๐บ๐ธ
[email protected]
2026-09-22 10:34:52
(1 day ago)
CrowdSec ban: crowdsecurity/unifi-flood-detection (duration: 71h59m57s)
Port Scan
๐บ๐ธ
TPI-Abuse
2026-09-22 00:18:57
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.83.42.89 (89.42.83.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.83.42.89 (89.42.83.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 20:18:53.164000 2026] [security2:error] [pid 20532:tid 20532] [client 34.83.42.89:39376] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.losbarbarosdelnorte.com|F|2"] [data ".losbarbarosdelnorte.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.losbarbarosdelnorte.com"] [uri "/z9x8c7v6b5-debug-trigger-mail.losbarbarosdelnorte.com"] [unique_id "arHJbewY0uP3O9DD6Qoy8QAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 21:07:38
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.83.42.89 (89.42.83.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.83.42.89 (89.42.83.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 17:07:31.882771 2026] [security2:error] [pid 30046:tid 30140] [client 34.83.42.89:45204] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.lordennerdale.com"] [uri "/backend/.env"] [unique_id "arGckyPOmqBOzZr0n9I9bQAAAIc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 20:24:22
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.83.42.89 (89.42.83.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.83.42.89 (89.42.83.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 16:24:15.098957 2026] [security2:error] [pid 16527:tid 16527] [client 34.83.42.89:42156] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "llaira.com.artizandecor.com"] [uri "/.env"] [unique_id "arGSbyErbXXE0HL3OXJ3ZgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
JustMeHere
2026-09-21 17:22:34
(2 days ago)
[Mon Sep 21 13:22:25.654704 2026] [security2:error] [pid 43224:tid 43267] [client 34.83.42.89:37108] ...
show more
[Mon Sep 21 13:22:25.654704 2026] [security2:error] [pid 43224:tid 43267] [client 34.83.42.89:37108] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.15.0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "kr.yorknation.com"] [uri "/"] [unique_id "arFn0eVAhfCN56au3l2D9QAAAQ8"]
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 17:03:11
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.83.42.89 (89.42.83.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.83.42.89 (89.42.83.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 13:03:06.752780 2026] [security2:error] [pid 30185:tid 30185] [client 34.83.42.89:50186] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lmjetservices.com"] [uri "/.git/HEAD"] [unique_id "arFjSje8OyMs7QNecrVSgAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐ด
clauss
2026-09-21 16:35:15
(2 days ago)
34.83.42.89 - - [21/Sep/2026:19:35:10 +0300] "GET /.env.example HTTP/2.0" 301 0 "-" "DuckAssistBot/1 ...
show more
34.83.42.89 - - [21/Sep/2026:19:35:10 +0300] "GET /.env.example HTTP/2.0" 301 0 "-" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)"
34.83.42.89 - - [21/Sep/2026:19:35:14 +0300] "GET /.env.example HTTP/2.0" 404 21351 "https://www.local-hosts.com/.env.example" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)"
...
show less
Web App Attack
๐บ๐ธ
mnsf
2026-09-21 15:05:40
(2 days ago)
Too many Status 40X (16)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 14:59:31
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.83.42.89 (89.42.83.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.83.42.89 (89.42.83.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 10:59:24.389841 2026] [security2:error] [pid 22434:tid 22434] [client 34.83.42.89:39636] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||lopansri.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "lopansri.com"] [uri "/z9x8c7v6b5-debug-trigger-lopansri.com"] [unique_id "arFGTLa_1OUkQJRojve4CwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
deskpass.com
2026-09-21 14:37:43
(2 days ago)
POST /lib/terminal-xhr.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 14:35:11
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.83.42.89 (89.42.83.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.83.42.89 (89.42.83.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 10:35:08.375627 2026] [security2:error] [pid 3775:tid 3775] [client 34.83.42.89:45522] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "infojeffreysbay.com"] [uri "/@fs/src/.env"] [unique_id "arFAnMBYqAEEFSb70cifywAAAEg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-09-21 14:30:25
(2 days ago)
This address declares itself a crawler and keeps requesting pages after being refused (HTTP 403/429) ...
show more
This address declares itself a crawler and keeps requesting pages after being refused (HTTP 403/429) and told to stop by robots.txt. A crawler that ignores refusals costs our servers capacity for nothing and is treated as abusive; blocked. Please make it honour robots.txt and the refusals it is given. | ua: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] ) (+4 more) | path: /utils/.env (+14 more) | 2026-09-21 14:30 UTC
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-21 14:13:51
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.83.42.89 (89.42.83.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.83.42.89 (89.42.83.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 10:13:45.423185 2026] [security2:error] [pid 27663:tid 27663] [client 34.83.42.89:49244] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||lolycarrillo.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "lolycarrillo.com"] [uri "/z9x8c7v6b5-debug-trigger-lolycarrillo.com"] [unique_id "arE7mVt9caaXgnxwZUdQTgAAACs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐พ
Rizzy
2026-09-21 14:07:21
(2 days ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ฉ๐ช
raph
2026-09-21 14:01:36
(2 days ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack