🇫🇷
dynamix
2026-09-13 00:08:34
(6 minutes ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 23:30:24
(44 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.80.2.198 (198.2.80.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.2.198 (198.2.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 19:30:20.834939 2026] [security2:error] [pid 1632:tid 1632] [client 34.80.2.198:35916] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mysteriesrevealed.click"] [uri "/@fs/.env"] [unique_id "aqXgjDjtt8_14eMcfwgvXwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
Celtic
2026-09-12 23:26:16
(48 minutes ago)
Blocked by Fail2Ban with Jail (plesk-modsecurity)
Brute-Force
SSH
Anonymous
2026-09-12 23:25:43
(49 minutes ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-12 22:45:21
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.80.2.198 (198.2.80.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.2.198 (198.2.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 18:45:13.551847 2026] [security2:error] [pid 21201:tid 21201] [client 34.80.2.198:47774] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "myriadpubs.com"] [uri "/@fs/.env"] [unique_id "aqXV-TgsdUmN476yow9CFQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 22:02:11
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.80.2.198 (198.2.80.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.2.198 (198.2.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 18:02:07.386695 2026] [security2:error] [pid 11231:tid 11231] [client 34.80.2.198:37484] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "myomni.us"] [uri "/img../.env"] [unique_id "aqXL38DmNfd13I_XA2pKPAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
voormedia
2026-09-12 22:02:08
(2 hours ago)
Accessed trap at '/.npmrc'
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 21:43:52
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.80.2.198 (198.2.80.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.2.198 (198.2.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 17:43:45.944028 2026] [security2:error] [pid 11404:tid 11404] [client 34.80.2.198:34166] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mymuscles.com"] [uri "/@fs/proc/self/cwd/.env"] [unique_id "aqXHkajOCI5UXYOevvMeLwAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
Mendip_Defender
2026-09-12 21:12:57
(3 hours ago)
34.80.2.198 - - [12/Sep/2026:22:13:09 +0100] "GET /users/login HTTP/1.1" 404 6355 "-" "Mozilla/5.0 ( ...
show more
34.80.2.198 - - [12/Sep/2026:22:13:09 +0100] "GET /users/login HTTP/1.1" 404 6355 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36"
34.80.2.198 - - [12/Sep/2026:22:13:09 +0100] "GET /user/login HTTP/1.1" 404 6355 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36"
34.80.2.198 - - [12/Sep/2026:22:13:09 +0100] "GET /admin HTTP/1.1" 404 6355 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36"
...
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 21:06:49
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.80.2.198 (198.2.80.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.80.2.198 (198.2.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 17:06:44.540724 2026] [security2:error] [pid 6694:tid 6694] [client 34.80.2.198:46064] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mylesmitchell.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mylesmitchell.com"] [uri "/z9x8c7v6b5-debug-trigger-mylesmitchell.com"] [unique_id "aqW-5NwqxnStsLVAvlLmFAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Baking333
2026-09-12 21:01:08
(3 hours ago)
[redacted] 34.80.2.198 - - [12/Sep/2026:22:01:06 +0100] "GET /api/uploads/%2e%2e%2f%2e%2e%[redacted] ...
show more
[redacted] 34.80.2.198 - - [12/Sep/2026:22:01:06 +0100] "GET /api/uploads/%2e%2e%2f%2e%2e%[redacted] HTTP/1.1" 404 494 0/117 "-" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://[redacted]/)" [redacted] 34.80.2.198 - - [12/Sep/2026:22:01:06 +0100] "GET /.dockerenv HTTP/1.1" 302 1532 0/72258 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://[redacted]/)"
show less
Bad Web Bot
Web App Attack
🇨🇦
Mediashaker
2026-09-12 20:13:49
(4 hours ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 34.80.2.198 (TW/Taiw ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 34.80.2.198 (TW/Taiwan/198.2.80.34.bc.googleusercontent.com)
show less
Bad Web Bot
🇳🇱
MyGlobalFlowers
2026-09-12 20:09:40
(4 hours ago)
Multiple WAF Violations
Web App Attack
🇩🇪
mygcode.de
2026-09-12 20:05:58
(4 hours ago)
Scanning for Exploits
Bad Web Bot
🇩🇪
todix
2026-09-12 19:49:46
(4 hours ago)
Web App Attack Exploid from 34.80.2.198
Web App Attack