๐บ๐ธ
TPI-Abuse
2026-09-22 10:07:18
(7 minutes ago)
(mod_security) mod_security (id:210730) triggered by 34.80.231.89 (89.231.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.80.231.89 (89.231.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 06:07:12.814178 2026] [security2:error] [pid 1388:tid 1388] [client 34.80.231.89:56054] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||solidthought.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "solidthought.com"] [uri "/z9x8c7v6b5-debug-trigger-solidthought.com"] [unique_id "arJTUL7iV9jgOr_2VfO5nwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-22 10:00:01
(14 minutes ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 09:19:39
(54 minutes ago)
(mod_security) mod_security (id:210730) triggered by 34.80.231.89 (89.231.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.80.231.89 (89.231.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 05:19:35.197081 2026] [security2:error] [pid 16287:tid 16287] [client 34.80.231.89:51336] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||stananddana.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "stananddana.com"] [uri "/z9x8c7v6b5-debug-trigger-stananddana.com"] [unique_id "arJIJzH-6GXqVMYNdvP-tQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐พ
Rizzy
2026-09-22 09:18:40
(55 minutes ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 08:58:28
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 34.80.231.89 (89.231.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.80.231.89 (89.231.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 04:58:24.698034 2026] [security2:error] [pid 18922:tid 18922] [client 34.80.231.89:35480] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||stthomastrainer.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "stthomastrainer.com"] [uri "/z9x8c7v6b5-debug-trigger-stthomastrainer.com"] [unique_id "arJDMGgfZ7rHH13qicMTAwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 08:43:17
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 34.80.231.89 (89.231.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.80.231.89 (89.231.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 04:43:12.737389 2026] [security2:error] [pid 32091:tid 32091] [client 34.80.231.89:41758] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||superzilla.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "superzilla.com"] [uri "/z9x8c7v6b5-debug-trigger-superzilla.com"] [unique_id "arI_oKDk00Xo930zeKqDSAAAADk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-22 08:30:42
(1 hour ago)
Excessive 404/403 errors
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-22 08:27:16
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 34.80.231.89 (89.231.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.80.231.89 (89.231.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 04:27:10.956076 2026] [security2:error] [pid 29027:tid 29027] [client 34.80.231.89:45136] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||taacorp.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "taacorp.com"] [uri "/z9x8c7v6b5-debug-trigger-taacorp.com"] [unique_id "arI73gehiwX57e4ZHSm55wAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 08:11:44
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.80.231.89 (89.231.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.80.231.89 (89.231.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 04:11:36.939175 2026] [security2:error] [pid 15799:tid 15799] [client 34.80.231.89:49668] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||tausiet.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "tausiet.com"] [uri "/z9x8c7v6b5-debug-trigger-tausiet.com"] [unique_id "arI4OGkz2BFfZPbvWJgD5gAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 07:54:30
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.80.231.89 (89.231.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.80.231.89 (89.231.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 03:54:24.814127 2026] [security2:error] [pid 13779:tid 13779] [client 34.80.231.89:58010] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||teenybikini.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "teenybikini.com"] [uri "/z9x8c7v6b5-debug-trigger-teenybikini.com"] [unique_id "arI0MIlVDIm_tOe37fNCyAAAAHY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
robotstxt
2026-09-22 07:46:42
(2 hours ago)
34.80.231.89 - - [22/Sep/2026:07:46:34 +0000] "GET /project/.env HTTP/2.0" 403 16019 "-" "Mozilla/5. ...
show more
34.80.231.89 - - [22/Sep/2026:07:46:34 +0000] "GET /project/.env HTTP/2.0" 403 16019 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)"
34.80.231.89 - - [22/Sep/2026:07:46:34 +0000] "GET /agent/.env HTTP/2.0" 403 16021 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)"
34.80.231.89 - - [22/Sep/2026:07:46:34 +0000] "GET /workspace/.env HTTP/2.0" 403 16024 "-" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)"
34.80.231.89 - - [22/Sep/2026:07:46:34 +0000] "GET /.env.local HTTP/2.0" 403 16023 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.4; +https://openai.com/gptbot"
34.80.231.89 - - [22/Sep/2026:07:46:34 +0000] "GET /api/v1/.env HTTP/2.0" 403 16020 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 07:39:09
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.80.231.89 (89.231.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.80.231.89 (89.231.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 03:39:01.009412 2026] [security2:error] [pid 20789:tid 20789] [client 34.80.231.89:45766] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||tersch.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "tersch.com"] [uri "/z9x8c7v6b5-debug-trigger-tersch.com"] [unique_id "arIwlWRGoJwfWVMHWbnUYgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 07:21:13
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.80.231.89 (89.231.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.80.231.89 (89.231.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 03:21:05.878406 2026] [security2:error] [pid 10313:tid 10313] [client 34.80.231.89:57844] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||thebeesgold.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "thebeesgold.com"] [uri "/z9x8c7v6b5-debug-trigger-thebeesgold.com"] [unique_id "arIsYSO6Mjc6U8UOMQubvAAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-09-22 07:05:09
(3 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 07:04:20
(3 hours ago)
(mod_security) mod_security (id:243320) triggered by 34.80.231.89 (89.231.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:243320) triggered by 34.80.231.89 (89.231.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 03:04:13.678407 2026] [security2:error] [pid 28500:tid 28500] [client 34.80.231.89:57092] ModSecurity: Access denied with code 403 (phase 2). String match "/.profile" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6621"] [id "243320"] [rev "1"] [msg "COMODO WAF: Information disclosure vulnerability in Cloud Foundry PHP Buildpack (aka php-buildpack) before 4.3.18 and PHP Buildpack Cf-release before 242, as used in Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.6.38 and 1.7.x before 1.7.19 and other products (CVE-2016-6639)||theeternalperspective.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "theeternalperspective.com"] [uri "/.profile"] [unique_id "arIobdSg4lHJTTp0UlGPcAAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack