๐ซ๐ท
masterguru
2026-10-11 01:26:20
(4 minutes ago)
BAD BOT - Detected and Blocked.. Matched phrase "bytespider" at REQUEST_HEADERS:User-Agent. (1100000 ...
show more
BAD BOT - Detected and Blocked.. Matched phrase "bytespider" at REQUEST_HEADERS:User-Agent. (1100000-195)
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-11 00:57:14
(34 minutes ago)
(mod_security) mod_security (id:210730) triggered by 34.83.19.179 (179.19.83.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.83.19.179 (179.19.83.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 20:57:08.700881 2026] [security2:error] [pid 2572:tid 2600] [client 34.83.19.179:41392] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||livingalegacybulldogges.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "livingalegacybulldogges.com"] [uri "/z9x8c7v6b5-debug-trigger-livingalegacybulldogges.com"] [unique_id "asre5M6BQpTO8AsmsIyMVwAAARg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-10-11 00:36:05
(55 minutes ago)
Excessive multi-domain requests
Brute-Force
๐ฉ๐ช
Live Home Cams
2026-10-11 00:30:38
(1 hour ago)
WebApp brute force attack detected. Multiple file scanning attempts from 34.83.19.179. Detected by f ...
show more
WebApp brute force attack detected. Multiple file scanning attempts from 34.83.19.179. Detected by fail2ban.
show less
Web App Attack
Brute-Force
๐จ๐ฆ
Mediashaker
2026-10-11 00:18:42
(1 hour ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 34.83.19.179 (US/Uni ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 34.83.19.179 (US/United States/179.19.83.34.bc.googleusercontent.com)
show less
Bad Web Bot
๐บ๐ธ
TAY
2026-10-10 23:46:56
(1 hour ago)
34.83.19.179 - - [11/Oct/2026:07:46:55 +0800] "GET /js../.env HTTP/1.1" 200 595 "-" "Mozilla/5.0 (co ...
show more
34.83.19.179 - - [11/Oct/2026:07:46:55 +0800] "GET /js../.env HTTP/1.1" 200 595 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)"
34.83.19.179 - - [11/Oct/2026:07:46:55 +0800] "GET /images../.env HTTP/1.1" 200 595 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
34.83.19.179 - - [11/Oct/2026:07:46:55 +0800] "GET /uploads../.env HTTP/1.1" 200 595 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36"
34.83.19.179 - - [11/Oct/2026:07:46:55 +0800] "GET /assets../.env HTTP/1.1" 200 595 "-" "Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)"
34.83.19.179 - - [11/Oct/2026:07:46:55 +0800] "GET /build../.env HTTP/1.1" 200 595 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )"
34.83.19.179 - - [11/Oct/2026:07:46:55 +0800] "GET /files../.env HTTP/1.1" 200 595 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-Us
...
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-10-10 23:28:02
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.83.19.179 (179.19.83.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.83.19.179 (179.19.83.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 19:27:53.776637 2026] [security2:error] [pid 11098:tid 11098] [client 34.83.19.179:51064] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||linnardfinancial.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "linnardfinancial.com"] [uri "/z9x8c7v6b5-debug-trigger-linnardfinancial.com"] [unique_id "asrJ-QKsNvStZeGQhMW_AgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-10 22:47:00
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.83.19.179 (179.19.83.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.83.19.179 (179.19.83.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 18:46:58.027233 2026] [security2:error] [pid 30554:tid 30554] [client 34.83.19.179:54906] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||limobusrichmond.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "limobusrichmond.com"] [uri "/z9x8c7v6b5-debug-trigger-limobusrichmond.com"] [unique_id "asrAYpPANI-3avWcUSTsDwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-10 22:15:26
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.83.19.179 (179.19.83.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.83.19.179 (179.19.83.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 18:15:21.971597 2026] [security2:error] [pid 25517:tid 25517] [client 34.83.19.179:54654] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||lighthousegive.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "lighthousegive.com"] [uri "/z9x8c7v6b5-debug-trigger-lighthousegive.com"] [unique_id "asq4-biLWlRUHekDSiID0QAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-10 21:47:47
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.83.19.179 (179.19.83.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.83.19.179 (179.19.83.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 17:47:41.827405 2026] [security2:error] [pid 3766:tid 3778] [client 34.83.19.179:41126] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||lifecoachcertified.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "lifecoachcertified.com"] [uri "/z9x8c7v6b5-debug-trigger-lifecoachcertified.com"] [unique_id "asqyffnW07LfyA9OnDNcCAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
maxpower
2026-10-10 21:39:40
(3 hours ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.83.19.179 (US/United States/179.19.83 ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.83.19.179 (US/United States/179.19.83.34.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.83.19.179 - - [10/Oct/2026:23:39:37 +0200] "GET /.ssh/id_rsa HTTP/2.0" 200 4802 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)" "34.83.19.179" host=lidotrocadero.com
show less
Port Scan
Anonymous
2026-10-10 21:20:04
(4 hours ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-10-10 21:02:19
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.83.19.179 (179.19.83.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.83.19.179 (179.19.83.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 17:02:15.725792 2026] [security2:error] [pid 18045:tid 18045] [client 34.83.19.179:42128] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||lgougeon.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "lgougeon.com"] [uri "/z9x8c7v6b5-debug-trigger-lgougeon.com"] [unique_id "asqn1ziuur0jrRnKqztSlAAAADg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-10 20:44:18
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.83.19.179 (179.19.83.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.83.19.179 (179.19.83.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 16:44:12.708988 2026] [security2:error] [pid 11160:tid 11160] [client 34.83.19.179:60350] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||lewpratt.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "lewpratt.com"] [uri "/z9x8c7v6b5-debug-trigger-lewpratt.com"] [unique_id "asqjnI9MuL1Yge_DvfskCAAAAH8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
IndigoRidge
2026-10-10 20:31:53
(4 hours ago)
[Sat Oct 10 16:31:51.792664 2026] [authz_core:error] [pid 3222229:tid 140582240143104] [client 34.83 ...
show more
[Sat Oct 10 16:31:51.792664 2026] [authz_core:error] [pid 3222229:tid 140582240143104] [client 34.83.19.179:0] AH01630: client denied by server configuration: /var/www/vhosts/levee-capital.com/error_docs/forbidden.html
[Sat Oct 10 16:31:52.587611 2026] [authz_core:error] [pid 3222229:tid 140582256928512] [client 34.83.19.179:0] AH01630: client denied by server configuration: /var/www/vhosts/levee-capital.com/httpdocs/web
[Sat Oct 10 16:31:52.587674 2026] [authz_core:error] [pid 3222229:tid 140582256928512] [client 34.83.19.179:0] AH01630: client denied by server configuration: /var/www/vhosts/levee-capital.com/error_docs/forbidden.html
[Sat Oct 10 16:31:52.600007 2026] [authz_core:error] [pid 3222031:tid 140582349248256] [client 34.83.19.179:0] AH01630: client denied by server configuration: /var/www/vhosts/levee-capital.com/httpdocs/backend
[Sat Oct 10 16:31:52.600066 2026] [authz_core:error] [pid 3222031:tid 140582349248256] [client 34.83.19.179:0] AH01630: client denied by server co
...
show less
Web App Attack