Anonymous
2026-10-03 06:10:01
(3 days ago)
suspicious request in access.log
Web App Attack
๐ฒ๐ฝ
octageeks.com
2026-10-03 04:17:16
(3 days ago)
Wordpress malicious attack:[octablocked]
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-03 03:22:41
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.90.44.65 (65.44.90.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.90.44.65 (65.44.90.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 23:22:34.702778 2026] [security2:error] [pid 8995:tid 8995] [client 34.90.44.65:40614] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "piratecostumesonline.com"] [uri "/@fs/app/.env.local"] [unique_id "asB0-pZWiSAOecqDy2TmyQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
robotstxt
2026-10-03 01:35:22
(3 days ago)
34.90.44.65 - - [03/Oct/2026:01:34:30 +0000] "GET /q7bcu7epjtqsujptg9zl HTTP/2.0" 403 189 "https://w ...
show more
34.90.44.65 - - [03/Oct/2026:01:34:30 +0000] "GET /q7bcu7epjtqsujptg9zl HTTP/2.0" 403 189 "https://www.wpvul.com/q7bcu7epjtqsujptg9zl" "Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)" "-" edge="34.90.44.65"
34.90.44.65 - - [03/Oct/2026:01:34:30 +0000] "GET /reset-password HTTP/2.0" 403 165 "https://www.wpvul.com/reset-password" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36" "-" edge="34.90.44.65"
34.90.44.65 - - [03/Oct/2026:01:34:30 +0000] "GET /admin HTTP/2.0" 403 165 "https://www.wpvul.com/admin" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36" "-" edge="34.90.44.65"
34.90.44.65 - - [03/Oct/2026:01:34:30 +0000] "GET /signup HTTP/2.0" 403 165 "https://www.wpvul.com/signup" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36" "-" edge="34.90.44.65"
34.90.44.65 - - [03/Oct/2026:
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-03 01:31:36
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 34.90.44.65 (65.44.90.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.90.44.65 (65.44.90.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 21:31:33.156755 2026] [security2:error] [pid 4460:tid 4460] [client 34.90.44.65:44620] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||sonnyvo.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "sonnyvo.com"] [uri "/z9x8c7v6b5-debug-trigger-sonnyvo.com"] [unique_id "asBa9atSsxWoov9JeWFZIgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-10-02 22:52:40
(3 days ago)
Web attack/malicious scanning detected
Web App Attack
๐ช๐ธ
robotstxt
2026-10-02 22:34:01
(3 days ago)
34.90.44.65 - - [02/Oct/2026:22:32:57 +0000] "GET /build/manifest.json HTTP/2.0" 403 20064 "https:// ...
show more
34.90.44.65 - - [02/Oct/2026:22:32:57 +0000] "GET /build/manifest.json HTTP/2.0" 403 20064 "https://wpvulnerability.com/build/manifest.json" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Mobile Safari/537.36 EdgA/153.0.0.0" "-" edge="34.90.44.65"
34.90.44.65 - - [02/Oct/2026:22:32:57 +0000] "GET /dist/manifest.json HTTP/2.0" 403 20064 "https://wpvulnerability.com/dist/manifest.json" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Mobile Safari/537.36 EdgA/153.0.0.0" "-" edge="34.90.44.65"
34.90.44.65 - - [02/Oct/2026:22:32:57 +0000] "GET /.vite/manifest.json HTTP/2.0" 403 20064 "https://wpvulnerability.com/.vite/manifest.json" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Mobile Safari/537.36 EdgA/153.0.0.0" "-" edge="34.90.44.65"
34.90.44.65 - - [02/Oct/2026:22:32:57 +0000] "GET /z9x8c7v6b5-debug-trigger-wpvulnerability.com HTTP/2.0" 403 20393 "https:
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 18:26:24
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 34.90.44.65 (65.44.90.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.90.44.65 (65.44.90.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 14:26:16.985747 2026] [security2:error] [pid 26100:tid 26244] [client 34.90.44.65:45250] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.thebiglies.com|F|2"] [data ".thebiglies.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.thebiglies.com"] [uri "/z9x8c7v6b5-debug-trigger-www.thebiglies.com"] [unique_id "ar_3SJSJoAc0jCOmORQMegAAARA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-10-02 17:38:46
(4 days ago)
BAD BOT - Detected and Blocked.. Matched phrase "ccbot" at REQUEST_HEADERS:User-Agent. (1100000-193)
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-02 17:33:53
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 34.90.44.65 (65.44.90.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.90.44.65 (65.44.90.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 13:33:49.006121 2026] [security2:error] [pid 13944:tid 13944] [client 34.90.44.65:46304] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.wurkroom.biz.smartstylehair.com|F|2"] [data ".wurkroom.biz.smartstylehair.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.wurkroom.biz.smartstylehair.com"] [uri "/z9x8c7v6b5-debug-trigger-www.wurkroom.biz.smartstylehair.com"] [unique_id "ar_q_VoeWSxnbQBeXQQoNgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 17:08:11
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 34.90.44.65 (65.44.90.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.90.44.65 (65.44.90.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 13:08:05.902987 2026] [security2:error] [pid 23351:tid 23351] [client 34.90.44.65:53784] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.amybeam.com|F|2"] [data ".amybeam.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.amybeam.com"] [uri "/z9x8c7v6b5-debug-trigger-www.amybeam.com"] [unique_id "ar_k9RpLQMQx_7aW1du6DwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
robotstxt
2026-10-02 16:24:31
(4 days ago)
34.90.44.65 - - [02/Oct/2026:16:23:35 +0000] "GET /dist/.vite/manifest.json HTTP/2.0" 403 36396 "-" ...
show more
34.90.44.65 - - [02/Oct/2026:16:23:35 +0000] "GET /dist/.vite/manifest.json HTTP/2.0" 403 36396 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "34.90.44.65" edge="162.159.106.122"
34.90.44.65 - - [02/Oct/2026:16:23:37 +0000] "GET /.env.js HTTP/2.0" 403 2 "-" "Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)" "34.90.44.65" edge="104.22.148.30"
34.90.44.65 - - [02/Oct/2026:16:23:42 +0000] "GET /.dockerenv HTTP/2.0" 403 2 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1)" "34.90.44.65" edge="172.71.95.44"
34.90.44.65 - - [02/Oct/2026:16:23:44 +0000] "GET /.aws/credentials HTTP/2.0" 403 36393 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)" "34.90.44.65" edge="172.71.95.44"
34.90.44.65 - - [02/Oct/2026:16:23:44 +0000] "GET /.aws/config HTTP/2.0" 403 36393 "-" "Mozilla/5.0 (Macintosh; Int
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 15:36:24
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 34.90.44.65 (65.44.90.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.90.44.65 (65.44.90.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 11:36:17.799491 2026] [security2:error] [pid 10008:tid 10008] [client 34.90.44.65:53340] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||worshipconcert.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "worshipconcert.com"] [uri "/z9x8c7v6b5-debug-trigger-worshipconcert.com"] [unique_id "ar_PcfXzTMYFtZt3K4yJXgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-10-02 14:58:25
(4 days ago)
Excessive 404/403 errors
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-10-02 12:36:13
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 34.90.44.65 (65.44.90.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.90.44.65 (65.44.90.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 08:36:09.884935 2026] [security2:error] [pid 2513:tid 2513] [client 34.90.44.65:59832] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||test.fritsknuf.com|F|2"] [data ".fritsknuf.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "test.fritsknuf.com"] [uri "/z9x8c7v6b5-debug-trigger-test.fritsknuf.com"] [unique_id "ar-lOWWpxUaSAQSJHZ_VAgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack