๐บ๐ธ
TPI-Abuse
2026-10-03 07:43:22
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.95.239.56 (56.239.95.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.95.239.56 (56.239.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 03 03:43:16.134743 2026] [security2:error] [pid 19793:tid 19793] [client 34.95.239.56:50980] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.loudenlow.com"] [uri "/css../.env"] [unique_id "asCyFJM4X_A3f7swxq68gQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-03 07:25:41
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 34.95.239.56 (56.239.95.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.95.239.56 (56.239.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 03 03:25:33.818167 2026] [security2:error] [pid 23349:tid 23349] [client 34.95.239.56:45968] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.thebumans.com|F|2"] [data ".thebumans.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.thebumans.com"] [uri "/z9x8c7v6b5-debug-trigger-www.thebumans.com"] [unique_id "asCt7drX-frzX5abf9CmlwAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-03 05:57:46
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 34.95.239.56 (56.239.95.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.95.239.56 (56.239.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 03 01:57:42.597640 2026] [security2:error] [pid 3555:tid 3760] [client 34.95.239.56:45102] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.thecomputergreek.com|F|2"] [data ".thecomputergreek.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.thecomputergreek.com"] [uri "/z9x8c7v6b5-debug-trigger-www.thecomputergreek.com"] [unique_id "asCZVpM2bKfvxn-0OndVlwAAARA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
TheDjRider
2026-10-03 04:36:04
(4 days ago)
CrowdSec detected Web application reconnaissance. Scenario: crowdsecurity/http-probing. Automatic ba ...
show more
CrowdSec detected Web application reconnaissance. Scenario: crowdsecurity/http-probing. Automatic ban triggered. Detection time (UTC): 2026-10-03T04:36:02.32310804Z. Context: http_status=404
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-03 02:34:03
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.95.239.56 (56.239.95.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.95.239.56 (56.239.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 22:33:55.958668 2026] [security2:error] [pid 18937:tid 18937] [client 34.95.239.56:57108] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.the-it-man.com"] [uri "/.htpasswd"] [unique_id "asBpk5p_8T8n9VRpzeXn2gAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
H24
2026-10-03 02:10:03
(4 days ago)
/@fs/..%2f..%2f..%2f..%2f..%2froot/.env /dist../.env /secrets.env /credentials.json /secrets.json /l ...
show more
/@fs/..%2f..%2f..%2f..%2f..%2froot/.env /dist../.env /secrets.env /credentials.json /secrets.json /lib/terminal-xhr.php /@fs/.env /build../.env /.git/HEAD /.git/config
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-03 00:00:32
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 34.95.239.56 (56.239.95.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.95.239.56 (56.239.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 20:00:25.094751 2026] [security2:error] [pid 28795:tid 28795] [client 34.95.239.56:40242] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.rotarymagnetics.com|F|2"] [data ".rotarymagnetics.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.rotarymagnetics.com"] [uri "/z9x8c7v6b5-debug-trigger-www.rotarymagnetics.com"] [unique_id "asBFmdCKXq-qmymsu8YzcQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-02 21:29:58
(4 days ago)
malicious scanning tool activity
Web App Attack
๐ณ๐ฑ
Site.eu
2026-10-02 20:52:36
(4 days ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-10-02 19:44:52
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 34.95.239.56 (56.239.95.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.95.239.56 (56.239.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 15:44:45.146400 2026] [security2:error] [pid 8624:tid 8624] [client 34.95.239.56:38482] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.jbcllcnet.com|F|2"] [data ".jbcllcnet.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.jbcllcnet.com"] [uri "/z9x8c7v6b5-debug-trigger-www.jbcllcnet.com"] [unique_id "asAJrUG9E5WMvK4MpZDKHAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 19:13:51
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 34.95.239.56 (56.239.95.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.95.239.56 (56.239.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 15:13:45.077598 2026] [security2:error] [pid 12011:tid 12011] [client 34.95.239.56:36940] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||thecrimsonpirate.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "thecrimsonpirate.com"] [uri "/z9x8c7v6b5-debug-trigger-thecrimsonpirate.com"] [unique_id "asACacrR-2_b3o_uODT79AAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-02 11:30:37
(5 days ago)
git/env leak probe
Web App Attack
๐ฌ๐ง
consul.to
2026-10-02 11:23:04
(5 days ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 10:32:48
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 34.95.239.56 (56.239.95.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.95.239.56 (56.239.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 06:32:45.411337 2026] [security2:error] [pid 14743:tid 14743] [client 34.95.239.56:40500] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||thegrousewoods.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "thegrousewoods.com"] [uri "/z9x8c7v6b5-debug-trigger-thegrousewoods.com"] [unique_id "ar-ITSagxTmpefU7dt9JhwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 09:44:49
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 34.95.239.56 (56.239.95.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.95.239.56 (56.239.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 05:44:41.658258 2026] [security2:error] [pid 465:tid 465] [client 34.95.239.56:50880] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||portlunchgroup.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "portlunchgroup.com"] [uri "/z9x8c7v6b5-debug-trigger-portlunchgroup.com"] [unique_id "ar99CYDyzgy-6tzpKjpwNAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack