๐บ๐ธ
TPI-Abuse
2026-09-21 05:43:02
(26 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.80.5.242 (242.5.80.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.5.242 (242.5.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 01:42:56.627006 2026] [security2:error] [pid 5463:tid 5463] [client 34.80.5.242:45972] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.joseluisperez.com"] [uri "/.env.old"] [unique_id "arDD4IyUFppFKdc8bwFjgAAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 05:11:59
(57 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.80.5.242 (242.5.80.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.5.242 (242.5.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 01:11:53.130579 2026] [security2:error] [pid 13732:tid 13732] [client 34.80.5.242:54532] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "livegoodherbs.com"] [uri "/packages/.env"] [unique_id "arC8mYlrFR72ymoNQVniOQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 04:45:42
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.80.5.242 (242.5.80.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.5.242 (242.5.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 00:45:35.738735 2026] [security2:error] [pid 2213:tid 2213] [client 34.80.5.242:50638] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipostsocialmedia.com"] [uri "/.git/config"] [unique_id "arC2b9JZtqT5v3JyhXontwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 04:25:40
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.80.5.242 (242.5.80.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.5.242 (242.5.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 00:25:33.447755 2026] [security2:error] [pid 15501:tid 15501] [client 34.80.5.242:53204] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.lekacos.com"] [uri "/agents/.env"] [unique_id "arCxvXTXSlJ-XksiRDgRNwAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 04:09:41
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.80.5.242 (242.5.80.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.80.5.242 (242.5.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 00:09:36.461390 2026] [security2:error] [pid 28991:tid 28991] [client 34.80.5.242:45928] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mikethehomehelper.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mikethehomehelper.com"] [uri "/z9x8c7v6b5-debug-trigger-mikethehomehelper.com"] [unique_id "arCuAJScrCq2mv7JW_QVLgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 03:53:09
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.80.5.242 (242.5.80.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.5.242 (242.5.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 23:53:05.762237 2026] [security2:error] [pid 29785:tid 29785] [client 34.80.5.242:59036] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.lonestaredgeworks.com"] [uri "/@fs/src/.env"] [unique_id "arCqIRg23VY9-b3HGI-J6gAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
masterguru
2026-09-21 02:44:26
(3 hours ago)
Inbound Anomaly Score Exceeded (Total Score: 5). Operator GE matched 5 at TX:anomaly_score. (949110- ...
show more
Inbound Anomaly Score Exceeded (Total Score: 5). Operator GE matched 5 at TX:anomaly_score. (949110-122)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-21 02:15:35
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.80.5.242 (242.5.80.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.80.5.242 (242.5.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 22:15:29.223181 2026] [security2:error] [pid 14161:tid 14170] [client 34.80.5.242:53810] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||lasertagandgames.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "lasertagandgames.com"] [uri "/z9x8c7v6b5-debug-trigger-lasertagandgames.com"] [unique_id "arCTQbRCwF4hW-EAs-ZYeAAAAIU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 01:28:47
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.80.5.242 (242.5.80.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.5.242 (242.5.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 21:28:42.193157 2026] [security2:error] [pid 24114:tid 24114] [client 34.80.5.242:51306] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.lamporix.com"] [uri "/.git/HEAD"] [unique_id "arCISgnw4zSMBZy0G3KGXQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 00:55:24
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.80.5.242 (242.5.80.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.5.242 (242.5.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 20:55:20.084898 2026] [security2:error] [pid 2371:tid 2371] [client 34.80.5.242:42328] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.kaplankrew.com"] [uri "/admin/.env"] [unique_id "arCAeClZwO2ibNS6vM-uqAAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 00:37:47
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.80.5.242 (242.5.80.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.5.242 (242.5.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 20:37:43.602565 2026] [security2:error] [pid 27661:tid 27661] [client 34.80.5.242:34802] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.jfordclanrecipes.com"] [uri "/frontend/.env"] [unique_id "arB8V37hjKd9OaMpCGrRkAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-21 00:32:22
(5 hours ago)
Blocked by ModSec and CSF
Port Scan
๐บ๐ธ
TPI-Abuse
2026-09-21 00:16:33
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.80.5.242 (242.5.80.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.5.242 (242.5.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 20:16:27.967808 2026] [security2:error] [pid 16349:tid 16349] [client 34.80.5.242:40856] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.lisalehmann.com"] [uri "/.env.old"] [unique_id "arB3W88vMpmtkIU4p38EXAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
Zdenฤk Svancar
2026-09-20 23:58:34
(6 hours ago)
34.80.5.242 - - [20/Sep/2026:23:58:33 +0000] "GET /packages/.env HTTP/1.1" 404 118 "-" "Mozilla/5.0 ...
show more
34.80.5.242 - - [20/Sep/2026:23:58:33 +0000] "GET /packages/.env HTTP/1.1" 404 118 "-" "Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)"
34.80.5.242 - - [20/Sep/2026:23:58:33 +0000] "GET /src/.env HTTP/1.1" 404 118 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )"
...
show less
Port Scan
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 23:43:16
(6 hours ago)
(mod_security) mod_security (id:243320) triggered by 34.80.5.242 (242.5.80.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:243320) triggered by 34.80.5.242 (242.5.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 19:43:12.437894 2026] [security2:error] [pid 6166:tid 6166] [client 34.80.5.242:33700] ModSecurity: Access denied with code 403 (phase 2). String match "/.profile" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6621"] [id "243320"] [rev "1"] [msg "COMODO WAF: Information disclosure vulnerability in Cloud Foundry PHP Buildpack (aka php-buildpack) before 4.3.18 and PHP Buildpack Cf-release before 242, as used in Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.6.38 and 1.7.x before 1.7.19 and other products (CVE-2016-6639)||lovelybeyondwords.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "lovelybeyondwords.com"] [uri "/.profile"] [unique_id "arBvkMFnVNvnXLDg21qYXQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack