πΊπΈ
TPI-Abuse
2026-10-01 07:25:02
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 35.203.31.180 (180.31.203.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.203.31.180 (180.31.203.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 03:24:56.436105 2026] [security2:error] [pid 7840:tid 7840] [client 35.203.31.180:41422] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.guernsey-boat-registration.com|F|2"] [data ".guernsey-boat-registration.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.guernsey-boat-registration.com"] [uri "/z9x8c7v6b5-debug-trigger-www.guernsey-boat-registration.com"] [unique_id "ar4KyCs9aMPr5f9ZVgpIFwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Site.eu
2026-10-01 06:31:07
(2 days ago)
Excessive multi-domain requests
Brute-Force
π©πͺ
updown.io
2026-10-01 05:22:43
(2 days ago)
{"level":"info","ts":1790832160.3624732,"logger":"http.log.access.log1","msg":"handled request","req ...
show more
{"level":"info","ts":1790832160.3624732,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"35.203.31.180","remote_port":"45390","client_ip":"35.203.31.180","proto":"HTTP/2.0","method":"GET","host":"status.gunnerstoday.com","uri":"/7epuuw6d4ky8qpwcszf4","headers":{"X-Nextjs-Data":["1"],"User-Agent":["Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)"],"Accept":["*/*"],"Accept-Encoding":["gzip"],"X-Middleware-Subrequest":["src/middleware:nowaf:src/middleware:src/middleware:src/middleware:src/middleware:middleware:middleware:nowaf:middleware:middleware:middleware:pages/_middleware"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"h2","server_name":"status.gunnerstoday.com","ech":false}},"bytes_read":0,"user_id":"","duration":0.000104038,"size":0,"status":429,"resp_headers":{"Server":["Caddy"],"Alt-Svc":["h3=\":443\"; ma=2592000"],"Retry-After":["1"]}}
{"level":"info","ts":1790832160.366637,"logger":"http.log.access.log1","ms
...
show less
DDoS Attack
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-01 05:05:12
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.203.31.180 (180.31.203.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.203.31.180 (180.31.203.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 01:05:04.544356 2026] [security2:error] [pid 32388:tid 32388] [client 35.203.31.180:52736] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.harvestfrc.com"] [uri "/js../.env"] [unique_id "ar3qAH6FIF7-c0822lmtAAAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-01 04:30:08
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.203.31.180 (180.31.203.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.203.31.180 (180.31.203.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 00:30:02.176811 2026] [security2:error] [pid 23596:tid 23596] [client 35.203.31.180:37310] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.healthycaregiving.com"] [uri "/static//app/.env"] [unique_id "ar3hysjSM1g8ngtG-_2ytgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-01 03:40:05
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.203.31.180 (180.31.203.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.203.31.180 (180.31.203.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 23:39:57.253130 2026] [security2:error] [pid 5930:tid 5945] [client 35.203.31.180:60042] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.jd-web-designs.com"] [uri "/.env.development"] [unique_id "ar3WDXwF7H85FKTAbuVhSQAAAIc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
mad-abuseip
2026-10-01 03:20:16
(2 days ago)
SCORE:99 REASON:suspicious-score:103 | "POST /api/v1/node-load-method/customMCP HTTP/1.1" SCORE:99 ...
show more
SCORE:99 REASON:suspicious-score:103 | "POST /api/v1/node-load-method/customMCP HTTP/1.1" SCORE:99 REASON:suspicious-score:103 - "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)"
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-01 03:11:22
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.203.31.180 (180.31.203.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.203.31.180 (180.31.203.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 23:11:15.738234 2026] [security2:error] [pid 30805:tid 30805] [client 35.203.31.180:50348] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wmodradio.com"] [uri "/.env.dev"] [unique_id "ar3PU2tP-GdkyzHjPAxRUgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
consul.to
2026-10-01 02:48:23
(2 days ago)
Web attack/malicious scanning detected
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-01 00:59:59
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 35.203.31.180 (180.31.203.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.203.31.180 (180.31.203.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 20:59:53.431366 2026] [security2:error] [pid 24902:tid 24902] [client 35.203.31.180:41094] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||halotoys.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "halotoys.com"] [uri "/z9x8c7v6b5-debug-trigger-halotoys.com"] [unique_id "ar2wiTJFedkwq8jjRdXTKwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π§πͺ
cmbplf
2026-10-01 00:40:54
(2 days ago)
658 requests with url.path *.env
171 requests with url.path */@fs/*
Brute-Force
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-10-01 00:14:54
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 35.203.31.180 (180.31.203.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.203.31.180 (180.31.203.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 20:14:48.373780 2026] [security2:error] [pid 7688:tid 7716] [client 35.203.31.180:58360] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.havacubvision.com|F|2"] [data ".havacubvision.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.havacubvision.com"] [uri "/z9x8c7v6b5-debug-trigger-www.havacubvision.com"] [unique_id "ar2l-LelAtFaQpwdQ63N2AAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
SpaceHost-Server
2026-09-30 22:25:19
(3 days ago)
Brute-Force
Web App Attack
π©πͺ
LRob
2026-09-30 22:09:18
(3 days ago)
Wordlist path sweep | method: POST, GET | path: /lib/terminal-xhr.php, /asset-manifest.json, /model/ ...
show more
Wordlist path sweep | method: POST, GET | path: /lib/terminal-xhr.php, /asset-manifest.json, /model/info (+3 more) | ua: Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/), Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 Edg/153.0.0.0, Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/ (+1 more)
show less
Port Scan
Web App Attack
π―π΅
nhawsjones
2026-09-30 20:28:42
(3 days ago)
[Thu Oct 01 05:28:40.458954 2026] [authz_core:error] [pid 345558:tid 345558] [client 35.203.31.180:4 ...
show more
[Thu Oct 01 05:28:40.458954 2026] [authz_core:error] [pid 345558:tid 345558] [client 35.203.31.180:43268] AH01630: client denied by server configuration: /var/www/external/server-status, referer: https://hawsjones.com/server-status
...
show less
Brute-Force