๐บ๐ธ
TPI-Abuse
2026-09-20 14:41:56
(9 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.80.55.55 (55.55.80.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.80.55.55 (55.55.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 10:41:48.436955 2026] [security2:error] [pid 2937826:tid 2937826] [client 34.80.55.55:41340] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||deal-arabia.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "deal-arabia.com"] [uri "/z9x8c7v6b5-debug-trigger-deal-arabia.com"] [unique_id "aq_wrPkKEzNzJQdBWdHOWAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 13:50:58
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.80.55.55 (55.55.80.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.55.55 (55.55.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 09:50:53.879214 2026] [security2:error] [pid 894:tid 894] [client 34.80.55.55:42090] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dcwenger.com"] [uri "/backend/.env"] [unique_id "aq_kvXPPLf_irR9yb3XArQAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ฌ
mypatricks
2026-09-20 13:18:26
(10 hours ago)
34.80.55.55 | Port: 9411 | DNS: 55.55.80.34.bc.googleusercontent.com 2026-09-20T21:18:24+08:00 Asia/ ...
show more
34.80.55.55 | Port: 9411 | DNS: 55.55.80.34.bc.googleusercontent.com 2026-09-20T21:18:24+08:00 Asia/Taipei | Fake Baiduspider Detected | UA: Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html) HTTP/1.1 443 GET | URL: /v1/onboarding/config?token= | Ref: - | Country: TW/Taiwan/+08:00 IP City: Taipei a3e11da9fc510b1f-NRT/Tokyo, Japan 12 hits/2 secs Robots 1
show less
Brute-Force
Web App Attack
Blog Spam
Web Spam
Exploited Host
๐บ๐ธ
TPI-Abuse
2026-09-20 13:18:19
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.80.55.55 (55.55.80.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.55.55 (55.55.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 09:18:15.384921 2026] [security2:error] [pid 13125:tid 13125] [client 34.80.55.55:57304] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "chevronparkett.com"] [uri "/.env.local"] [unique_id "aq_dF0I6P4YWH3QvwXPa5QAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
dbmwebdesign
2026-09-20 13:05:31
(10 hours ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
Anonymous
2026-09-20 12:59:05
(10 hours ago)
git/env leak probe
Web App Attack
๐ธ๐ฌ
Cloudkul Cloudkul
2026-09-20 12:43:33
(11 hours ago)
Attempted Not Found (404 status code) requests on our application, more than 30% of their total requ ...
show more
Attempted Not Found (404 status code) requests on our application, more than 30% of their total requests.
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 12:40:51
(11 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.80.55.55 (55.55.80.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.80.55.55 (55.55.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 08:40:44.633205 2026] [security2:error] [pid 25889:tid 25889] [client 34.80.55.55:47834] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||banis-associates.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "banis-associates.com"] [uri "/storage/logs/laravel.log"] [unique_id "aq_UTJCd_U2ROh-RAQ3m4wAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-20 12:35:03
(11 hours ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
๐ฌ๐ง
consul.to
2026-09-20 12:24:06
(11 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐ฎ๐น
VHosting
2026-09-20 12:20:04
(11 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2026-09-20 12:16:19
(11 hours ago)
(modsecurity) srv101 ModSecurity 34.80.55.55 (TW/Taiwan/55.55.80.34.bc.googleusercontent.com): 30 in ...
show more
(modsecurity) srv101 ModSecurity 34.80.55.55 (TW/Taiwan/55.55.80.34.bc.googleusercontent.com): 30 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐ฉ๐ช
Marc
2026-09-20 12:12:32
(11 hours ago)
34.80.55.55 - - [20/Sep/2026:14:12:31 +0200] "GET /api/v1/config HTTP/2.0" 404 291 "-" "Mozilla/5.0 ...
show more
34.80.55.55 - - [20/Sep/2026:14:12:31 +0200] "GET /api/v1/config HTTP/2.0" 404 291 "-" "Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)" 34.80.55.55 - - [20/Sep/2026:14:12:31 +0200] "GET /api/v2/config HTTP/2.0" 404 269 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)" 34.80.55.55 - - [20/Sep/2026:14:12:31 +0200] "GET /api/v2/settings HTTP/2.0" 404 269 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)"
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-20 11:39:35
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.80.55.55 (55.55.80.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.55.55 (55.55.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 07:39:28.064875 2026] [security2:error] [pid 9395:tid 9395] [client 34.80.55.55:40246] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "15cherryavenue.com"] [uri "/backend/.env"] [unique_id "aq_F8HYoA8y7bDbt-dqDrgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack