🇺🇸
TPI-Abuse
2026-09-13 13:55:58
(44 minutes ago)
(mod_security) mod_security (id:210730) triggered by 35.187.176.248 (248.176.187.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.187.176.248 (248.176.187.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 09:55:46.878787 2026] [security2:error] [pid 29366:tid 29366] [client 35.187.176.248:44584] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||rendermatrix.com|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "rendermatrix.com"] [uri "/host.key"] [unique_id "aqarYuauGd_3dFYYXCAyJAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇷🇴
clauss
2026-09-13 13:54:07
(46 minutes ago)
35.187.176.248 - - [13/Sep/2026:16:54:06 +0300] "GET /secrets.yml HTTP/2.0" 301 0 "-" "Mozilla/5.0 ( ...
show more
35.187.176.248 - - [13/Sep/2026:16:54:06 +0300] "GET /secrets.yml HTTP/2.0" 301 0 "-" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)"
35.187.176.248 - - [13/Sep/2026:16:54:06 +0300] "GET /firebase-adminsdk.json HTTP/2.0" 301 0 "-" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)"
...
show less
Web App Attack
🇫🇷
masterguru
2026-09-13 13:34:53
(1 hour ago)
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encod ...
show more
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encoding/ /proxy/ /lock-token/ /content-range/ /if/ /x-http-method-override/ /x-http-method/ /x-method-override/ /x-middleware-subrequest/ /expect/" at TX:header_name_920450_x-middleware-subrequest. (920450-201)
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-13 13:30:05
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.187.176.248 (248.176.187.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.187.176.248 (248.176.187.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 09:30:01.159311 2026] [security2:error] [pid 3756:tid 3756] [client 35.187.176.248:37806] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "redweddingnapkins.com"] [uri "/%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env"] [unique_id "aqalWXvK2V7GrGo-UMJ-nAAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-13 13:22:29
(1 hour ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
🇫🇷
masterguru
2026-09-13 13:11:51
(1 hour ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-195)
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 13:09:11
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 35.187.176.248 (248.176.187.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.187.176.248 (248.176.187.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 09:09:05.749264 2026] [security2:error] [pid 17201:tid 17201] [client 35.187.176.248:51738] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||realstorybooks.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "realstorybooks.com"] [uri "/rclone.conf"] [unique_id "aqagcSeonq3Al-e7_Zr6VgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
CoreTech srl
2026-09-13 12:58:56
(1 hour ago)
cloudlinux2 fail2ban: 2026-09-13 14:55:09,042 fail2ban.filter [1591]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-13 14:55:09,042 fail2ban.filter [1591]: INFO [plesk-modsecurity] Found 49.206.39.1 - 2026-09-13 14:55:08cloudlinux2 fail2ban: 2026-09-13 14:55:32,378 fail2ban.filter [1591]: INFO [plesk-modsecurity] Found 34.85.170.84 - 2026-09-13 14:55:32cloudlinux2 fail2ban: 2026-09-13 14:55:32,570 fail2ban.filter [1591]: INFO [plesk-modsecurity] Found 34.85.170.84 - 2026-09-13 14:55:32cloudlinux2 fail2ban: 2026-09-13 14:55:32,399 fail2ban.filter [1591]: INFO [plesk-modsecurity] Found 34.85.170.84 - 2026-09-13 14:55:32cloudlinux2 fail2ban: 2026-09-13 14:55:32,632 fail2ban.actions [1591]: NOTICE [plesk-modsecurity] Ban 34.85.170.84cloudlinux2 fail2ban: 2026-09-13 14:55:32,638 fail2ban.filter [1591]: INFO [recidive] Found 34.85.170.84 - 2026-09-13 14:55:32cloudlinux2 fail2ban: 2026-09-13 14:55:47,260 fail2ban.actions [1591]: NOTICE [plesk-modsecurity] Unban 83.110.188.71cloudlinux2 fail2ban: 2026-09-13 14:56:12,930 fail2ban.fi
show less
Brute-Force
🇺🇸
TPI-Abuse
2026-09-13 12:52:05
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.187.176.248 (248.176.187.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.187.176.248 (248.176.187.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 08:51:58.583353 2026] [security2:error] [pid 1129822:tid 1129822] [client 35.187.176.248:39578] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "raystransmission.com"] [uri "/%2e%2e/.env"] [unique_id "aqacbu2VMQ4gf4OkYXJIbQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
cmbplf
2026-09-13 12:45:32
(1 hour ago)
910 requests with url.path *.env
350 requests with url.path */@fs/*
150 requests with url.path */ ...
show more
910 requests with url.path *.env
350 requests with url.path */@fs/*
150 requests with url.path */proc/*
show less
Brute-Force
Bad Web Bot
🇩🇪
NewGastroline
2026-09-13 12:45:12
(1 hour ago)
Malicious request blocked by CrowdSec on gastro-prod1.boreus.de
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 12:34:51
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.187.176.248 (248.176.187.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.187.176.248 (248.176.187.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 08:34:43.062427 2026] [security2:error] [pid 29311:tid 29311] [client 35.187.176.248:56248] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "randomgroovemusic.com"] [uri "/%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env"] [unique_id "aqaYY-ebBWm2lTS6gHP1bgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
maxpower
2026-09-13 12:32:16
(2 hours ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 35.187.176.248 (BE/Belgium/248.176.187.3 ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 35.187.176.248 (BE/Belgium/248.176.187.35.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 35.187.176.248 - - [13/Sep/2026:14:32:13 +0200] "GET /@fs/home/ubuntu/.aws/credentials?raw?? HTTP/2.0" 200 12117 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)" "-" host=ramsesconsulting.com
show less
Port Scan
🇹🇭
thaizone.com
2026-09-13 12:24:18
(2 hours ago)
Hacking attempts against websites (D1) #1
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-13 12:19:09
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.187.176.248 (248.176.187.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.187.176.248 (248.176.187.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 08:19:05.608374 2026] [security2:error] [pid 8054:tid 8054] [client 35.187.176.248:53512] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||rahmanou.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "rahmanou.com"] [uri "/rclone.conf"] [unique_id "aqaUuWL-LGF8fsf5PZlW2QAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack