๐บ๐ธ
TPI-Abuse
2026-09-30 13:19:29
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.204.239.217 (217.239.204.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.204.239.217 (217.239.204.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 09:19:23.793809 2026] [security2:error] [pid 9959:tid 9959] [client 35.204.239.217:49544] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.leothecolorman.com"] [uri "/.env.js"] [unique_id "ar0MW71gyjopPf7FiUQGUwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-09-30 12:35:03
(2 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
TAY
2026-09-30 11:39:55
(3 hours ago)
35.204.239.217 - - [30/Sep/2026:19:39:53 +0800] "GET /api/w/admins/jobs_u/get_log_file/../../../../p ...
show more
35.204.239.217 - - [30/Sep/2026:19:39:53 +0800] "GET /api/w/admins/jobs_u/get_log_file/../../../../proc/self/environ HTTP/1.1" 200 595 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
35.204.239.217 - - [30/Sep/2026:19:39:54 +0800] "GET /static../.env HTTP/1.1" 200 595 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)"
35.204.239.217 - - [30/Sep/2026:19:39:54 +0800] "GET /css../.env HTTP/1.1" 200 595 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)"
35.204.239.217 - - [30/Sep/2026:19:39:54 +0800] "GET /media../.env HTTP/1.1" 200 595 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1)"
35.204.239.217 - - [30/Sep/2026:19:39:54 +0800] "GET /files../.env HTTP/1.1" 200 595 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)"
35.204.239.217 - - [30/Sep/2026:19:39:55 +0800] "GET /assets../.env HTTP/1.1" 200 6454 "-" "Mozilla/5.0 (compatible;
...
show less
Brute-Force
Anonymous
2026-09-30 11:36:55
(3 hours ago)
IP matched detection query 50 and more bad rqs apache.
Hacking
Bad Web Bot
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 11:23:34
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.204.239.217 (217.239.204.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.204.239.217 (217.239.204.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 07:23:27.088712 2026] [security2:error] [pid 11822:tid 11822] [client 35.204.239.217:35820] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||limocorpuschristi.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "limocorpuschristi.com"] [uri "/z9x8c7v6b5-debug-trigger-limocorpuschristi.com"] [unique_id "arzxLwwNN4m2PHtU228eugAAACk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-30 11:20:26
(3 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-30 10:55:48
(4 hours ago)
[ti-22al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-22al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 35.204.239.217 - - [30/Sep/2026:12:55:42 +0200] "GET /uploads../.env HTTP/2.0" 403 58 "-" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 10:51:16
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.204.239.217 (217.239.204.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.204.239.217 (217.239.204.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 06:51:10.822105 2026] [security2:error] [pid 1137:tid 1137] [client 35.204.239.217:44696] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||legalnexusbali.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "legalnexusbali.com"] [uri "/z9x8c7v6b5-debug-trigger-legalnexusbali.com"] [unique_id "arzpnlqq74yDb1kWkS6EIQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-30 10:39:39
(4 hours ago)
Multiple WAF Violations
Web App Attack
๐จ๐ฆ
polycoda
2026-09-30 08:09:43
(7 hours ago)
AutoBlock: ๐ก Port Scan (Non Decay-Based)
Port Scan
๐บ๐ธ
micropedro
2026-09-30 07:08:38
(8 hours ago)
3 incidents: web scanning/attack. First: 2026-09-30 03:08, Last: 2026-09-30 03:08 UTC. Triggers: fir ...
show more
3 incidents: web scanning/attack. First: 2026-09-30 03:08, Last: 2026-09-30 03:08 UTC. Triggers: firewall-http,non-public-port,port-trap.
show less
Port Scan
Web App Attack