzZG8dyBQsmXWcoqgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 00:29:42
(20 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.80.136.61 (61.136.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.80.136.61 (61.136.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 20:29:34.976570 2026] [security2:error] [pid 30862:tid 30862] [client 34.80.136.61:41426] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.rjdyckarchitect.com|F|2"] [data ".rjdyckarchitect.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.rjdyckarchitect.com"] [uri "/z9x8c7v6b5-debug-trigger-autodiscover.rjdyckarchitect.com"] [unique_id "arB6brltS-iBIrIhkSf4pwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
netclix.gr
2026-09-21 00:19:00
(20 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.80.136.61 (TW/Taiwan/61.136.80.34.bc ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.80.136.61 (TW/Taiwan/61.136.80.34.bc.googleusercontent.com): (CF_ENABLE)
show less
SQL Injection
πΊπΈ
TPI-Abuse
2026-09-21 00:03:17
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.80.136.61 (61.136.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.136.61 (61.136.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 20:03:12.392699 2026] [security2:error] [pid 28825:tid 28825] [client 34.80.136.61:49988] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.pr-professional.com"] [uri "/admin/.env"] [unique_id "arB0QGVHLuu6ZlyBAsQMDwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-20 23:46:23
(20 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.80.136.61 (61.136.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.80.136.61 (61.136.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 19:46:16.747433 2026] [security2:error] [pid 5757:tid 5757] [client 34.80.136.61:51750] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.snowfection.com|F|2"] [data ".snowfection.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.snowfection.com"] [uri "/z9x8c7v6b5-debug-trigger-mail.snowfection.com"] [unique_id "arBwSG7gj4TI9jQw8bJeBQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack