๐บ๐ธ
TPI-Abuse
2026-10-03 07:44:58
(11 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.199.177.27 (27.177.199.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.199.177.27 (27.177.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 03 03:44:52.623518 2026] [security2:error] [pid 11956:tid 11956] [client 35.199.177.27:47622] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.mydobdate.com|F|2"] [data ".mydobdate.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.mydobdate.com"] [uri "/z9x8c7v6b5-debug-trigger-www.mydobdate.com"] [unique_id "asCydMUTuepUjVyF02hUXQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-03 07:25:32
(12 hours ago)
35.199.177.27 - - [03/Oct/2026:09:25:32 +0200] "GET / HTTP/2.0" 301 169 "-" "Mozilla/5.0 (compatible ...
show more
35.199.177.27 - - [03/Oct/2026:09:25:32 +0200] "GET / HTTP/2.0" 301 169 "-" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http:///search/)"
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-03 06:58:05
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.199.177.27 (27.177.199.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.199.177.27 (27.177.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 03 02:57:57.782939 2026] [security2:error] [pid 6036:tid 6036] [client 35.199.177.27:33660] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.my1611.com"] [uri "/.env.php.bak"] [unique_id "asCndaUcU1LicC7_atjEygAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
interbiznw.com
2026-10-03 06:53:29
(12 hours ago)
fail2ban-ban
Hacking
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-03 05:17:54
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.199.177.27 (27.177.199.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.199.177.27 (27.177.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 03 01:17:50.573104 2026] [security2:error] [pid 32567:tid 32567] [client 35.199.177.27:42528] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.marklex.com"] [uri "/.env.js"] [unique_id "asCP_kox-NCPQ90yLFVRVwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
ConsulHosting
2026-10-03 05:13:05
(14 hours ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
๐ณ๐ฑ
Site.eu
2026-10-03 05:07:34
(14 hours ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-10-03 04:10:36
(15 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.199.177.27 (27.177.199.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.199.177.27 (27.177.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 03 00:10:31.901763 2026] [security2:error] [pid 3523:tid 3523] [client 35.199.177.27:46524] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.mufasa.borzois.com|F|2"] [data ".mufasa.borzois.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.mufasa.borzois.com"] [uri "/z9x8c7v6b5-debug-trigger-www.mufasa.borzois.com"] [unique_id "asCAN10HYKuX4NwRuDwLpQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-10-03 03:31:13
(16 hours ago)
107 requests with url.path */@fs/*
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-03 03:26:25
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.199.177.27 (27.177.199.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.199.177.27 (27.177.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 23:26:17.517949 2026] [security2:error] [pid 19815:tid 19815] [client 35.199.177.27:37460] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.murpf.com"] [uri "/.env.js"] [unique_id "asB12Uvvk3xQlQUs0czv8QAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
palzer.IT
2026-10-03 03:01:33
(16 hours ago)
Fail2ban automatic report for plesk-apache-badbot: 35.199.177.27 - - [03/Oct/2026:05:01:03 +0200] GE ...
show more
Fail2ban automatic report for plesk-apache-badbot: 35.199.177.27 - - [03/Oct/2026:05:01:03 +0200] GET /model/info [DOMAIN_REMOVED] 404 34576 - Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +[DOMAIN_REMOVED]
show less
Bad Web Bot
๐ฉ๐ช
Philister11
2026-10-03 02:52:17
(16 hours ago)
CrowdSec: LePresidente/http-generic-403-bf (US/AS396982)
Web App Attack
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-10-03 02:40:17
(16 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.199.177.27 (27.177.199.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.199.177.27 (27.177.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 22:40:05.964341 2026] [security2:error] [pid 25698:tid 25698] [client 35.199.177.27:43680] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.crossfiregold.com|F|2"] [data ".crossfiregold.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.crossfiregold.com"] [uri "/z9x8c7v6b5-debug-trigger-www.crossfiregold.com"] [unique_id "asBrBXoOss7GG27Jp6ufnAAAADk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-03 02:18:52
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.199.177.27 (27.177.199.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.199.177.27 (27.177.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 22:18:45.272734 2026] [security2:error] [pid 10567:tid 10567] [client 35.199.177.27:58768] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.namefinder.com"] [uri "/.env.js"] [unique_id "asBmBdSOnw2Ef4JqSUqaUQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Philister11
2026-10-03 01:56:28
(17 hours ago)
CrowdSec: crowdsecurity/http-sensitive-files (US/AS396982)
Web App Attack
Hacking