๐ฉ๐ช
konseptit
2026-09-21 06:19:18
(5 days ago)
(mod_security) mod_security triggered on hostname [redacted] 34.80.72.233 (TW/Taiwan/233.72.80.34.bc ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.80.72.233 (TW/Taiwan/233.72.80.34.bc.googleusercontent.com)
show less
SQL Injection
๐ง๐ท
hostseries
2026-09-21 03:55:25
(5 days ago)
Trigger: LF_CPANEL
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-21 03:23:07
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.80.72.233 (233.72.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.72.233 (233.72.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 23:23:03.459090 2026] [security2:error] [pid 16342:tid 16342] [client 34.80.72.233:36314] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.saltcityprint.com"] [uri "/@fs/app/.env"] [unique_id "arCjFywucIWaxSkSr6l6ZAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 02:49:21
(5 days ago)
(mod_security) mod_security (id:949110) triggered by 34.80.72.233 (233.72.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:949110) triggered by 34.80.72.233 (233.72.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 22:49:15.093238 2026] [security2:error] [pid 11691:tid 11691] [client 34.80.72.233:39466] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "scrase.com"] [uri "/rclone.conf"] [unique_id "arCbK-PxR6BfP9oKkVYmqQAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐พ
Rizzy
2026-09-21 02:47:54
(5 days ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 01:36:40
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 34.80.72.233 (233.72.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.80.72.233 (233.72.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 21:36:33.289859 2026] [security2:error] [pid 18545:tid 18545] [client 34.80.72.233:56132] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.newerc.com|F|2"] [data ".newerc.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.newerc.com"] [uri "/z9x8c7v6b5-debug-trigger-www.newerc.com"] [unique_id "arCKIZ9OnWmxm7T9OSpQPgAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 01:18:43
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.80.72.233 (233.72.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.72.233 (233.72.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 21:18:38.676972 2026] [security2:error] [pid 28814:tid 28814] [client 34.80.72.233:58130] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.robertseyewear.com"] [uri "/api/v1/.env"] [unique_id "arCF7p4f_E5A_29g1YgGDwAAAEA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 01:01:27
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.80.72.233 (233.72.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.72.233 (233.72.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 21:01:20.924722 2026] [security2:error] [pid 28909:tid 28935] [client 34.80.72.233:53296] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.sandbarsteve.com"] [uri "/.env.bak"] [unique_id "arCB4ABu0q6s2SRZeFAnSgAAARg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 00:46:07
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.80.72.233 (233.72.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.72.233 (233.72.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 20:46:02.665010 2026] [security2:error] [pid 2007:tid 2007] [client 34.80.72.233:38008] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.prezence.com"] [uri "/services/.env"] [unique_id "arB-SpAod6HvvRbNtE7I_gAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 00:26:51
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 34.80.72.233 (233.72.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.80.72.233 (233.72.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 20:26:43.287339 2026] [security2:error] [pid 20689:tid 20689] [client 34.80.72.233:42094] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.rhkglobal.com|F|2"] [data ".rhkglobal.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.rhkglobal.com"] [uri "/z9x8c7v6b5-debug-trigger-mail.rhkglobal.com"] [unique_id "arB5w7jcyaSuA4QpBXitCAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 00:01:40
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 34.80.72.233 (233.72.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.80.72.233 (233.72.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 20:01:33.916277 2026] [security2:error] [pid 11954:tid 11954] [client 34.80.72.233:58452] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.ritterlien.com|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.ritterlien.com"] [uri "/ssl/localhost.key"] [unique_id "arBz3V-3Qiw6j-1hY-sRLQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 23:30:12
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.80.72.233 (233.72.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.72.233 (233.72.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 19:30:03.784416 2026] [security2:error] [pid 9324:tid 9324] [client 34.80.72.233:60052] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.seeingblue.com"] [uri "/@fs/app/.env"] [unique_id "arBsexlmv0ylLQ350Vj7dgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 23:14:40
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.80.72.233 (233.72.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.72.233 (233.72.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 19:14:33.692585 2026] [security2:error] [pid 3415:tid 3415] [client 34.80.72.233:35206] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mountainjaytherapy.com"] [uri "/.git/HEAD"] [unique_id "arBo2Qfg5I-cDLpkOMXQuwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 22:59:22
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.80.72.233 (233.72.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.72.233 (233.72.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 18:59:18.047641 2026] [security2:error] [pid 7178:tid 7178] [client 34.80.72.233:45064] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.openheartwellness.com"] [uri "/workspace/.env"] [unique_id "arBlRm0134RGw-iS9i9ZEQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 22:39:55
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.80.72.233 (233.72.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.72.233 (233.72.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 18:39:51.178643 2026] [security2:error] [pid 9440:tid 9440] [client 34.80.72.233:47734] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dashboard.nutandboltguy.com"] [uri "/.env"] [unique_id "arBgt7udPn789WDUAWqcswAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack