๐บ๐ธ
TPI-Abuse
2026-09-22 16:59:10
(12 minutes ago)
(mod_security) mod_security (id:210730) triggered by 34.80.98.82 (82.98.80.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.80.98.82 (82.98.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 12:59:06.550860 2026] [security2:error] [pid 2213:tid 2213] [client 34.80.98.82:39668] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||stananddana.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "stananddana.com"] [uri "/z9x8c7v6b5-debug-trigger-stananddana.com"] [unique_id "arKz2kCQXdBHUiK5bzhtxgAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-22 16:22:43
(48 minutes ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 16:16:32
(54 minutes ago)
(mod_security) mod_security (id:210580) triggered by 34.80.98.82 (82.98.80.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210580) triggered by 34.80.98.82 (82.98.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 12:16:26.724250 2026] [security2:error] [pid 25415:tid 25415] [client 34.80.98.82:49414] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at ARGS:href. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||sub-sea9.com|F|2"] [data "Matched Data: proc/self/environ found within ARGS:href: /proc/self/environ"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "sub-sea9.com"] [uri "/_image"] [unique_id "arKp2nhIIwm8chc_qzMF0QAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
IndigoRidge
2026-09-22 16:02:32
(1 hour ago)
34.80.98.82 - - [22/Sep/2026:12:02:32 -0400] "GET /@fs/src/.env?raw?? HTTP/1.1" 403 5705 "-" "Mozill ...
show more
34.80.98.82 - - [22/Sep/2026:12:02:32 -0400] "GET /@fs/src/.env?raw?? HTTP/1.1" 403 5705 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1)"
34.80.98.82 - - [22/Sep/2026:12:02:32 -0400] "GET /@fs/app/.env?raw?? HTTP/1.1" 403 5705 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)"
34.80.98.82 - - [22/Sep/2026:12:02:32 -0400] "GET /@fs/..%252f..%252f..%252f..%252f..%252froot/.env?raw?? HTTP/1.1" 403 5705 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36"
...
show less
Web App Attack
Anonymous
2026-09-22 15:47:24
(1 hour ago)
Blocked by ModSec and CSF
Port Scan
๐ช๐ธ
robotstxt
2026-09-22 14:43:13
(2 hours ago)
34.80.98.82 - - [22/Sep/2026:14:42:53 +0000] "GET /.env.prod HTTP/2.0" 403 16023 "-" "DuckAssistBot/ ...
show more
34.80.98.82 - - [22/Sep/2026:14:42:53 +0000] "GET /.env.prod HTTP/2.0" 403 16023 "-" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)"
34.80.98.82 - - [22/Sep/2026:14:42:53 +0000] "GET /.env.save HTTP/2.0" 403 16023 "-" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)"
34.80.98.82 - - [22/Sep/2026:14:42:53 +0000] "GET /api/.env HTTP/2.0" 403 16022 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)"
34.80.98.82 - - [22/Sep/2026:14:42:53 +0000] "GET /config/.env HTTP/2.0" 403 16021 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)"
34.80.98.82 - - [22/Sep/2026:14:42:53 +0000] "GET /admin/.env HTTP/2.0" 403 16022 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.4; +https://openai.com/gptbot"
...
show less
Web App Attack
๐ณ๐ฑ
svr
2026-09-22 13:42:04
(3 hours ago)
Abusive Automated Web Scanner
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 13:16:09
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.80.98.82 (82.98.80.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.80.98.82 (82.98.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 09:16:01.810827 2026] [security2:error] [pid 25292:tid 25292] [client 34.80.98.82:36464] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||thewarmachineguns.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "thewarmachineguns.com"] [uri "/z9x8c7v6b5-debug-trigger-thewarmachineguns.com"] [unique_id "arJ_kaE6a4OKjeaAeAb8mwAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ฌ
anotherwatcher
2026-09-22 13:11:04
(4 hours ago)
bad bot
Bad Web Bot
๐ซ๐ท
dynamix
2026-09-22 11:52:40
(5 hours ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 11:44:52
(5 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.80.98.82 (82.98.80.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.80.98.82 (82.98.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 07:44:44.864248 2026] [security2:error] [pid 27234:tid 27234] [client 34.80.98.82:40078] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||truthsabouthealthcare.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "truthsabouthealthcare.com"] [uri "/z9x8c7v6b5-debug-trigger-truthsabouthealthcare.com"] [unique_id "arJqLFXQp4XWYJAIGMbEuAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
bazter.pro
2026-09-22 11:29:37
(5 hours ago)
Fail2Ban: plesk-bot-aggressive - 15 failures
Port Scan
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-09-22 11:25:48
(5 hours ago)
This address sent web requests that have no legitimate reading: known exploit paths, path traversal, ...
show more
This address sent web requests that have no legitimate reading: known exploit paths, path traversal, injected payloads, or the signature of a vulnerability scanner. This is an attack on the sites we host, blocked on sight. Please check the machine behind it for an attack tool or malware. | method: GET | path: /asset-manifest.json (+5 more) | 2026-09-22 11:25 UTC
show less
Hacking
Web App Attack
๐บ๐ธ
masterguru
2026-09-22 11:16:25
(5 hours ago)
COMODO WAF: OS File Access Attempt. Matched phrase "proc/self/environ" at ARGS:0. (210580-169)
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-22 11:06:30
(6 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.80.98.82 (82.98.80.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.80.98.82 (82.98.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 07:06:24.127713 2026] [security2:error] [pid 13717:tid 13763] [client 34.80.98.82:59182] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||unitedonegroup.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "unitedonegroup.com"] [uri "/z9x8c7v6b5-debug-trigger-unitedonegroup.com"] [unique_id "arJhL2bTaJUsFoSLEikv6gAAAcM"]
show less
Brute-Force
Bad Web Bot
Web App Attack