Anonymous
2026-10-02 20:27:52
(5 hours ago)
Blocked by ModSec and CSF
Port Scan
๐ฉ๐ช
LRob
2026-10-02 20:25:09
(5 hours ago)
Wordlist path sweep | method: GET, POST | path: /model/info, /lib/terminal-xhr.php, /1g6i1vxpopiljbr ...
show more
Wordlist path sweep | method: GET, POST | path: /model/info, /lib/terminal-xhr.php, /1g6i1vxpopiljbrvgbue (+3 more) | ua: Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/), Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot), Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler) (+2 more)
show less
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 18:41:04
(6 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.84.155.184 (184.155.84.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.84.155.184 (184.155.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 14:40:57.429840 2026] [security2:error] [pid 2033:tid 2033] [client 34.84.155.184:33020] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||syscomprint.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "syscomprint.com"] [uri "/z9x8c7v6b5-debug-trigger-syscomprint.com"] [unique_id "ar_6uWj6WDEYfRG1BiNrZwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 17:36:31
(8 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.84.155.184 (184.155.84.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.84.155.184 (184.155.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 13:36:27.870002 2026] [security2:error] [pid 8038:tid 8038] [client 34.84.155.184:43224] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||tatying.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "tatying.com"] [uri "/z9x8c7v6b5-debug-trigger-tatying.com"] [unique_id "ar_rm-MEeLUJmn2Eacs3FQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 17:15:15
(8 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.84.155.184 (184.155.84.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:949110) triggered by 34.84.155.184 (184.155.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 13:15:09.402499 2026] [security2:error] [pid 1530:tid 1530] [client 34.84.155.184:39834] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "tikehaubookings.com"] [uri "/z9x8c7v6b5-debug-trigger-tikehaubookings.com"] [unique_id "ar_mnR_He8acPk3e9d2hIQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
bazter.pro
2026-10-02 15:28:31
(10 hours ago)
Fail2Ban: plesk-bot-aggressive - 15 failures
Port Scan
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 15:10:13
(10 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.84.155.184 (184.155.84.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.84.155.184 (184.155.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 11:10:09.158773 2026] [security2:error] [pid 24046:tid 24046] [client 34.84.155.184:60806] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.willowcreekretreathouse.com|F|2"] [data ".willowcreekretreathouse.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.willowcreekretreathouse.com"] [uri "/z9x8c7v6b5-debug-trigger-www.willowcreekretreathouse.com"] [unique_id "ar_JUaoznV6KAmtF6iS9bwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 14:44:34
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.84.155.184 (184.155.84.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.155.184 (184.155.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 10:44:29.696091 2026] [security2:error] [pid 29329:tid 29359] [client 34.84.155.184:56936] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.sweeneyzone.com"] [uri "/.htpasswd"] [unique_id "ar_DTfEBDmfN5P0vCxLA4AAAANA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 13:59:16
(11 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.84.155.184 (184.155.84.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.84.155.184 (184.155.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 09:59:09.356514 2026] [security2:error] [pid 20325:tid 20325] [client 34.84.155.184:41672] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||swaincustomdesigns.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "swaincustomdesigns.com"] [uri "/z9x8c7v6b5-debug-trigger-swaincustomdesigns.com"] [unique_id "ar-4rSuNST4AYsU_15q0PQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 13:22:42
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.84.155.184 (184.155.84.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.155.184 (184.155.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 09:22:35.608106 2026] [security2:error] [pid 6181:tid 6181] [client 34.84.155.184:60096] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.wildlandconservancy.com"] [uri "/js../.env"] [unique_id "ar-wG9j9jlqFnE6o-yvPVQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 10:50:45
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.84.155.184 (184.155.84.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.155.184 (184.155.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 06:50:39.860249 2026] [security2:error] [pid 31926:tid 31926] [client 34.84.155.184:45310] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.transcapitalsolutions.com"] [uri "/.env.php.bak"] [unique_id "ar-Mf5hYaDJAPybId7zddAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 10:35:14
(15 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.84.155.184 (184.155.84.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.84.155.184 (184.155.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 06:35:07.922650 2026] [security2:error] [pid 3134:tid 3134] [client 34.84.155.184:51368] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||sekizinci.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "sekizinci.com"] [uri "/z9x8c7v6b5-debug-trigger-sekizinci.com"] [unique_id "ar-I2xAHO-G9Ey-WmLFOKAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 10:05:20
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.84.155.184 (184.155.84.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.155.184 (184.155.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 06:05:15.354325 2026] [security2:error] [pid 27750:tid 27750] [client 34.84.155.184:48574] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.toys-alliance.com"] [uri "/.htpasswd"] [unique_id "ar-B28OU-0EHUHlrRtFWpAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-10-02 09:42:07
(15 hours ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-10-02 09:28:07
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.84.155.184 (184.155.84.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.155.184 (184.155.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 05:28:00.706783 2026] [security2:error] [pid 26316:tid 26316] [client 34.84.155.184:50116] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.thebeesgold.com"] [uri "/dist/.env"] [unique_id "ar95IGCcnAjyJfkVMBEMCgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack