๐ซ๐ฎ
sibahota
2026-10-01 15:31:12
(43 minutes ago)
34.84.235.32 - - [01/Oct/2026:15:31:07 +0000] demo.nidandiagnostic.com "GET /wz0v36d32kuq0e4eskrh HT ...
show more
34.84.235.32 - - [01/Oct/2026:15:31:07 +0000] demo.nidandiagnostic.com "GET /wz0v36d32kuq0e4eskrh HTTP/2.0" 403 26 0.000 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36" - - - "http://demo.nidandiagnostic.com"
34.84.235.32 - - [01/Oct/2026:15:31:08 +0000] demo.nidandiagnostic.com "GET /.htpasswd HTTP/2.0" 403 26 0.000 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.4; +https://openai.com/gptbot" - - - "http://demo.nidandiagnostic.com"
...
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-01 15:30:22
(44 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.84.235.32 (32.235.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.235.32 (32.235.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 11:30:16.326933 2026] [security2:error] [pid 12400:tid 12400] [client 34.84.235.32:51750] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.leighcunningham.com"] [uri "/.env.js"] [unique_id "ar58iOjaCeVQ4uraezsFLgAAADY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 14:52:18
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 34.84.235.32 (32.235.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.84.235.32 (32.235.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 10:52:10.790624 2026] [security2:error] [pid 21731:tid 21731] [client 34.84.235.32:40528] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||leothecolorman.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "leothecolorman.com"] [uri "/z9x8c7v6b5-debug-trigger-leothecolorman.com"] [unique_id "ar5zmtbg3xBYcdD54lPi4QAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐พ
Rizzy
2026-10-01 14:48:49
(1 hour ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ณ๐ฑ
Site.eu
2026-10-01 14:26:40
(1 hour ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-10-01 12:52:52
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.84.235.32 (32.235.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.235.32 (32.235.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 08:52:48.576073 2026] [security2:error] [pid 29440:tid 29440] [client 34.84.235.32:36674] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.mariekespresser.com"] [uri "/static../.env"] [unique_id "ar5XoAlBH6Afgh1VKw6_SAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
oralunal
2026-10-01 12:49:40
(3 hours ago)
IP banned by Fail2Ban in jail its-suss access.log mvfnds
...
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 12:30:39
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.84.235.32 (32.235.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.84.235.32 (32.235.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 08:30:31.642023 2026] [security2:error] [pid 30297:tid 30374] [client 34.84.235.32:57870] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||leadingedgesupply.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "leadingedgesupply.com"] [uri "/z9x8c7v6b5-debug-trigger-leadingedgesupply.com"] [unique_id "ar5SZ6e8fe_7LVluXsl7awAAAEY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 12:12:10
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.84.235.32 (32.235.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.84.235.32 (32.235.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 08:12:03.433491 2026] [security2:error] [pid 16069:tid 16069] [client 34.84.235.32:33840] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mnalabama.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mnalabama.com"] [uri "/z9x8c7v6b5-debug-trigger-mnalabama.com"] [unique_id "ar5OE_CrefS4HKCT8SddYwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-01 12:10:03
(4 hours ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-10-01 11:35:19
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.84.235.32 (32.235.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.84.235.32 (32.235.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 07:35:12.635627 2026] [security2:error] [pid 3377:tid 3377] [client 34.84.235.32:57290] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||missyallen.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "missyallen.com"] [uri "/z9x8c7v6b5-debug-trigger-missyallen.com"] [unique_id "ar5FcGf00DqvphJFXSI8GQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 11:17:47
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.84.235.32 (32.235.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.235.32 (32.235.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 07:17:41.417044 2026] [security2:error] [pid 5739:tid 5766] [client 34.84.235.32:34612] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.jrc3.com"] [uri "/admin/.env"] [unique_id "ar5BVcmcjWMRvuFyUgOT0AAAAJE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 10:28:40
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.84.235.32 (32.235.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.235.32 (32.235.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 06:28:34.084697 2026] [security2:error] [pid 4288:tid 4288] [client 34.84.235.32:51002] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.keeftone.com"] [uri "/.next/.env"] [unique_id "ar410rayERddtTo3va8hQAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-10-01 10:16:11
(5 hours ago)
Excessive 404/403 errors
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-10-01 09:50:47
(6 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.84.235.32 (32.235.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.84.235.32 (32.235.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 05:50:40.994856 2026] [security2:error] [pid 13992:tid 13992] [client 34.84.235.32:41118] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||lightningbug.farm|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "lightningbug.farm"] [uri "/rclone.conf"] [unique_id "ar4s8FlzAg03MFAtBheIngAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack