๐บ๐ธ
TPI-Abuse
2026-09-22 01:05:59
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.194.213.48 (48.213.194.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.194.213.48 (48.213.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 21:05:54.448421 2026] [security2:error] [pid 7275:tid 7275] [client 35.194.213.48:60514] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.modeltdr.com"] [uri "/.git/config"] [unique_id "arHUciXxM4qndSSZkYbWDwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 00:06:18
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 35.194.213.48 (48.213.194.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.194.213.48 (48.213.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 20:05:54.587584 2026] [security2:error] [pid 26358:tid 26358] [client 35.194.213.48:37334] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.proyectando.com|F|2"] [data ".proyectando.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.proyectando.com"] [uri "/z9x8c7v6b5-debug-trigger-www.proyectando.com"] [unique_id "arHGYnCVVpU5JtTloop6jAAAAGc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 23:45:53
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 35.194.213.48 (48.213.194.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.194.213.48 (48.213.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 19:45:47.455928 2026] [security2:error] [pid 26967:tid 26993] [client 35.194.213.48:54160] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||redesign.mdbscommercialcleaning.com|F|2"] [data ".mdbscommercialcleaning.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "redesign.mdbscommercialcleaning.com"] [uri "/z9x8c7v6b5-debug-trigger-redesign.mdbscommercialcleaning.com"] [unique_id "arHBq_H-a_wbwIp_jmUZQQAAAIc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ด
jad-abuse
2026-09-21 21:24:52
(3 days ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe, aws_creds, source_backup, git_exposure, ignition_debug, actuator, server_status, ssh_keys. Observed by 1 sensor(s); 251 hits.
show less
Hacking
Web App Attack
๐ฎ๐น
VHosting
2026-09-21 18:30:04
(3 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
Anonymous
2026-09-21 15:32:43
(3 days ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-09-21 15:24:34
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.194.213.48 (48.213.194.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.194.213.48 (48.213.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 11:24:30.658044 2026] [security2:error] [pid 11604:tid 11604] [client 35.194.213.48:53270] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.cajunfriedturkey.com"] [uri "/@fs/.env"] [unique_id "arFMLrvWT1mqMPQBay_2cQAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-21 15:14:40
(3 days ago)
Aggressive web scan
Web App Attack
Anonymous
2026-09-21 14:57:00
(3 days ago)
XSS Attempt
Hacking
๐ฉ๐ช
ghostwarriors
2026-09-21 14:50:10
(3 days ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 14:49:03
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.194.213.48 (48.213.194.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.194.213.48 (48.213.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 10:48:58.857621 2026] [security2:error] [pid 7761:tid 7761] [client 35.194.213.48:43272] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.collegetvticket.com"] [uri "/wp-config.php.old"] [unique_id "arFD2rjk_siKeiVqrIfaLAAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
yitzhaq
2026-09-21 14:35:54
(3 days ago)
35.194.213.48 - - [21/Sep/2026:16:35:51 +0200] "GET /rclone.conf HTTP/2.0" 403 298 "-" "Mozilla/5.0 ...
show more
35.194.213.48 - - [21/Sep/2026:16:35:51 +0200] "GET /rclone.conf HTTP/2.0" 403 298 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot)"
35.194.213.48 - - [21/Sep/2026:16:35:51 +0200] "GET /%2e%2e/.env HTTP/2.0" 400 325 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)"
35.194.213.48 - - [21/Sep/2026:16:35:52 +0200] "POST /api/graphql HTTP/2.0" 404 318 "https://[site]" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
35.194.213.48 - - [21/Sep/2026:16:35:52 +0200] "GET /images../.env HTTP/2.0" 404 295 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)"
35.194.213.48 - - [21/Sep/2026:16:35:52 +0200] "GET /uploads../.env HTTP/2.0" 403 298 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)"
35.194.213.48 - - [21/Sep/2026:16:35:52 +0200] "GET /@fs/root/.aws/credentials?raw??
show less
Web App Attack
Hacking
๐ฟ๐ฆ
conure.sh
2026-09-21 14:20:30
(3 days ago)
csagent: score 20.5: 404 noise floor x2, secrets grab x2; 1 domain(s) in 3s
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 14:12:33
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.194.213.48 (48.213.194.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.194.213.48 (48.213.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 10:12:30.448026 2026] [security2:error] [pid 240465:tid 240465] [client 35.194.213.48:53730] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ramoundos.com"] [uri "/@fs/app/.env"] [unique_id "arE7TtZEBZsBzbsZjXKbgQAAADw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 13:52:49
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 35.194.213.48 (48.213.194.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.194.213.48 (48.213.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 09:52:42.397667 2026] [security2:error] [pid 5613:tid 5613] [client 35.194.213.48:41642] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||redbends.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "redbends.com"] [uri "/z9x8c7v6b5-debug-trigger-redbends.com"] [unique_id "arE2qoeF-KDUb2OcXXP6iAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack