๐บ๐ธ
TPI-Abuse
2026-09-24 16:43:46
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 35.203.76.116 (116.76.203.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.203.76.116 (116.76.203.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 12:43:39.805421 2026] [security2:error] [pid 14666:tid 14666] [client 35.203.76.116:58504] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.homerbiz.com|F|2"] [data ".homerbiz.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.homerbiz.com"] [uri "/z9x8c7v6b5-debug-trigger-www.homerbiz.com"] [unique_id "arVTOxB15hcPLlEu4WmzFgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-24 15:30:03
(2 hours ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 15:07:37
(3 hours ago)
(mod_security) mod_security (id:210580) triggered by 35.203.76.116 (116.76.203.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210580) triggered by 35.203.76.116 (116.76.203.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 11:07:31.705020 2026] [security2:error] [pid 24083:tid 24083] [client 35.203.76.116:60176] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at ARGS:path. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||www.holisticbuildingexperience.com|F|2"] [data "Matched Data: proc/self/environ found within ARGS:path: ../../../../proc/self/environ"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "www.holisticbuildingexperience.com"] [uri "/userfiles/x"] [unique_id "arU8szlR14br9mETgvlNTQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-24 14:25:10
(3 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐ช๐ธ
masterguru
2026-09-24 14:24:11
(3 hours ago)
BAD BOT - Detected and Blocked.. Matched phrase "baidu" at REQUEST_HEADERS:user-agent. (1100000-178)
Bad Web Bot
Anonymous
2026-09-24 13:43:02
(4 hours ago)
Bot / scanning and/or hacking attempts: GET /.env.js HTTP/2.0, POST /api/designer/v1/file-content HT ...
show more
Bot / scanning and/or hacking attempts: GET /.env.js HTTP/2.0, POST /api/designer/v1/file-content HTTP/2.0, POST /read-document HTTP/2.0, POST /api/templates/preview HTTP/2.0
show less
Hacking
Web App Attack
๐ฌ๐ง
thetomtaylor.co.uk
2026-09-24 13:06:00
(5 hours ago)
Fail2Ban - [WAF]ModSecurity OWASP CRS rule violation on nginx-modsecurity ... [ice01]
Hacking
SQL Injection
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 11:38:36
(6 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.203.76.116 (116.76.203.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.203.76.116 (116.76.203.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 07:38:33.201246 2026] [security2:error] [pid 25665:tid 25665] [client 35.203.76.116:55842] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.hisimengineering.com|F|2"] [data ".hisimengineering.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.hisimengineering.com"] [uri "/z9x8c7v6b5-debug-trigger-www.hisimengineering.com"] [unique_id "arULuW0CKzxutdAVdkisMgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 10:34:33
(7 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.203.76.116 (116.76.203.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.203.76.116 (116.76.203.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 06:34:29.043976 2026] [security2:error] [pid 19560:tid 19560] [client 35.203.76.116:33310] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.hillconsultants.com|F|2"] [data ".hillconsultants.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.hillconsultants.com"] [uri "/z9x8c7v6b5-debug-trigger-www.hillconsultants.com"] [unique_id "arT8td5TZyK_jcu89uo1wwAAADU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
rubixstudios
2026-09-24 09:55:03
(8 hours ago)
Excessive HTTP requests consistent with automated attack behaviour detected by Imunify360
DDoS Attack
Brute-Force
Web App Attack
๐บ๐ธ
robotstxt
2026-09-24 09:39:27
(8 hours ago)
35.203.76.116 - - [24/Sep/2026:09:39:14 +0000] "GET /dist/.vite/manifest.json HTTP/2.0" 403 2 "-" "M ...
show more
35.203.76.116 - - [24/Sep/2026:09:39:14 +0000] "GET /dist/.vite/manifest.json HTTP/2.0" 403 2 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 Edg/153.0.0.0" "-" edge="35.203.76.116"
35.203.76.116 - - [24/Sep/2026:09:39:17 +0000] "GET /.dockerenv HTTP/2.0" 403 20 "-" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)" "-" edge="35.203.76.116"
35.203.76.116 - - [24/Sep/2026:09:39:17 +0000] "GET /.env?raw HTTP/2.0" 403 20 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)" "-" edge="35.203.76.116"
35.203.76.116 - - [24/Sep/2026:09:39:18 +0000] "GET /.env?import&raw HTTP/2.0" 403 20 "-" "Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)" "-" edge="35.203.76.116"
35.203.76.116 - - [24/Sep/2026:09:39:18 +0000] "GET /.env?import&url&inline HTTP/2.0" 403 20 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Appleb
...
show less
Web App Attack
๐ฉ๐ช
XICTRON
2026-09-24 08:05:06
(10 hours ago)
ModSecurity rule violation detected by Fail2Ban
Web App Attack
๐บ๐ธ
Blue Pumpkin
2026-09-24 07:56:18
(10 hours ago)
35.203.76.116 - - [24/Sep/2026:07:56:17 +0000] "GET /.ssh/id_ed25519 HTTP/1.1" 404 4881 "-" "Mozilla ...
show more
35.203.76.116 - - [24/Sep/2026:07:56:17 +0000] "GET /.ssh/id_ed25519 HTTP/1.1" 404 4881 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
...
show less
Brute-Force
๐ฉ๐ช
EGP Abuse Dept
2026-09-24 07:48:18
(10 hours ago)
Scanning for web/db/file exploits on www.hetwissel.com
SQL Injection
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 06:08:28
(12 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.203.76.116 (116.76.203.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.203.76.116 (116.76.203.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 02:08:24.897404 2026] [security2:error] [pid 31744:tid 31744] [client 35.203.76.116:34832] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.henhousebbq.com|F|2"] [data ".henhousebbq.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.henhousebbq.com"] [uri "/z9x8c7v6b5-debug-trigger-www.henhousebbq.com"] [unique_id "arS-WHRlzwmXHhVotwBvPwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack