๐บ๐ธ
TPI-Abuse
2026-09-21 06:32:00
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.229.33.242 (242.33.229.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.33.242 (242.33.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 02:31:52.146128 2026] [security2:error] [pid 20701:tid 20701] [client 35.229.33.242:48018] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.daveskountrykatering.com"] [uri "/project/.env"] [unique_id "arDPWLy1kj_OBCzlOMgGAQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-09-21 05:34:05
(2 days ago)
csagent: score 18.5: 404 noise floor x34, wp-config backup grab x1; 1 domain(s) in 1s
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 04:33:27
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.229.33.242 (242.33.229.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.33.242 (242.33.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 00:33:22.563048 2026] [security2:error] [pid 18567:tid 18567] [client 35.229.33.242:58820] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.altered-egos.com"] [uri "/.env"] [unique_id "arCzklLKbOxQJb75rtfKbAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 04:09:06
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.229.33.242 (242.33.229.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.33.242 (242.33.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 00:08:58.449744 2026] [security2:error] [pid 27027:tid 27027] [client 35.229.33.242:33496] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.artigelisim.com"] [uri "/@fs/src/.env"] [unique_id "arCt2g0ZIrRjFGjdMnEfuAAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 03:25:54
(2 days ago)
(mod_security) mod_security (id:949110) triggered by 35.229.33.242 (242.33.229.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:949110) triggered by 35.229.33.242 (242.33.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 23:25:47.930705 2026] [security2:error] [pid 3870:tid 3870] [client 35.229.33.242:60916] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "boraborapearlbookings.com"] [uri "/z9x8c7v6b5-debug-trigger-boraborapearlbookings.com"] [unique_id "arCju7CO8ZkN8mmHsa6IkgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
โจ
2026-09-21 02:58:11
(2 days ago)
Domain : business2oz.com
Rule : env
2026-09-21 02:56:23 ***hidden-privacy*** GET /.env.example - 443 ...
show more
Domain : business2oz.com
Rule : env
2026-09-21 02:56:23 ***hidden-privacy*** GET /.env.example - 443 - 35.229.33.242 HTTP/2 DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot) https://business2oz.com/.env.example www.business2oz.com 404 0 2 103 491 96 - -
show less
Hacking
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-09-21 02:46:18
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.229.33.242 (242.33.229.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.33.242 (242.33.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 22:46:15.208587 2026] [security2:error] [pid 2900:tid 2900] [client 35.229.33.242:43280] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.comobarbershop.com"] [uri "/assets/.env"] [unique_id "arCad83k5NKiiOAWcrdyBwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
poundawebsiteltd
2026-09-21 02:45:02
(2 days ago)
Malicious activity in general-malicious. Evidence: (apache_probe) Failed Access (403/404) 35.229.33. ...
show more
Malicious activity in general-malicious. Evidence: (apache_probe) Failed Access (403/404) 35.229.33.242 (US/United States/[REDACTED_DOMAIN]): 20 in the last 3600 secs | UA: (apache_probe) Failed Access (403/404) 35.229.33.242 (US/United States/242.33.229.35.bc.googleusercontent.com): 20 in the last 3600 secs
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 02:28:58
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.229.33.242 (242.33.229.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.33.242 (242.33.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 22:28:52.854218 2026] [security2:error] [pid 3645475:tid 3645475] [client 35.229.33.242:57372] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.cbtattam.com"] [uri "/.env.www"] [unique_id "arCWZPgu9PBmozGdIQKADgAAADE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 01:23:38
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 35.229.33.242 (242.33.229.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.229.33.242 (242.33.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 21:23:34.662663 2026] [security2:error] [pid 31224:tid 31224] [client 35.229.33.242:53964] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.amyisms.com|F|2"] [data ".axd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.amyisms.com"] [uri "/elmah.axd"] [unique_id "arCHFiwY9IBH853dxgekJAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 00:53:01
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.229.33.242 (242.33.229.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.33.242 (242.33.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 20:52:54.318460 2026] [security2:error] [pid 31180:tid 31180] [client 35.229.33.242:41304] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.arsndetx.com"] [uri "/.env.backup"] [unique_id "arB_5jbrnaEP7HbN3o6pUgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 00:10:07
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.229.33.242 (242.33.229.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.33.242 (242.33.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 20:10:03.193829 2026] [security2:error] [pid 15432:tid 15432] [client 35.229.33.242:51638] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "beetreelabs.com"] [uri "/.env.local"] [unique_id "arB120vTVaZYuBQtctM2lAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 23:48:27
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.229.33.242 (242.33.229.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.33.242 (242.33.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 19:48:20.101807 2026] [security2:error] [pid 7174:tid 7174] [client 35.229.33.242:49226] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.brbcash.com"] [uri "/backend/.env"] [unique_id "arBwxLgwTKe4P6YX5DOUEwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 23:22:19
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.229.33.242 (242.33.229.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.33.242 (242.33.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 19:22:15.430070 2026] [security2:error] [pid 17663:tid 17663] [client 35.229.33.242:49198] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.americanlegion935.com"] [uri "/config/.env"] [unique_id "arBqp_Y40lOSJLqnkPq8zQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 22:52:13
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.229.33.242 (242.33.229.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.33.242 (242.33.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 18:52:08.428941 2026] [security2:error] [pid 1451:tid 1451] [client 35.229.33.242:51846] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.celebritybikinigossip.com"] [uri "/.env.example"] [unique_id "arBjmAcsdKZTuF0r9ZbnnwAAAEQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack