๐บ๐ธ
TPI-Abuse
2026-09-21 06:19:33
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 35.194.220.100 (100.220.194.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.194.220.100 (100.220.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 02:19:25.732592 2026] [security2:error] [pid 22047:tid 22047] [client 35.194.220.100:51842] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.80corvette.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.80corvette.com"] [uri "/rclone.conf"] [unique_id "arDMbcplkkFrGrKBi5RpXgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 05:00:07
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.194.220.100 (100.220.194.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.194.220.100 (100.220.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 01:00:01.144397 2026] [security2:error] [pid 1562:tid 1562] [client 35.194.220.100:53300] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.indie100.com"] [uri "/.env.backup"] [unique_id "arC50ZsmF87lhjAlYnOVlAAAACk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-21 04:43:42
(2 days ago)
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .back/ .b ...
show more
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .back/ .backup/ .bak/ .bck/ .bk/ .bkp/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .cnf/ .com/ .compositefont/ .config/ .conf/ .copy/ .crt/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dist/ .dll/ .dos/ .dpkg-dist/ .drv/ .gadget/ .hta/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .inf/ .ini/ .jks/ .jse/ .key/ .licx/ .lnk/ .log/ .mdb/ .msc/ .ocx/ .old/ .pass/ .pdb/ .pfx/ .pif/ .pem/ .pol/ .prf/ .printer/ .pwd/ .rdb/ .rdp/ .reg/ .resources/ .resx/ .sav/ .save/ .scr/ .sct/ .sh/ .shs/ .sql/ .sqlite/ .sqlite3/ .swap/ .swo/ .swp/ .sys/ .temp/ .tfstate/ .tlb/ .tmp/ .vb/ .vbe/ .vbs/ .vbproj/ .vsdisco/ .vxd/ .webinfo/ .ws/ .wsc/ .wsf/ .wsh/ .xsd/ .xsx/" at TX:extension. (920440-193)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-21 04:30:18
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.194.220.100 (100.220.194.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.194.220.100 (100.220.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 00:30:06.065223 2026] [security2:error] [pid 4406:tid 4406] [client 35.194.220.100:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.aabondwnc.com"] [uri "/@fs/app/.env"] [unique_id "arCyzjlT1fHKj6_rO7hdVAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 04:06:44
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.194.220.100 (100.220.194.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.194.220.100 (100.220.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 00:06:41.106593 2026] [security2:error] [pid 30982:tid 30982] [client 35.194.220.100:38760] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.aallred.com"] [uri "/.env.local"] [unique_id "arCtUbNWTQKs-hiYWTBRpwAAACo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 03:01:11
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 35.194.220.100 (100.220.194.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.194.220.100 (100.220.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 23:01:05.050924 2026] [security2:error] [pid 20254:tid 20254] [client 35.194.220.100:41300] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||3dworld-wide.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "3dworld-wide.com"] [uri "/z9x8c7v6b5-debug-trigger-3dworld-wide.com"] [unique_id "arCd8R1gqS7iSCzAYrBywQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 02:12:00
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.194.220.100 (100.220.194.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.194.220.100 (100.220.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 22:11:54.434859 2026] [security2:error] [pid 12638:tid 12638] [client 35.194.220.100:51952] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "abcollie.com"] [uri "/common/.env"] [unique_id "arCSamAyZuwUdLUgK_lMKgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-21 02:02:29
(2 days ago)
Banned by Fail2Ban on server
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 00:32:39
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.194.220.100 (100.220.194.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.194.220.100 (100.220.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 20:32:33.623761 2026] [security2:error] [pid 28735:tid 28735] [client 35.194.220.100:58824] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.accordionfactory.com"] [uri "/.env.local"] [unique_id "arB7Ia5MJiB5qrsA1BbKhwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-21 00:29:44
(2 days ago)
20 attempts against mh-misbehave-ban on jva-noble-dev
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-21 00:05:07
(2 days ago)
WAF repeated trigger detected by Fail2Ban
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 23:27:28
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 35.194.220.100 (100.220.194.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.194.220.100 (100.220.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 19:27:23.972145 2026] [security2:error] [pid 27768:tid 27768] [client 35.194.220.100:33894] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||acmyles.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "acmyles.com"] [uri "/z9x8c7v6b5-debug-trigger-acmyles.com"] [unique_id "arBr2xcHT0ULCW9l9-GQewAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
middelkoopcc
2026-09-20 23:12:09
(2 days ago)
2026-09-21 01:10:43 AH01071: Got error 'Primary script unknown' && 2026-09-21 01:10:43 AH01071: Got ...
show more
2026-09-21 01:10:43 AH01071: Got error 'Primary script unknown' && 2026-09-21 01:10:43 AH01071: Got error 'Primary script unknown' && 2026-09-21 01:10:43 AH10244: invalid URI path (/public/plugins/grafana-clock-panel/../../../../../../../../proc/self/environ) && 262 more within 20 minutes
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 22:21:26
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 35.194.220.100 (100.220.194.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.194.220.100 (100.220.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 18:21:22.231567 2026] [security2:error] [pid 32558:tid 32568] [client 35.194.220.100:55394] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.2291106.com|F|2"] [data ".2291106.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.2291106.com"] [uri "/z9x8c7v6b5-debug-trigger-mail.2291106.com"] [unique_id "arBcYhWBCD8CsGqSLuqL1QAAAEY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-20 22:06:28
(2 days ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking