๐ช๐ธ
masterguru
2026-10-01 15:24:57
(12 hours ago)
Inbound Anomaly Score Exceeded (Total Score: 5). Operator GE matched 5 at TX:anomaly_score. (949110- ...
show more
Inbound Anomaly Score Exceeded (Total Score: 5). Operator GE matched 5 at TX:anomaly_score. (949110-122)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-01 15:14:01
(12 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.84.228.70 (70.228.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.84.228.70 (70.228.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 11:13:53.769419 2026] [security2:error] [pid 1602:tid 1602] [client 34.84.228.70:48258] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.plazacristal.com|F|2"] [data ".plazacristal.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.plazacristal.com"] [uri "/z9x8c7v6b5-debug-trigger-mail.plazacristal.com"] [unique_id "ar54seVSLdieTEUkXgzgcgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-10-01 14:58:29
(12 hours ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.84.228.70 (JP/Japan/70.228.84.34.b ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.84.228.70 (JP/Japan/70.228.84.34.bc.googleusercontent.com): 2 in the last 3600 secs (0-196)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-01 14:52:00
(13 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.84.228.70 (70.228.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.84.228.70 (70.228.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 10:51:52.757609 2026] [security2:error] [pid 17780:tid 17780] [client 34.84.228.70:57120] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||samuelpaley.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "samuelpaley.com"] [uri "/z9x8c7v6b5-debug-trigger-samuelpaley.com"] [unique_id "ar5ziONSUpTkRkL94_11IwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-01 14:34:22
(13 hours ago)
[ti-14al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 34. ...
show more
[ti-14al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 34.84.228.70 - - [01/Oct/2026:16:34:21 +0200] "GET /.htpasswd HTTP/1.1" 403 521 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)"
...
show less
Bad Web Bot
Web App Attack
๐ฌ๐ง
Shadymint
2026-10-01 14:32:49
(13 hours ago)
url probing from IP marked as abusive
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 14:31:37
(13 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.84.228.70 (70.228.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.84.228.70 (70.228.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 10:31:31.516580 2026] [security2:error] [pid 5851:tid 5851] [client 34.84.228.70:33818] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.purelywhimsical.com|F|2"] [data ".purelywhimsical.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.purelywhimsical.com"] [uri "/z9x8c7v6b5-debug-trigger-www.purelywhimsical.com"] [unique_id "ar5uwxHFUTpGBtaPMFLsbgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ฌ
simpeg-adm.bandung.go.id
2026-10-01 14:10:57
(13 hours ago)
01/Oct/2026:14:10:56 +0000;34.84.228.70;"/rbwf0464bya539fcislx"
01/Oct/2026:14:10:56 +0000;34.84.228 ...
show more
01/Oct/2026:14:10:56 +0000;34.84.228.70;"/rbwf0464bya539fcislx"
01/Oct/2026:14:10:56 +0000;34.84.228.70;"/dist/manifest.json"
01/Oct/2026:14:10:56 +0000;34.84.228.70;"/z9x8c7v6b5-debug-trigger-vendors.rochealphotography.com"
01/Oct/2026:14:10:56 +0000;34.84.228.70;"/lib/terminal-xhr.php"
01/Oct/2026:14:10:56 +0000;34.84.228.70;"/dist/.vite/manifest.json"
01/Oct/2026:14:10:56 +0000;34.84.228.70;"/mjonwvardkcvy8may5vo"
01/Oct/2026:14:10:56 +0000;34.84.228.70;"/.vite/manifest.json"
...
show less
Web Spam
Brute-Force
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-10-01 14:01:51
(13 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-01 14:00:37
(13 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.84.228.70 (70.228.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.84.228.70 (70.228.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 10:00:32.878396 2026] [security2:error] [pid 32513:tid 32525] [client 34.84.228.70:47198] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||salvoni.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "salvoni.com"] [uri "/z9x8c7v6b5-debug-trigger-salvoni.com"] [unique_id "ar5ngHoumoIfjoCWbzEtxAAAAEg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-01 14:00:06
(13 hours ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-10-01 13:40:04
(14 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.84.228.70 (70.228.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.84.228.70 (70.228.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 09:39:58.913457 2026] [security2:error] [pid 5881:tid 5881] [client 34.84.228.70:55732] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.pembrokefinance.com|F|2"] [data ".pembrokefinance.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.pembrokefinance.com"] [uri "/z9x8c7v6b5-debug-trigger-mail.pembrokefinance.com"] [unique_id "ar5irjR7g2pxIfi6Tda4CwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-10-01 13:31:21
(14 hours ago)
excessive HTTP 404 errors
Bad Web Bot
๐ซ๐ท
dynamix
2026-10-01 13:22:28
(14 hours ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 13:20:11
(14 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.84.228.70 (70.228.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.84.228.70 (70.228.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 09:20:02.793954 2026] [security2:error] [pid 3408:tid 3408] [client 34.84.228.70:60178] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.albertmassaad.com|F|2"] [data ".albertmassaad.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.albertmassaad.com"] [uri "/z9x8c7v6b5-debug-trigger-www.albertmassaad.com"] [unique_id "ar5eArUzU0XTgCO5lEL2PQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack