๐บ๐ธ
TPI-Abuse
2026-09-21 22:50:54
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 34.81.68.87 (87.68.81.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.81.68.87 (87.68.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 18:50:50.701915 2026] [security2:error] [pid 14591:tid 14591] [client 34.81.68.87:60820] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.five21.com|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.five21.com"] [uri "/ssl/localhost.key"] [unique_id "arG0yutLQnf5MsNSCldttgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
DEV-DNS
2026-09-21 21:25:55
(5 days ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
๐ฉ๐ช
zUnlegit
2026-09-21 21:25:25
(5 days ago)
Automated web scanner requested sensitive path: /.aws/credentials
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 20:33:42
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.81.68.87 (87.68.81.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.68.87 (87.68.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 16:33:39.185564 2026] [security2:error] [pid 15306:tid 15306] [client 34.81.68.87:60186] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.krankybitchguitars.com"] [uri "/.env.backup"] [unique_id "arGUo0QQiMY-l6b6NKymmQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 19:54:53
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 34.81.68.87 (87.68.81.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.81.68.87 (87.68.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 15:54:49.847803 2026] [security2:error] [pid 20905:tid 20905] [client 34.81.68.87:45904] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.mapleleaf-marketing.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.mapleleaf-marketing.com"] [uri "/rclone.conf"] [unique_id "arGLia7hDxfNZuggLUrOOgAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
kivitendo.de
2026-09-21 17:11:34
(5 days ago)
[Mon Sep 21 19:11:30.657718 2026] [authz_core:error] [pid 17412:tid 17412] [client 34.81.68.87:58074 ...
show more
[Mon Sep 21 19:11:30.657718 2026] [authz_core:error] [pid 17412:tid 17412] [client 34.81.68.87:58074] AH01630: client denied by server configuration: /var/www/html/server-status
[Mon Sep 21 19:11:33.770466 2026] [authz_core:error] [pid 17952:tid 17952] [client 34.81.68.87:60460] AH01630: client denied by server configuration: /var/www/html/.htpasswd
...
show less
Brute-Force
Web App Attack
Anonymous
2026-09-21 16:30:02
(5 days ago)
CrowdSec decision: crowdsecurity/http-admin-interface-probing (origin: crowdsec)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 15:12:04
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 34.81.68.87 (87.68.81.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.81.68.87 (87.68.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 11:11:57.372492 2026] [security2:error] [pid 28964:tid 28964] [client 34.81.68.87:45000] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.labcomputers.com|F|2"] [data ".labcomputers.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.labcomputers.com"] [uri "/z9x8c7v6b5-debug-trigger-www.labcomputers.com"] [unique_id "arFJPduPsaeaoousMp2hjgAAAEk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
taivas.nl
2026-09-21 15:02:31
(5 days ago)
Site scraper
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 14:56:45
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 34.81.68.87 (87.68.81.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.81.68.87 (87.68.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 10:56:42.015303 2026] [security2:error] [pid 28338:tid 28338] [client 34.81.68.87:55634] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.kugbe.com|F|2"] [data ".kugbe.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.kugbe.com"] [uri "/z9x8c7v6b5-debug-trigger-mail.kugbe.com"] [unique_id "arFFqtBrcK1L4x0n4punoAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
SkyDancer
2026-09-21 14:51:59
(5 days ago)
Multiple unauthorized attempts to access using wrong credentials. Attack automatically blocked by Sk ...
show more
Multiple unauthorized attempts to access using wrong credentials. Attack automatically blocked by SkyDancer Ai. EXT-SYS-Vx
show less
Hacking
Brute-Force
SSH
๐ฉ๐ช
thesimonmanuel
2026-09-21 14:49:57
(5 days ago)
34.81.68.87 - - [21/Sep/2026:20:19:56 +0530] "GET /agent/.env HTTP/2.0" 403 106 "-" "Mozilla/5.0 (co ...
show more
34.81.68.87 - - [21/Sep/2026:20:19:56 +0530] "GET /agent/.env HTTP/2.0" 403 106 "-" "Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)"
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 14:38:29
(5 days ago)
(mod_security) mod_security (id:210580) triggered by 34.81.68.87 (87.68.81.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210580) triggered by 34.81.68.87 (87.68.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 10:38:21.335071 2026] [security2:error] [pid 28756:tid 28756] [client 34.81.68.87:58648] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at ARGS:path. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||abbysue.com|F|2"] [data "Matched Data: proc/self/environ found within ARGS:path: ../../../../proc/self/environ"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "abbysue.com"] [uri "/userfiles/x"] [unique_id "arFBXasyk8SnRy8mnV_DOwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-21 14:30:04
(5 days ago)
CrowdSec decision: crowdsecurity/http-bad-user-agent (origin: crowdsec)
Port Scan
๐บ๐ธ
TPI-Abuse
2026-09-21 14:20:43
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 34.81.68.87 (87.68.81.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.81.68.87 (87.68.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 10:20:40.303437 2026] [security2:error] [pid 5163:tid 5163] [client 34.81.68.87:46874] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.knoxvillelimos.com|F|2"] [data ".knoxvillelimos.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.knoxvillelimos.com"] [uri "/z9x8c7v6b5-debug-trigger-www.knoxvillelimos.com"] [unique_id "arE9OPq3VB0XOP7qRiX98wAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack