๐บ๐ธ
TPI-Abuse
2026-09-22 01:34:26
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.189.181.27 (27.181.189.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.189.181.27 (27.181.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 21:34:22.270010 2026] [security2:error] [pid 17741:tid 17741] [client 35.189.181.27:49022] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.maffiniandbearce.com"] [uri "/.env.local"] [unique_id "arHbHkXIB8_oDte_3H6j8gAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 00:47:54
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.189.181.27 (27.181.189.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.189.181.27 (27.181.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 20:47:48.757877 2026] [security2:error] [pid 442:tid 442] [client 35.189.181.27:46284] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.theknowledgemaster.com|F|2"] [data ".theknowledgemaster.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.theknowledgemaster.com"] [uri "/z9x8c7v6b5-debug-trigger-mail.theknowledgemaster.com"] [unique_id "arHQNDGv6EAW14M_buOuTwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-22 00:44:59
(3 hours ago)
Aggressive web scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 00:29:13
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.189.181.27 (27.181.189.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.189.181.27 (27.181.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 20:29:06.318022 2026] [security2:error] [pid 14420:tid 14420] [client 35.189.181.27:36136] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "galaxyretro.com"] [uri "/.env.production"] [unique_id "arHL0sKOJJ8nvMRf5tuDkQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
robotstxt
2026-09-21 22:37:47
(5 hours ago)
35.189.181.27 - - [21/Sep/2026:22:37:26 +0000] "GET / HTTP/2.0" 403 60767 "https://outcomes10.com/" ...
show more
35.189.181.27 - - [21/Sep/2026:22:37:26 +0000] "GET / HTTP/2.0" 403 60767 "https://outcomes10.com/" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)" "-" edge="35.189.181.27"
35.189.181.27 - - [21/Sep/2026:22:37:26 +0000] "GET /z9x8c7v6b5-debug-trigger-outcomes10.com HTTP/2.0" 403 36719 "https://outcomes10.com/z9x8c7v6b5-debug-trigger-outcomes10.com" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)" "-" edge="35.189.181.27"
35.189.181.27 - - [21/Sep/2026:22:37:26 +0000] "GET /.aws/credentials HTTP/2.0" 403 36719 "https://outcomes10.com/.aws/credentials" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1)" "-" edge="35.189.181.27"
35.189.181.27 - - [21/Sep/2026:22:37:26 +0000] "GET /.aws/config HTTP/2.0" 403 36719 "https://outcomes10.com/.aws/config" "Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)" "-" edge="35.189.181.27"
35.189.181.27 - - [21/Sep/2026:22:37:27 +0000]
...
show less
Web App Attack
๐ง๐ช
cmbplf
2026-09-21 22:10:02
(5 hours ago)
127 requests with url.path */@fs/*
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-21 22:03:38
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.189.181.27 (27.181.189.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.189.181.27 (27.181.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 18:03:34.280209 2026] [security2:error] [pid 29518:tid 29518] [client 35.189.181.27:50348] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.pakistanvision.com"] [uri "/.git/HEAD"] [unique_id "arGptlkvGS-5c5CCNlKJKwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 21:41:16
(6 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.189.181.27 (27.181.189.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.189.181.27 (27.181.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 17:41:09.236224 2026] [security2:error] [pid 26601:tid 26601] [client 35.189.181.27:53166] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.paintingqueen.com|F|2"] [data ".paintingqueen.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.paintingqueen.com"] [uri "/z9x8c7v6b5-debug-trigger-www.paintingqueen.com"] [unique_id "arGkdelOgqYaXSXE-EMQLgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 20:49:05
(6 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.189.181.27 (27.181.189.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.189.181.27 (27.181.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 16:48:57.096006 2026] [security2:error] [pid 25331:tid 25331] [client 35.189.181.27:40336] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.outofthebluephotography.com|F|2"] [data ".outofthebluephotography.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.outofthebluephotography.com"] [uri "/z9x8c7v6b5-debug-trigger-www.outofthebluephotography.com"] [unique_id "arGYOcql_UhDAUXLTgVQlwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 19:59:12
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.189.181.27 (27.181.189.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.189.181.27 (27.181.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 15:59:07.350606 2026] [security2:error] [pid 18006:tid 18006] [client 35.189.181.27:59644] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.osmanbozkurt.com"] [uri "/build/.env"] [unique_id "arGMi5VWKWV9jbGUxA3NugAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
interbiznw.com
2026-09-21 19:39:31
(8 hours ago)
malicious-web-requests-vulnerability-scanning
Hacking
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 19:31:51
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.189.181.27 (27.181.189.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.189.181.27 (27.181.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 15:31:43.845653 2026] [security2:error] [pid 19691:tid 19691] [client 35.189.181.27:38786] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.ouzcorp.com"] [uri "/admin/.env"] [unique_id "arGGH9IB3r6mDD7FfrKA3wAAADg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-21 18:53:37
(8 hours ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 16:18:00
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.189.181.27 (27.181.189.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.189.181.27 (27.181.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 12:17:51.256013 2026] [security2:error] [pid 9173:tid 9191] [client 35.189.181.27:46770] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.oswgr.com"] [uri "/.git/HEAD"] [unique_id "arFYr88yzsqJoYwKpyTNAAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-21 14:05:09
(13 hours ago)
WAF repeated trigger detected by Fail2Ban
Web App Attack