🇺🇸
TPI-Abuse
2026-09-15 22:48:06
(51 minutes ago)
(mod_security) mod_security (id:210492) triggered by 35.227.119.78 (78.119.227.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.227.119.78 (78.119.227.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 18:48:00.858516 2026] [security2:error] [pid 14833:tid 14833] [client 35.227.119.78:57486] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "emmlogistics.com"] [uri "/@fs/var/task/.env"] [unique_id "aqnLIOAujtw0pLzfl-BZrgAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-15 19:30:14
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.227.119.78 (78.119.227.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.227.119.78 (78.119.227.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 15:30:09.173900 2026] [security2:error] [pid 12486:tid 12495] [client 35.227.119.78:51644] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "djkirby.com"] [uri "/.git/config"] [unique_id "aqmcwYiiwd155l_gHQVdYwAAAEc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-15 18:45:13
(4 hours ago)
[dev.backorder.gr] httpd-config-scan: sites=global; logs=/var/log/nginx/access.log; samples=/@fs/pro ...
show more
[dev.backorder.gr] httpd-config-scan: sites=global; logs=/var/log/nginx/access.log; samples=/@fs/proc/self/cmdline?raw?? | /public/plugins/grafana-clock-panel/../../../../../../../../proc/self/environ | /api/w/admins/jobs_u/get_log_file/../../../../proc/self/environ
show less
Hacking
Web App Attack
Anonymous
2026-09-15 18:14:32
(5 hours ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
🇺🇸
TPI-Abuse
2026-09-15 17:57:48
(5 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.227.119.78 (78.119.227.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.227.119.78 (78.119.227.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 13:57:42.874310 2026] [security2:error] [pid 3025:tid 3025] [client 35.227.119.78:57298] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||delomel.net|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "delomel.net"] [uri "/rclone.conf"] [unique_id "aqmHFneiz817tHlucVL3YwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-15 17:47:01
(5 hours ago)
Blocked by ModSec and CSF
Port Scan
🇺🇸
TPI-Abuse
2026-09-15 17:20:36
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.227.119.78 (78.119.227.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.227.119.78 (78.119.227.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 13:20:30.987255 2026] [security2:error] [pid 1617:tid 1617] [client 35.227.119.78:54390] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "daviddenotaris.com"] [uri "/%2e%2e/%2e%2e/%2e%2e/%2e%2e/.env"] [unique_id "aql-XvOFLbsLINopQfiOhgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-15 17:03:58
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.227.119.78 (78.119.227.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.227.119.78 (78.119.227.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 13:03:54.389129 2026] [security2:error] [pid 4329:tid 4329] [client 35.227.119.78:49770] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dansplans.com"] [uri "/static//app/.env"] [unique_id "aql6elCai6H78Ze-2mLLKAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-15 17:03:43
(6 hours ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-15 16:44:57
(6 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.227.119.78 (78.119.227.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.227.119.78 (78.119.227.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 12:44:50.631099 2026] [security2:error] [pid 21758:tid 21758] [client 35.227.119.78:44760] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||dailybeautysupply.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "dailybeautysupply.com"] [uri "/rclone.conf"] [unique_id "aql2Asx52B3L_m2uF1iviwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-15 16:27:04
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.227.119.78 (78.119.227.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.227.119.78 (78.119.227.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 12:26:58.902217 2026] [security2:error] [pid 5956:tid 5956] [client 35.227.119.78:34106] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cvoguemag.com"] [uri "/.git/HEAD"] [unique_id "aqlx0p8DwYM_FKsCDQF6iQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-15 16:04:31
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.227.119.78 (78.119.227.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.227.119.78 (78.119.227.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 12:04:22.841573 2026] [security2:error] [pid 1351:tid 1351] [client 35.227.119.78:59686] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cspminc.com"] [uri "/.htpasswd"] [unique_id "aqlshqX8v5mmaR44FSJHcQAAADs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
poundawebsiteltd
2026-09-15 16:02:36
(7 hours ago)
Malicious activity in general-malicious. Evidence: (apache_probe) Failed Access (403/404) 35.227.119 ...
show more
Malicious activity in general-malicious. Evidence: (apache_probe) Failed Access (403/404) 35.227.119.78 (US/United States/[REDACTED_DOMAIN]): 20 in the last 3600 secs | UA: (apache_probe) Failed Access (403/404) 35.227.119.78 (US/United States/78.119.227.35.bc.googleusercontent.com): 20 in the last 3600 secs
show less
Brute-Force
Web App Attack
🇳🇱
Site.eu
2026-09-15 15:56:03
(7 hours ago)
Excessive 404/403 errors
Brute-Force
🇺🇸
TPI-Abuse
2026-09-15 15:36:38
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.227.119.78 (78.119.227.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.227.119.78 (78.119.227.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 11:36:33.105238 2026] [security2:error] [pid 27678:tid 27678] [client 35.227.119.78:53062] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "creekside.biz"] [uri "/@fs/.env"] [unique_id "aqlmAbrvaWdRNI6zJWQawQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack