πΊπΈ
TPI-Abuse
2026-09-21 05:16:49
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.229.80.85 (85.80.229.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.80.85 (85.80.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 01:16:44.057119 2026] [security2:error] [pid 23959:tid 23959] [client 35.229.80.85:60664] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mymclife.com"] [uri "/api/v1/.env"] [unique_id "arC9vBQAuN2iVsVuGZcw8wAAADE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 04:33:59
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.229.80.85 (85.80.229.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.80.85 (85.80.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 00:33:52.511574 2026] [security2:error] [pid 9035:tid 9068] [client 35.229.80.85:47576] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.miraclearts.com"] [uri "/.env.local"] [unique_id "arCzsEpZGFS1Ajg0gW8Z9AAAANY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 03:31:17
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.229.80.85 (85.80.229.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.80.85 (85.80.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 23:31:09.618079 2026] [security2:error] [pid 25928:tid 25928] [client 35.229.80.85:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.sahinozalit.com"] [uri "/.env.old"] [unique_id "arCk_SeXtpFDMGY7bPxHSwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΏπ¦
conure.sh
2026-09-21 02:28:44
(17 hours ago)
csagent: score 20.0: secrets grab x2; 2 domain(s) in 1s
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 02:23:58
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.229.80.85 (85.80.229.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.80.85 (85.80.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 22:23:53.591385 2026] [security2:error] [pid 11337:tid 11337] [client 35.229.80.85:55150] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.reelfruits.com"] [uri "/.env.old"] [unique_id "arCVOSINlQrtgFNSBY9zgQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 02:03:12
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.229.80.85 (85.80.229.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.80.85 (85.80.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 22:03:06.481039 2026] [security2:error] [pid 4858:tid 4858] [client 35.229.80.85:53962] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.marisetravel.com"] [uri "/userfiles"] [unique_id "arCQWjddNzQVYe_eXEF7wwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 01:17:52
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.229.80.85 (85.80.229.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.80.85 (85.80.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 21:17:45.314764 2026] [security2:error] [pid 21455:tid 21455] [client 35.229.80.85:36146] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.rosemeadefarms.com"] [uri "/.git/HEAD"] [unique_id "arCFudyJLRDg-CvHkf5XDAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¨π¦
polycoda
2026-09-21 01:12:44
(19 hours ago)
AutoBlock: π― Vulnerability Scanner (Non Decay-Based) - π‘ Port Scan (Non Decay-Based)
Port Scan
Hacking
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 00:54:03
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.229.80.85 (85.80.229.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.80.85 (85.80.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 20:53:56.710060 2026] [security2:error] [pid 21078:tid 21078] [client 35.229.80.85:43162] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.newfedco.com"] [uri "/admin/.env"] [unique_id "arCAJGE1HckdpQ3xohZzrAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 00:20:33
(20 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.229.80.85 (85.80.229.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.229.80.85 (85.80.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 20:20:25.216642 2026] [security2:error] [pid 12006:tid 12006] [client 35.229.80.85:59550] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.narrowacresbees.com|F|2"] [data ".narrowacresbees.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.narrowacresbees.com"] [uri "/z9x8c7v6b5-debug-trigger-mail.narrowacresbees.com"] [unique_id "arB4SfWgw5UssKd7fNnuGwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πͺπΈ
masterguru
2026-09-21 00:08:02
(20 hours ago)
Inbound Anomaly Score Exceeded (Total Score: 5). Operator GE matched 5 at TX:anomaly_score. (949110- ...
show more
Inbound Anomaly Score Exceeded (Total Score: 5). Operator GE matched 5 at TX:anomaly_score. (949110-122)
show less
Hacking
πΊπΈ
TPI-Abuse
2026-09-20 23:47:44
(20 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.229.80.85 (85.80.229.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.229.80.85 (85.80.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 19:47:41.383676 2026] [security2:error] [pid 14206:tid 14291] [client 35.229.80.85:43152] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||missmadlove.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "missmadlove.com"] [uri "/z9x8c7v6b5-debug-trigger-missmadlove.com"] [unique_id "arBwnVM7tXT2LoZ3Yl79jgAAAcQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-20 23:14:12
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.229.80.85 (85.80.229.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.80.85 (85.80.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 19:14:07.038160 2026] [security2:error] [pid 10124:tid 10124] [client 35.229.80.85:54006] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.ronelgas.com"] [uri "/api/.env"] [unique_id "arBovzWuci9vlOHBdKSoRAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-20 22:51:36
(21 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.229.80.85 (85.80.229.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.229.80.85 (85.80.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 18:51:28.480175 2026] [security2:error] [pid 13940:tid 13940] [client 35.229.80.85:36394] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.makaihe.com|F|2"] [data ".makaihe.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.makaihe.com"] [uri "/z9x8c7v6b5-debug-trigger-mail.makaihe.com"] [unique_id "arBjcIAI8pjUgNyL2KWwaQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-20 22:30:13
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.229.80.85 (85.80.229.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.80.85 (85.80.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 18:30:07.478100 2026] [security2:error] [pid 26661:tid 26661] [client 35.229.80.85:54234] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.rosecityexpress.com"] [uri "/.env.production"] [unique_id "arBeb1SKhlFb39Ui8mutvQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack