πΊπΈ
TPI-Abuse
2026-09-30 14:51:01
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.85.92.23 (23.92.85.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.85.92.23 (23.92.85.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 10:50:55.265685 2026] [security2:error] [pid 10148:tid 10148] [client 34.85.92.23:58038] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.mikeneame.com"] [uri "/.env.js"] [unique_id "ar0hz07JQbEUR_uzYJpG2QAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Savvii
2026-09-30 14:39:44
(2 hours ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
πͺπΈ
masterguru
2026-09-30 14:23:42
(2 hours ago)
Inbound Anomaly Score Exceeded (Total Score: 5). Operator GE matched 5 at TX:anomaly_score. (949110- ...
show more
Inbound Anomaly Score Exceeded (Total Score: 5). Operator GE matched 5 at TX:anomaly_score. (949110-122)
show less
Hacking
πΊπΈ
TPI-Abuse
2026-09-30 14:15:36
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.85.92.23 (23.92.85.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.85.92.23 (23.92.85.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 10:15:32.369634 2026] [security2:error] [pid 24961:tid 24961] [client 34.85.92.23:54522] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.michaelward.com|F|2"] [data ".michaelward.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.michaelward.com"] [uri "/z9x8c7v6b5-debug-trigger-www.michaelward.com"] [unique_id "ar0ZhAj8YSOubl4Nc4B7ZwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-30 13:46:31
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.85.92.23 (23.92.85.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.85.92.23 (23.92.85.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 09:46:23.429977 2026] [security2:error] [pid 15586:tid 15586] [client 34.85.92.23:37524] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||joepaladino.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "joepaladino.com"] [uri "/z9x8c7v6b5-debug-trigger-joepaladino.com"] [unique_id "ar0Sr8FCusMQgSXc6z7oewAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-30 13:07:05
(4 hours ago)
Automated web scanner. Requested suspicious paths: /dist/.vite/manifest.json | /build/manifest.json ...
show more
Automated web scanner. Requested suspicious paths: /dist/.vite/manifest.json | /build/manifest.json | /dist/manifest.json | /.vite/manifest.json. UTC: 2026-09-30 12:53:10.
show less
Web App Attack
π²πΎ
Rizzy
2026-09-30 13:01:10
(4 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-30 12:45:33
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.85.92.23 (23.92.85.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.85.92.23 (23.92.85.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 08:45:30.063795 2026] [security2:error] [pid 23379:tid 23379] [client 34.85.92.23:50266] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.michaelholdengc.com"] [uri "/media../.env"] [unique_id "ar0Earpvk2zhRru-jQmopwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
consul.to
2026-09-30 11:44:42
(5 hours ago)
Web attack/malicious scanning detected
Web App Attack
πΈπ¬
Cloudkul Cloudkul
2026-09-30 11:11:59
(6 hours ago)
Attempted Not Found (404 status code) requests on our application, more than 30% of their total requ ...
show more
Attempted Not Found (404 status code) requests on our application, more than 30% of their total requests.
show less
Brute-Force
Web App Attack
π«π·
dynamix
2026-09-30 10:01:29
(7 hours ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-09-30 09:53:20
(7 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
πΊπΈ
OceanTreasure
2026-09-30 07:10:57
(10 hours ago)
tcp/8443; Unsolicited SYN to a port that has never been offered on this address (closed, no service ...
show more
tcp/8443; Unsolicited SYN to a port that has never been offered on this address (closed, no service ever) @ 2026-09-30T07:06:26Z
show less
Port Scan
π¨π¦
polycoda
2026-09-30 07:06:41
(10 hours ago)
AutoBlock: π‘ Port Scan (Non Decay-Based)
Port Scan