๐บ๐ธ
TPI-Abuse
2026-09-22 16:44:57
(34 minutes ago)
(mod_security) mod_security (id:210580) triggered by 34.81.147.24 (24.147.81.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210580) triggered by 34.81.147.24 (24.147.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 12:44:49.862723 2026] [security2:error] [pid 7830:tid 7830] [client 34.81.147.24:0] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at ARGS:href. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||gibitdigital.com|F|2"] [data "Matched Data: proc/self/environ found within ARGS:href: /proc/self/environ"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "gibitdigital.com"] [uri "/_image"] [unique_id "arKwgZpqIP_EDZeHrFFCOgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 15:10:25
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.81.147.24 (24.147.81.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.81.147.24 (24.147.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 11:10:17.405736 2026] [security2:error] [pid 2604:tid 2604] [client 34.81.147.24:37784] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||joggersnipple.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "joggersnipple.com"] [uri "/z9x8c7v6b5-debug-trigger-joggersnipple.com"] [unique_id "arKaWefhSHFxsvLSC_tlZAAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 14:50:40
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.81.147.24 (24.147.81.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.81.147.24 (24.147.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 10:50:36.344428 2026] [security2:error] [pid 30134:tid 30134] [client 34.81.147.24:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kidswithcamerasmovie.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kidswithcamerasmovie.com"] [uri "/z9x8c7v6b5-debug-trigger-kidswithcamerasmovie.com"] [unique_id "arKVvI5l4ToBbnXwov_4LwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Swiptly
2026-09-22 14:46:39
(2 hours ago)
Excessive 403/404/405 PHP/CMS errors from scanning or broken bots
...
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-22 14:42:32
(2 hours ago)
Excessive multi-domain requests
Brute-Force
๐ท๐ด
clauss
2026-09-22 14:32:35
(2 hours ago)
34.81.147.24 - - [22/Sep/2026:17:32:34 +0300] "GET /secrets.yml HTTP/2.0" 301 0 "-" "Mozilla/5.0 (co ...
show more
34.81.147.24 - - [22/Sep/2026:17:32:34 +0300] "GET /secrets.yml HTTP/2.0" 301 0 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)"
34.81.147.24 - - [22/Sep/2026:17:32:34 +0300] "GET /firebase-adminsdk.json HTTP/2.0" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1)"
...
show less
Web App Attack
๐บ๐ธ
Mundo Bueno
2026-09-22 14:17:22
(3 hours ago)
[ISILIA Protection v2.3] Tentative d'accรจs: /files../.env [RATE LIMITED - 1800s quarantine] | Pays: ...
show more
[ISILIA Protection v2.3] Tentative d'accรจs: /files../.env [RATE LIMITED - 1800s quarantine] | Pays: TW | UA: Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)
show less
Hacking
Web App Attack
๐บ๐ธ
dot.mg
2026-09-22 13:58:30
(3 hours ago)
Scan of vulnerable files
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 13:33:24
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.81.147.24 (24.147.81.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.81.147.24 (24.147.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 09:33:19.437371 2026] [security2:error] [pid 2456:tid 2456] [client 34.81.147.24:51372] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||micahgartman.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "micahgartman.com"] [uri "/z9x8c7v6b5-debug-trigger-micahgartman.com"] [unique_id "arKDnynv73b3cHiwR2PhsQAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 12:33:22
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.81.147.24 (24.147.81.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.81.147.24 (24.147.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 08:33:17.162184 2026] [security2:error] [pid 20016:tid 20016] [client 34.81.147.24:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||nyemdr.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "nyemdr.com"] [uri "/z9x8c7v6b5-debug-trigger-nyemdr.com"] [unique_id "arJ1jXod_SbHA6YwNFByqwAAAFM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
oralunal
2026-09-22 12:18:48
(5 hours ago)
IP banned by Fail2Ban in jail oral-suss access.log mvfnds
...
Bad Web Bot
Web App Attack
๐ซ๐ท
Baking333
2026-09-22 11:59:51
(5 hours ago)
[redacted] 34.81.147.24 - - [22/Sep/2026:12:59:50 +0100] "GET /__vite_rsc_findSourceMapURL?filename= ...
show more
[redacted] 34.81.147.24 - - [22/Sep/2026:12:59:50 +0100] "GET /__vite_rsc_findSourceMapURL?filename=file:///app/.env&environmentName=rsc HTTP/2.0" 301 121 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1)" [redacted] 34.81.147.24 - - [22/Sep/2026:12:59:50 +0100] "GET /@fs/.env?raw&url?? HTTP/2.0" 301 60 "-" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://[redacted]/)"
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-22 11:41:22
(5 hours ago)
Port scan against our edge firewall, detected by Wazuh: Regel 31151 | abuseipdb 75% (19 Meldungen, T ...
show more
Port scan against our edge firewall, detected by Wazuh: Regel 31151 | abuseipdb 75% (19 Meldungen, TW)
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-09-22 11:33:54
(5 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.81.147.24 (24.147.81.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.81.147.24 (24.147.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 07:33:49.268109 2026] [security2:error] [pid 27081:tid 27081] [client 34.81.147.24:47004] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||postermodelsworldwideinc.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "postermodelsworldwideinc.com"] [uri "/z9x8c7v6b5-debug-trigger-postermodelsworldwideinc.com"] [unique_id "arJnncBcai7winlpAkvoFQAAADE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
regishoussin
2026-09-22 11:22:58
(5 hours ago)
Automated web scanning detected by Wazuh (rule 100241): repeated 400/404 errors from mass probing of ...
show more
Automated web scanning detected by Wazuh (rule 100241): repeated 400/404 errors from mass probing of admin/backdoor paths (e.g. wp-login.php, known CMS shell filenames) on an Apache web server, on 2026-09-22 11:22 UTC.
show less
Bad Web Bot
Web App Attack