๐ฒ๐พ
Rizzy
2026-10-01 18:00:32
(12 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 17:54:32
(12 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.200.95.16 (16.95.200.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.200.95.16 (16.95.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 13:54:26.321874 2026] [security2:error] [pid 18273:tid 18273] [client 35.200.95.16:42208] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.representacionesthompson.com|F|2"] [data ".representacionesthompson.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.representacionesthompson.com"] [uri "/z9x8c7v6b5-debug-trigger-www.representacionesthompson.com"] [unique_id "ar6eUh4rpnRfuOIjdUj-gQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 16:42:29
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.200.95.16 (16.95.200.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.200.95.16 (16.95.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 12:42:21.041568 2026] [security2:error] [pid 14578:tid 14578] [client 35.200.95.16:32932] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sekel.org"] [uri "/static//.env"] [unique_id "ar6NbZgm8a86Qfk5Y3z0GQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 15:41:44
(14 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.200.95.16 (16.95.200.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.200.95.16 (16.95.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 11:41:39.458598 2026] [security2:error] [pid 26071:tid 26071] [client 35.200.95.16:60752] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||rockhillcounselors.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "rockhillcounselors.com"] [uri "/z9x8c7v6b5-debug-trigger-rockhillcounselors.com"] [unique_id "ar5_MxouqIREEaoamQtaUQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 14:56:03
(15 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.200.95.16 (16.95.200.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.200.95.16 (16.95.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 10:55:59.631928 2026] [security2:error] [pid 23912:tid 23912] [client 35.200.95.16:40328] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||protonmultimedia.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "protonmultimedia.com"] [uri "/z9x8c7v6b5-debug-trigger-protonmultimedia.com"] [unique_id "ar50f4zBuMD9eBh9C7Q2bgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 14:40:42
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.200.95.16 (16.95.200.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.200.95.16 (16.95.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 10:40:35.905088 2026] [security2:error] [pid 30755:tid 30764] [client 35.200.95.16:50126] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.rmoeis.com"] [uri "/cache/original/%2e%2e/%2e%2e/.env"] [unique_id "ar5w40gLJe5Flzlv3UDqnwAAAIc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 14:10:30
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.200.95.16 (16.95.200.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.200.95.16 (16.95.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 10:10:23.820561 2026] [security2:error] [pid 10660:tid 10660] [client 35.200.95.16:37560] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "schoolsliaisoncommunity.net"] [uri "/static../.env"] [unique_id "ar5pz2nto6HMl2pzxncanAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 13:51:21
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.200.95.16 (16.95.200.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.200.95.16 (16.95.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 09:51:17.319478 2026] [security2:error] [pid 26041:tid 26041] [client 35.200.95.16:42136] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.ruthbalser.org"] [uri "/static//.env"] [unique_id "ar5lVbRZdxo12S7Wki7yugAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-01 13:17:39
(17 hours ago)
Blocked by ModSec and CSF
Port Scan
๐บ๐ธ
TPI-Abuse
2026-10-01 12:47:24
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.200.95.16 (16.95.200.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.200.95.16 (16.95.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 08:47:20.133657 2026] [security2:error] [pid 10065:tid 10065] [client 35.200.95.16:42282] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.poulsoncustomhomes.com"] [uri "/config/.env.php"] [unique_id "ar5WWHjl19Arw7lDpSzL6wAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 12:31:20
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.200.95.16 (16.95.200.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.200.95.16 (16.95.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 08:31:12.164673 2026] [security2:error] [pid 12385:tid 12385] [client 35.200.95.16:33742] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.swetzer.net"] [uri "/.htpasswd"] [unique_id "ar5SkM2GmhQjwu5xorXX6AAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
dot.mg
2026-10-01 12:12:10
(18 hours ago)
Scan of vulnerable files
Web App Attack
๐จ๐ฆ
polycoda
2026-10-01 12:00:26
(18 hours ago)
AutoBlock: ๐ก Port Scan (Non Decay-Based)
Port Scan
๐บ๐ธ
TPI-Abuse
2026-10-01 11:57:26
(18 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.200.95.16 (16.95.200.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.200.95.16 (16.95.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 07:57:20.585464 2026] [security2:error] [pid 14365:tid 14365] [client 35.200.95.16:33862] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||robyndesigns.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "robyndesigns.com"] [uri "/z9x8c7v6b5-debug-trigger-robyndesigns.com"] [unique_id "ar5KoIoHzi3fLZD8OHKaEQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 11:37:07
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.200.95.16 (16.95.200.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.200.95.16 (16.95.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 07:36:59.597217 2026] [security2:error] [pid 15022:tid 15032] [client 35.200.95.16:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.raytbrown.com"] [uri "/js../.env"] [unique_id "ar5F2zgU7pQlq_LdcGlogAAAAUg"]
show less
Brute-Force
Bad Web Bot
Web App Attack