πΊπΈ
TPI-Abuse
2026-09-29 21:06:51
(47 minutes ago)
(mod_security) mod_security (id:210492) triggered by 8.234.202.212 (212.202.234.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.234.202.212 (212.202.234.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 17:06:45.573371 2026] [security2:error] [pid 15218:tid 15218] [client 8.234.202.212:45284] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thinksite.net"] [uri "/.env.staging"] [unique_id "arwoZVxQvJmRY9G84KXuggAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
Apache
2026-09-29 20:19:56
(1 hour ago)
(mod_security) mod_security (id:930130) triggered by 8.234.202.212 (US/United States/212.202.234.8.b ...
show more
(mod_security) mod_security (id:930130) triggered by 8.234.202.212 (US/United States/212.202.234.8.bc.googleusercontent.com): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
SSH
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-29 19:47:03
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 8.234.202.212 (212.202.234.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 8.234.202.212 (212.202.234.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 15:46:57.037692 2026] [security2:error] [pid 30468:tid 30468] [client 8.234.202.212:43980] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.test.flightclaimservices.com|F|2"] [data ".test.flightclaimservices.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.test.flightclaimservices.com"] [uri "/z9x8c7v6b5-debug-trigger-www.test.flightclaimservices.com"] [unique_id "arwVsUv0FoH4-zZAglskIgAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
Aetherweb Ark
2026-09-29 19:33:30
(2 hours ago)
(mod_security) mod_security (id:949110) triggered by 8.234.202.212 (US/United States/212.202.234.8.b ...
show more
(mod_security) mod_security (id:949110) triggered by 8.234.202.212 (US/United States/212.202.234.8.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-29 18:55:23
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 8.234.202.212 (212.202.234.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 8.234.202.212 (212.202.234.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 14:55:18.776091 2026] [security2:error] [pid 6878:tid 6878] [client 8.234.202.212:43576] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.test.mathewyoung.com|F|2"] [data ".test.mathewyoung.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.test.mathewyoung.com"] [uri "/z9x8c7v6b5-debug-trigger-www.test.mathewyoung.com"] [unique_id "arwJluvf3H0CuTt0fk7OWgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¨π¦
Anytech
2026-09-29 18:48:30
(3 hours ago)
Blocked by Conn-Monitor: env-probing
Web App Attack
Hacking
πΊπΈ
interbiznw.com
2026-09-29 18:44:31
(3 hours ago)
malicious-web-requests-vulnerability-scanning
Hacking
Brute-Force
Exploited Host
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-29 18:14:31
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 8.234.202.212 (212.202.234.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 8.234.202.212 (212.202.234.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 14:14:26.720581 2026] [security2:error] [pid 6530:tid 6530] [client 8.234.202.212:33288] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||10bestrestaurants.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "10bestrestaurants.com"] [uri "/z9x8c7v6b5-debug-trigger-10bestrestaurants.com"] [unique_id "arwAAhfWVnM34MD6DmEKvAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Savvii
2026-09-29 17:48:01
(4 hours ago)
20 attempts against mh-misbehave-ban on frost
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-29 17:28:38
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 8.234.202.212 (212.202.234.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 8.234.202.212 (212.202.234.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 13:28:32.134680 2026] [security2:error] [pid 25449:tid 25449] [client 8.234.202.212:37152] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||cajunfriedturkey.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "cajunfriedturkey.com"] [uri "/z9x8c7v6b5-debug-trigger-cajunfriedturkey.com"] [unique_id "arv1QP46CcR35BqdORk9JgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Site.eu
2026-09-29 17:16:47
(4 hours ago)
Excessive multi-domain requests
Brute-Force
π³π±
e.fierstra
2026-09-29 17:04:44
(4 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
π³π±
WeCloudit-Anti-Abuse
2026-09-29 16:59:44
(4 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
π©πͺ
rh24
2026-09-29 16:55:21
(4 hours ago)
(badbots) Bad bot user-agent [redacted] from 8.234.202.212 (US/United States/212.202.234.8.bc.google ...
show more
(badbots) Bad bot user-agent [redacted] from 8.234.202.212 (US/United States/212.202.234.8.bc.googleusercontent.com)
show less
Hacking
π«π·
Sorgin Informatique
2026-09-29 16:51:55
(5 hours ago)
tee-88 : Bloc AI bots=>/1u1nvl4eicazru3areyo(ai.)
Hacking