(mod_security) mod_security (id:210831) triggered by 34.85.198.130 (130.198.85.34.bc.googleuserconte ...
show more(mod_security) mod_security (id:210831) triggered by 34.85.198.130 (130.198.85.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 12:16:49.703786 2026] [security2:error] [pid 8417:tid 8417] [client 34.85.198.130:57412] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||greed.wisk.org|F|4"] [data "Microsoft URL"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "greed.wisk.org"] [uri "/v1/actuator/env"] [unique_id "aibq8eHZnZjIO8w58A6PMwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
Multiple web server 400 error codes from same source ip
Web App Attack
Anonymous
(mod_security) mod_security triggered on hostname [redacted] 34.85.198.130 (US/United States/130.198 ...
show more(mod_security) mod_security triggered on hostname [redacted] 34.85.198.130 (US/United States/130.198.85.34.bc.googleusercontent.com)
show less
Aggressive web search of vulnerable pages: /phpinfo.php /info.php /php.php /test.php /debug.php /php ...
show moreAggressive web search of vulnerable pages: /phpinfo.php /info.php /php.php /test.php /debug.php /phptest.php /admin/phpinfo.php /api/phpinfo.ph ...
show less
[Mon Jun 08 11:53:11.319011 2026] [php:error] [pid 1712051] [client 34.85.198.130:50878] script '/va ...
show more[Mon Jun 08 11:53:11.319011 2026] [php:error] [pid 1712051] [client 34.85.198.130:50878] script '/var/www/html/campus-perpignan/phpinfo.php' not found or unable to stat
[Mon Jun 08 11:53:11.327558 2026] [php:error] [pid 1712052] [client 34.85.198.130:50892] script '/var/www/html/campus-perpignan/info.php' not found or unable to stat
[Mon Jun 08 11:53:11.362647 2026] [php:error] [pid 1711931] [client 34.85.198.130:50896] script '/var/www/html/campus-perpignan/php.php' not found or unable to stat
[Mon Jun 08 11:53:11.400816 2026] [php:error] [pid 1712050] [client 34.85.198.130:50910] script '/var/www/html/campus-perpignan/test.php' not found or unable to stat
[Mon Jun 08 11:53:11.411437 2026] [php:error] [pid 1711934] [client 34.85.198.130:50918] script '/var/www/html/campus-perpignan/debug.php' not found or unable to stat
...
show less
[MonJun0806:18:13.1147062026][security2:error][pid623714:tid623874][client34.85.198.130:0]ModSecurit ...
show more[MonJun0806:18:13.1147062026][security2:error][pid623714:tid623874][client34.85.198.130:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.9\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"jrtradeinnovation.ch\"][uri\"/actuator/auditevents\"][unique_id\"aiZChcj4WZUiiofbWEZJcgAAAJU\"]
show less
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 34.85.198.130 (US/Un ...
show more(apache-useragents) Failed apache-useragents trigger with match [redacted] from 34.85.198.130 (US/United States/130.198.85.34.bc.googleusercontent.com)
show less