๐ซ๐ท
masterguru
2026-09-22 00:41:16
(1 week ago)
Restricted File Access Attempt. Matched phrase "config.json" at REQUEST_FILENAME. (930130-196)
Hacking
Web App Attack
๐ฎ๐ฉ
Burayot
2026-09-22 00:37:50
(1 week ago)
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 35.222.160.132 (US/United States/132 ...
show more
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 35.222.160.132 (US/United States/132.160.222.35.bc.googleusercontent.com): 2 in the last 3600 secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 23:39:25
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.222.160.132 (132.160.222.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.222.160.132 (132.160.222.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 19:39:19.000119 2026] [security2:error] [pid 8979:tid 8979] [client 35.222.160.132:40710] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpking.com"] [uri "/.git/config"] [unique_id "arHAJlywccg0LXC6bKt11QAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 22:53:17
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.222.160.132 (132.160.222.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.222.160.132 (132.160.222.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 18:53:13.247684 2026] [security2:error] [pid 488:tid 488] [client 35.222.160.132:36684] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.abilityengraving.com"] [uri "/app/.env"] [unique_id "arG1WdrG0B7xb2ilmPPtGwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 22:37:01
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 35.222.160.132 (132.160.222.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.222.160.132 (132.160.222.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 18:36:55.381651 2026] [security2:error] [pid 22784:tid 22784] [client 35.222.160.132:39814] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.armandselmwoodpark.com|F|2"] [data ".armandselmwoodpark.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.armandselmwoodpark.com"] [uri "/z9x8c7v6b5-debug-trigger-www.armandselmwoodpark.com"] [unique_id "arGxh-9tHjmMQ64QoUh18wAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 21:59:04
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.222.160.132 (132.160.222.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.222.160.132 (132.160.222.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 17:58:59.398494 2026] [security2:error] [pid 7942:tid 7942] [client 35.222.160.132:50228] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.body-tone.com"] [uri "/services/.env"] [unique_id "arGoo1QqfCIKtoU_7mO7KAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 21:38:00
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.222.160.132 (132.160.222.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.222.160.132 (132.160.222.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 17:37:53.354074 2026] [security2:error] [pid 30844:tid 30844] [client 35.222.160.132:43038] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.bostonscience.com"] [uri "/assets../.env"] [unique_id "arGjsf05DPUT_h1CBCdPhQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 20:50:26
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 35.222.160.132 (132.160.222.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.222.160.132 (132.160.222.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 16:50:18.210088 2026] [security2:error] [pid 9109:tid 9109] [client 35.222.160.132:48610] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.crearetest.com|F|2"] [data ".crearetest.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.crearetest.com"] [uri "/z9x8c7v6b5-debug-trigger-mail.crearetest.com"] [unique_id "arGYiiHwXdmGy5H5Dhy2GgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 20:01:30
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.222.160.132 (132.160.222.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.222.160.132 (132.160.222.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 16:01:25.102836 2026] [security2:error] [pid 20421:tid 20421] [client 35.222.160.132:49016] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.damgoodit.com"] [uri "/.env.local"] [unique_id "arGNFV85CrE3LSDu2o1qfAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-21 18:23:22
(1 week ago)
35.222.160.132 - - [21/Sep/2026:20:23:22 +0200] "GET / HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Macintosh ...
show more
35.222.160.132 - - [21/Sep/2026:20:23:22 +0200] "GET / HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
35.222.160.132 - - [21/Sep/2026:20:23:22 +0200] "GET /api/env HTTP/1.1" 403 124 "-" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/)"
35.222.160.132 - - [21/Sep/2026:20:23:22 +0200] "POST / HTTP/1.1" 403 124 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)"
35.222.160.132 - - [21/Sep/2026:20:23:22 +0200] "GET /.aws/credentials HTTP/1.1" 403 124 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)"
35.222.160.132 - - [21/Sep/2026:20:23:22 +0200] "GET /__/firebase/init.json HTTP/1.1" 403 124 "-" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)"
35.222.160.132 - - [21/Sep/2026:20:23:22 +0200] "GET /.env.example HTTP/1.1" 403 124 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/pe
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 18:01:12
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.222.160.132 (132.160.222.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.222.160.132 (132.160.222.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 14:01:06.021973 2026] [security2:error] [pid 30700:tid 30700] [client 35.222.160.132:34872] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.chicagowca.com"] [uri "/api/v1/.env"] [unique_id "arFw4t4Q5kkRIklaeBLsyQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 17:07:15
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.222.160.132 (132.160.222.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.222.160.132 (132.160.222.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 13:07:09.892428 2026] [security2:error] [pid 30473:tid 30473] [client 35.222.160.132:53688] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.aantariaconstructions.com"] [uri "/.env.old"] [unique_id "arFkPQMvFG53mi2STuArrwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-09-21 16:09:08
(1 week ago)
Too many Status 40X (23)
Too many Status 50X (97)
Scanning/Probing (63)
Request Overload (120)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 15:29:27
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 35.222.160.132 (132.160.222.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.222.160.132 (132.160.222.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 11:29:24.101881 2026] [security2:error] [pid 12885:tid 12885] [client 35.222.160.132:56478] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||brewerfs.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "brewerfs.com"] [uri "/z9x8c7v6b5-debug-trigger-brewerfs.com"] [unique_id "arFNVJpARDye9OyVDQia3AAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 15:06:20
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.222.160.132 (132.160.222.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.222.160.132 (132.160.222.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 11:06:14.008602 2026] [security2:error] [pid 3135:tid 3161] [client 35.222.160.132:38508] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.anointedtour.com"] [uri "/@fs/var/task/.env"] [unique_id "arFH5s-DXC8wC7g7pLK_nAAAAFg"]
show less
Brute-Force
Bad Web Bot
Web App Attack