๐บ๐ธ
TPI-Abuse
2026-09-22 00:35:24
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.224.102.120 (120.102.224.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.224.102.120 (120.102.224.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 20:35:15.338206 2026] [security2:error] [pid 7229:tid 7229] [client 35.224.102.120:40900] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.mailperform.com"] [uri "/.env.example"] [unique_id "arHNQ_EYfzA1tvrE-7VnkwAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 00:13:05
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.224.102.120 (120.102.224.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.224.102.120 (120.102.224.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 20:13:01.803856 2026] [security2:error] [pid 4193:tid 4193] [client 35.224.102.120:43036] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.michaelprussin.com"] [uri "/frontend/.env"] [unique_id "arHIDYV8L1PQqge9ZO6jrwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
updown.io
2026-09-21 22:39:15
(3 days ago)
{"level":"info","ts":1790030351.7652168,"logger":"http.log.access.log1","msg":"handled request","req ...
show more
{"level":"info","ts":1790030351.7652168,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"35.224.102.120","remote_port":"38242","client_ip":"35.224.102.120","proto":"HTTP/2.0","method":"GET","host":"status.mgptoday.com","uri":"/.git/config","headers":{"Accept-Encoding":["gzip"],"X-Middleware-Subrequest":["src/middleware:nowaf:src/middleware:src/middleware:src/middleware:src/middleware:middleware:middleware:nowaf:middleware:middleware:middleware:pages/_middleware"],"X-Nextjs-Data":["1"],"User-Agent":["Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)"],"Accept":["*/*"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"h2","server_name":"status.mgptoday.com","ech":false}},"bytes_read":0,"user_id":"","duration":0.000273522,"size":0,"status":429,"resp_headers":{"Server":["Caddy"],"Alt-Svc":["h3=\":443\"; ma=2592000"],"Retry-After":["1"]}}
{"level":"info","ts":1790030351.7685394,"logger":"http.log.access.log1","msg":"handled request","requ
...
show less
DDoS Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 21:46:44
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.224.102.120 (120.102.224.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.224.102.120 (120.102.224.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 17:46:38.799992 2026] [security2:error] [pid 13977:tid 13977] [client 35.224.102.120:53978] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.mintgames.com"] [uri "/.env.production"] [unique_id "arGlvrHK9rfp29nfPSQrCgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-21 21:00:02
(3 days ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 20:51:55
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.224.102.120 (120.102.224.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.224.102.120 (120.102.224.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 16:51:50.413728 2026] [security2:error] [pid 29731:tid 29731] [client 35.224.102.120:34000] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.macryder.com"] [uri "/.env.production"] [unique_id "arGY5pbwos-IxcXzJi4rBQAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 20:19:34
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.224.102.120 (120.102.224.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.224.102.120 (120.102.224.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 16:19:28.780803 2026] [security2:error] [pid 30071:tid 30071] [client 35.224.102.120:33398] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.naturopathicsource.com"] [uri "/.git/config"] [unique_id "arGRUHbEAvNpGbp-x1p3oAAAAE4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 19:20:40
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.224.102.120 (120.102.224.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.224.102.120 (120.102.224.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 15:20:33.543846 2026] [security2:error] [pid 21929:tid 21929] [client 35.224.102.120:52590] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.rokket.com"] [uri "/data/.env"] [unique_id "arGDgRw_CZ3XuuKdYCjZowAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 18:54:29
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.224.102.120 (120.102.224.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.224.102.120 (120.102.224.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 14:54:24.705866 2026] [security2:error] [pid 11152:tid 11152] [client 35.224.102.120:55896] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.manzilly.com"] [uri "/.env.local"] [unique_id "arF9YMaOgQXPcdO3f-_ILQAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 18:19:19
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.224.102.120 (120.102.224.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.224.102.120 (120.102.224.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 14:19:13.010925 2026] [security2:error] [pid 16635:tid 16635] [client 35.224.102.120:42644] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.rangejudging.com"] [uri "/etc/.env"] [unique_id "arF1IQmlY2J1X4ouO6itFwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 18:02:30
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.224.102.120 (120.102.224.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.224.102.120 (120.102.224.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 14:02:21.885527 2026] [security2:error] [pid 21473:tid 21473] [client 35.224.102.120:34328] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.psychiatryabuse.com"] [uri "/packages/.env"] [unique_id "arFxLQzyJn-4gGDB-pGpngAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 17:21:27
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 35.224.102.120 (120.102.224.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.224.102.120 (120.102.224.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 13:21:22.457858 2026] [security2:error] [pid 10102:tid 10102] [client 35.224.102.120:56994] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.perthdps.com|F|2"] [data ".perthdps.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.perthdps.com"] [uri "/z9x8c7v6b5-debug-trigger-www.perthdps.com"] [unique_id "arFnktdpgChC1XLOqYC0YwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
hostmach
2026-09-21 17:13:13
(3 days ago)
(cpanel) Failed cPanel login from 35.224.102.120 (US/United States/120.102.224.35.bc.googleuserconte ...
show more
(cpanel) Failed cPanel login from 35.224.102.120 (US/United States/120.102.224.35.bc.googleusercontent.com): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CPANEL; Logs: [2026-09-21 13:13:05 -0400] info [webmaild] 35.224.102.120 - - "GET /.aws/credentials HTTP/1.1" FAILED LOGIN webmaild: login attempt without username
[2026-09-21 13:13:05 -0400] info [webmaild] 35.224.102.120 - - "GET /.env.backup HTTP/1.1" FAILED LOGIN webmaild: login attempt without username
[2026-09-21 13:13:06 -0400] info [webmaild] 35.224.102.120 - - "GET /api/v1/settings HTTP/1.1" FAILED LOGIN webmaild: login attempt without username
[2026-09-21 13:13:06 -0400] info [webmaild] 35.224.102.120 - - "GET /.aws/config HTTP/1.1" FAILED LOGIN webmaild: login attempt without username
[2026-09-21 13:13:07 -0400] info [webmaild] 35.224.102.120 - - "GET /config.json HTTP/1.1" FAILED LOGIN webmaild: login attempt without username
show less
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-09-21 16:53:33
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.224.102.120 (120.102.224.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.224.102.120 (120.102.224.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 12:53:27.900479 2026] [security2:error] [pid 11450:tid 11450] [client 35.224.102.120:35226] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.rocketcityhotwheelers.com"] [uri "/.env_1"] [unique_id "arFhB_TAONpE66u8syHkjgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 16:20:12
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.224.102.120 (120.102.224.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.224.102.120 (120.102.224.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 12:20:05.908991 2026] [security2:error] [pid 16065:tid 16065] [client 35.224.102.120:52686] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.margroberts.com"] [uri "/.env.old"] [unique_id "arFZNceoZfHpJ-bQ1q3X8wAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack