๐บ๐ธ
TPI-Abuse
2026-09-30 00:29:20
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.89.149.241 (241.149.89.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.89.149.241 (241.149.89.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 20:29:15.117281 2026] [security2:error] [pid 4789:tid 4789] [client 34.89.149.241:48816] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.cidv.com"] [uri "/@fs/var/task/.env"] [unique_id "arxX291Lp83ooXjgEjFKEwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
EGP Abuse Dept
2026-09-30 00:22:08
(1 hour ago)
Scanning for web/db/file exploits on www.clipsfotografie.nl
SQL Injection
Bad Web Bot
Web App Attack
๐ฉ๐ช
pscriptos
2026-09-30 00:05:30
(1 hour ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐ฉ๐ช
SwinT
2026-09-30 00:00:17
(1 hour ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 23:54:53
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 34.89.149.241 (241.149.89.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.89.149.241 (241.149.89.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 19:54:48.292065 2026] [security2:error] [pid 32414:tid 32414] [client 34.89.149.241:48428] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.citizens-referendum.eu.vjrott.com|F|2"] [data ".citizens-referendum.eu.vjrott.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.citizens-referendum.eu.vjrott.com"] [uri "/z9x8c7v6b5-debug-trigger-www.citizens-referendum.eu.vjrott.com"] [unique_id "arxPyO5l1b2CuzuxNF9DZgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
COMAITE
2026-09-29 23:37:34
(1 hour ago)
Suspicious URL access.
Web App Attack
๐ง๐ช
cmbplf
2026-09-29 23:09:50
(2 hours ago)
4.557 requests from abuseipdb.com blacklisted IP (1yr8mos16h)
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-29 22:42:46
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.89.149.241 (241.149.89.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.89.149.241 (241.149.89.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 18:42:43.964614 2026] [security2:error] [pid 1708:tid 1708] [client 34.89.149.241:41564] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||creartest.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "creartest.com"] [uri "/z9x8c7v6b5-debug-trigger-creartest.com"] [unique_id "arw-4zQJztHORnMjQxZdnwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐น
nomzamo
2026-09-29 22:14:53
(3 hours ago)
Fail2Ban reported: nginx-badbots
Brute-Force
Anonymous
2026-09-29 22:06:01
(3 hours ago)
IP matched detection query more than 2 hosts and only bad rq long ban.
Brute-Force
Web App Attack
Hacking
Anonymous
2026-09-29 21:50:51
(3 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
๐ท๐ด
clauss
2026-09-29 21:50:30
(3 hours ago)
34.89.149.241 - - [30/Sep/2026:00:50:26 +0300] "GET /rclone.conf HTTP/2.0" 403 146 "-" "Mozilla/5.0 ...
show more
34.89.149.241 - - [30/Sep/2026:00:50:26 +0300] "GET /rclone.conf HTTP/2.0" 403 146 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)"
34.89.149.241 - - [30/Sep/2026:00:50:30 +0300] "GET /__vite_rsc_findSourceMapURL?filename=file:///root/.aws/credentials&environmentName=rsc HTTP/2.0" 301 0 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 21:48:58
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.89.149.241 (241.149.89.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.89.149.241 (241.149.89.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 17:48:53.597112 2026] [security2:error] [pid 2678:tid 2678] [client 34.89.149.241:36326] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||lopansri.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "lopansri.com"] [uri "/z9x8c7v6b5-debug-trigger-lopansri.com"] [unique_id "arwyRTEv1nLOEKRm19BwWQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 21:33:49
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.89.149.241 (241.149.89.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.89.149.241 (241.149.89.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 17:33:44.599517 2026] [security2:error] [pid 9431:tid 9431] [client 34.89.149.241:53920] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.client.jamesallenwalker.com|F|2"] [data ".client.jamesallenwalker.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.client.jamesallenwalker.com"] [uri "/z9x8c7v6b5-debug-trigger-www.client.jamesallenwalker.com"] [unique_id "arwuuDSaFoJLEEnVCblwfAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-29 20:33:52
(5 hours ago)
20 attempts against mh_ha-misbehave-ban on pf221107
Brute-Force
Bad Web Bot
Web App Attack