๐ซ๐ท
raid3n09
2026-10-03 06:36:42
(2 days ago)
Automated malicious scan and unauthorized access attempt blocked.
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-03 05:18:06
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.89.243.14 (14.243.89.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.89.243.14 (14.243.89.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 03 01:17:59.239285 2026] [security2:error] [pid 19898:tid 19898] [client 34.89.243.14:55416] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||syscomprint.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "syscomprint.com"] [uri "/z9x8c7v6b5-debug-trigger-syscomprint.com"] [unique_id "asCQB3Y1arxPzmgjNgHzagAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-03 03:57:07
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.89.243.14 (14.243.89.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.89.243.14 (14.243.89.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 23:57:00.494049 2026] [security2:error] [pid 26577:tid 26577] [client 34.89.243.14:54758] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.swhowell.com|F|2"] [data ".swhowell.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.swhowell.com"] [uri "/z9x8c7v6b5-debug-trigger-www.swhowell.com"] [unique_id "asB9DLJVlz8omUsyDg4vawAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-03 03:39:56
(2 days ago)
34.89.243.14 - - [03/Oct/2026:03:39:55 +0000] "POST /cgi-bin/php?%ADd+allow_url_include%3d1+%ADd+aut ...
show more
34.89.243.14 - - [03/Oct/2026:03:39:55 +0000] "POST /cgi-bin/php?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input HTTP/2.0" 404 107 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)"
34.89.243.14 - - [03/Oct/2026:03:39:55 +0000] "POST /cgi-bin/php-cgi?-d+allow_url_include%3don+-d+auto_prepend_file%3dphp://input HTTP/2.0" 404 107 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-03 02:12:25
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.89.243.14 (14.243.89.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.89.243.14 (14.243.89.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 22:12:18.700621 2026] [security2:error] [pid 7947:tid 7947] [client 34.89.243.14:40270] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||technicallydental.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "technicallydental.com"] [uri "/z9x8c7v6b5-debug-trigger-technicallydental.com"] [unique_id "asBkghPMcKCrXnwPXpLOXAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-03 01:55:00
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.89.243.14 (14.243.89.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.89.243.14 (14.243.89.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 21:54:55.812068 2026] [security2:error] [pid 9106:tid 9106] [client 34.89.243.14:49632] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||tankservicesinc.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "tankservicesinc.com"] [uri "/z9x8c7v6b5-debug-trigger-tankservicesinc.com"] [unique_id "asBgb9c8BfF7s3MWw9OhnAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-03 01:34:51
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.89.243.14 (14.243.89.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.89.243.14 (14.243.89.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 21:34:46.477136 2026] [security2:error] [pid 32231:tid 32231] [client 34.89.243.14:48442] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.syndetec.com|F|2"] [data ".syndetec.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.syndetec.com"] [uri "/z9x8c7v6b5-debug-trigger-www.syndetec.com"] [unique_id "asBbtr8POwVFz4RBJYud0QAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
andypiper
2026-10-03 01:00:29
(2 days ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
๐ฌ๐ง
Apache
2026-10-03 00:51:44
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.89.243.14 (DE/Germany/14.243.89.34.bc.google ...
show more
(mod_security) mod_security (id:210492) triggered by 34.89.243.14 (DE/Germany/14.243.89.34.bc.googleusercontent.com): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
SSH
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-03 00:48:57
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.89.243.14 (14.243.89.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.89.243.14 (14.243.89.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 20:48:51.272564 2026] [security2:error] [pid 30167:tid 30191] [client 34.89.243.14:52756] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.plumeraproductions.com|F|2"] [data ".plumeraproductions.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.plumeraproductions.com"] [uri "/z9x8c7v6b5-debug-trigger-www.plumeraproductions.com"] [unique_id "asBQ8-21XwV6q2065g0uiwAAARU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
IVski.com
2026-10-03 00:16:24
(2 days ago)
IVski WAF | Next.js Server Action probe
Hacking
Brute-Force
Web App Attack
๐ซ๐ท
Rom74
2026-10-02 23:50:00
(2 days ago)
[Sat Oct 03 01:49:53.453965 2026] [security2:error] [pid 762082:tid 138913435858624] [client 34.89.2 ...
show more
[Sat Oct 03 01:49:53.453965 2026] [security2:error] [pid 762082:tid 138913435858624] [client 34.89.243.14:0] [client 34.89.243.14] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "teslogiciels.com"] [uri "/z9x8c7v6b5-debug-trigger-teslogiciels.com"] [unique_id "asBDIYiFwV8D69P7Y9HMRgAAABU"]
[Sat Oct 03 01:49:59.303680 2026] [security2:error] [pid 762083:tid 138913832134336] [client 34.89.243.14:0] [client 34.89.243.14] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anom
...
show less
Web App Attack
๐ฉ๐ช
LRob
2026-10-02 23:32:03
(2 days ago)
Crawler ignoring refusals | ua: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 ( ...
show more
Crawler ignoring refusals | ua: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36; compatibl | path: /lib/terminal-xhr.php
show less
Bad Web Bot
Anonymous
2026-10-02 23:06:03
(2 days ago)
Trying to access config files
Web App Attack
Anonymous
2026-10-02 22:44:38
(2 days ago)
Aggressive web scan
Web App Attack