Anonymous
2026-09-22 08:58:19
(13 minutes ago)
34.87.178.248 - - [22/Sep/2026:16:58:16 +0800] "GET /z9x8c7v6b5-debug-trigger-nonsensemakers.com HTT ...
show more
34.87.178.248 - - [22/Sep/2026:16:58:16 +0800] "GET /z9x8c7v6b5-debug-trigger-nonsensemakers.com HTTP/1.1" 404 39532 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot)"
34.87.178.248 - - [22/Sep/2026:16:58:16 +0800] "GET /v1wbeokextc0qwrmyv59 HTTP/1.1" 404 39532 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)"
34.87.178.248 - - [22/Sep/2026:16:58:16 +0800] "GET /skapwq4n3ok5zdmw4w9g HTTP/1.1" 404 39532 "-" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)"
34.87.178.248 - - [22/Sep/2026:16:58:16 +0800] "POST /api/v1/validate/code HTTP/1.1" 404 47528 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)"
34.87.178.248 - - [22/Sep/2026:16:58:17 +0800] "POST /graphql HTTP/1.1" 404 39532 "https://nonsensemakers.com" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (K
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 08:55:43
(15 minutes ago)
(mod_security) mod_security (id:210730) triggered by 34.87.178.248 (248.178.87.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.87.178.248 (248.178.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 04:55:37.444919 2026] [security2:error] [pid 13219:tid 13390] [client 34.87.178.248:57708] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||oldnorthwestlandco.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "oldnorthwestlandco.com"] [uri "/z9x8c7v6b5-debug-trigger-oldnorthwestlandco.com"] [unique_id "arJCiaoZyS1wwSkuu3QkiwAAAZM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 08:37:18
(34 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.87.178.248 (248.178.87.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.178.248 (248.178.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 04:37:15.076393 2026] [security2:error] [pid 19203:tid 19203] [client 34.87.178.248:39162] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "robtown.com"] [uri "/build/.env"] [unique_id "arI-O_CRY384g_GWqFtazAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
rh24
2026-09-22 08:31:58
(39 minutes ago)
(badbots) Bad bot user-agent [redacted] from 34.87.178.248 (SG/Singapore/248.178.87.34.bc.googleuser ...
show more
(badbots) Bad bot user-agent [redacted] from 34.87.178.248 (SG/Singapore/248.178.87.34.bc.googleusercontent.com)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-22 08:19:36
(51 minutes ago)
(mod_security) mod_security (id:210730) triggered by 34.87.178.248 (248.178.87.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.87.178.248 (248.178.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 04:19:30.636467 2026] [security2:error] [pid 2159:tid 2159] [client 34.87.178.248:53426] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||soviaenterprises.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "soviaenterprises.com"] [uri "/z9x8c7v6b5-debug-trigger-soviaenterprises.com"] [unique_id "arI6EgfZEAwQVkQroYQ9FQAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Starburst SysOp Team
2026-09-22 08:14:55
(56 minutes ago)
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encod ...
show more
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encoding/ /proxy/ /lock-token/ /content-range/ /if/ /x-http-method-override/ /x-http-method/ /x-method-override/ /x-middleware-subrequest/ /expect/" at TX:header_name_920450_x-middleware-subrequest. (920450-mnz6-1)
show less
Bad Web Bot
๐ซ๐ท
masterguru
2026-09-22 08:10:27
(1 hour ago)
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encod ...
show more
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encoding/ /proxy/ /lock-token/ /content-range/ /if/ /x-http-method-override/ /x-http-method/ /x-method-override/ /x-middleware-subrequest/ /expect/" at TX:header_name_920450_x-middleware-subrequest. (920450-197)
show less
Bad Web Bot
๐ณ๐ฑ
Site.eu
2026-09-22 08:07:22
(1 hour ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-22 07:41:44
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 34.87.178.248 (248.178.87.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.87.178.248 (248.178.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 03:41:38.595402 2026] [security2:error] [pid 10816:tid 10834] [client 34.87.178.248:33830] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||tmsx2.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "tmsx2.com"] [uri "/z9x8c7v6b5-debug-trigger-tmsx2.com"] [unique_id "arIxMoqPBhPpa7d3o1CtnAAAAY0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
dot.mg
2026-09-22 07:32:05
(1 hour ago)
Bad behaviour
Web Spam
๐บ๐ธ
TPI-Abuse
2026-09-22 07:26:29
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 34.87.178.248 (248.178.87.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.87.178.248 (248.178.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 03:26:22.603956 2026] [security2:error] [pid 27055:tid 27055] [client 34.87.178.248:48016] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||unified-dispatch.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "unified-dispatch.com"] [uri "/z9x8c7v6b5-debug-trigger-unified-dispatch.com"] [unique_id "arItntDtu8CzkQdm4TsgVgAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-22 07:23:39
(1 hour ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐บ๐ธ
[email protected]
2026-09-22 07:22:02
(1 hour ago)
CrowdSec ban: crowdsecurity/http-admin-interface-probing (duration: 71h59m52s)
Web App Attack
๐ฎ๐น
VHosting
2026-09-22 07:20:04
(1 hour ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 07:07:16
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.87.178.248 (248.178.87.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.87.178.248 (248.178.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 03:07:10.293444 2026] [security2:error] [pid 253725:tid 253725] [client 34.87.178.248:44360] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||williamfitzsimmons.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "williamfitzsimmons.com"] [uri "/z9x8c7v6b5-debug-trigger-williamfitzsimmons.com"] [unique_id "arIpHu5PBdhcd2_rZH6P7AAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack