Anonymous
2026-09-25 03:46:19
(23 hours ago)
Bad Web Bot
Anonymous
2026-09-24 03:46:16
(1 day ago)
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-22 01:18:17
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 35.231.145.245 (245.145.231.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.231.145.245 (245.145.231.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 21:18:11.032118 2026] [security2:error] [pid 27717:tid 27717] [client 35.231.145.245:48348] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.auditleverage.com"] [uri "/client/.env"] [unique_id "arHXUzeoOi4P0sX3JZPBBwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ฌ
Cloudkul Cloudkul
2026-09-22 00:32:02
(4 days ago)
Attempted Not Found (404 status code) requests on our application, more than 30% of their total requ ...
show more
Attempted Not Found (404 status code) requests on our application, more than 30% of their total requests.
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 00:27:23
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 35.231.145.245 (245.145.231.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.231.145.245 (245.145.231.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 20:27:19.200213 2026] [security2:error] [pid 30553:tid 30553] [client 35.231.145.245:33400] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||test.grabnerconsulting.com|F|2"] [data ".grabnerconsulting.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "test.grabnerconsulting.com"] [uri "/z9x8c7v6b5-debug-trigger-test.grabnerconsulting.com"] [unique_id "arHLZ3cWNU50pTU2CgzN2QAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
IndigoRidge
2026-09-21 22:04:54
(4 days ago)
[Mon Sep 21 18:04:52.928137 2026] [authz_core:error] [pid 2890161:tid 140581074343680] [client 35.23 ...
show more
[Mon Sep 21 18:04:52.928137 2026] [authz_core:error] [pid 2890161:tid 140581074343680] [client 35.231.145.245:0] AH01630: client denied by server configuration: /usr/share/psa-roundcube/api
[Mon Sep 21 18:04:52.981796 2026] [authz_core:error] [pid 2776598:tid 140581208561408] [client 35.231.145.245:0] AH01630: client denied by server configuration: /usr/share/psa-roundcube/graphql
[Mon Sep 21 18:04:53.642359 2026] [authz_core:error] [pid 2890161:tid 140581107914496] [client 35.231.145.245:0] AH01630: client denied by server configuration: /usr/share/psa-roundcube/credentials.js
[Mon Sep 21 18:04:53.832406 2026] [authz_core:error] [pid 2890161:tid 140581091129088] [client 35.231.145.245:0] AH01630: client denied by server configuration: /usr/share/psa-roundcube/common
[Mon Sep 21 18:04:54.239074 2026] [authz_core:error] [pid 2776599:tid 140582433175296] [client 35.231.145.245:0] AH01630: client denied by server configuration: /usr/share/psa-roundcube/static
...
show less
Web App Attack
๐บ๐ธ
mnsf
2026-09-21 21:05:39
(4 days ago)
Scanning/Probing (11)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 20:14:51
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 35.231.145.245 (245.145.231.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.231.145.245 (245.145.231.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 16:14:44.477358 2026] [security2:error] [pid 29346:tid 29346] [client 35.231.145.245:56860] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.b9k9.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.b9k9.com"] [uri "/rclone.conf"] [unique_id "arGQNN8OshNM-RuVn3yB-AAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 19:11:56
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 35.231.145.245 (245.145.231.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.231.145.245 (245.145.231.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 15:11:51.264484 2026] [security2:error] [pid 30451:tid 30451] [client 35.231.145.245:58408] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.avaliantlife.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.avaliantlife.com"] [uri "/rclone.conf"] [unique_id "arGBd_v7q8v4gTvbD_HGCAAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Mundo Bueno
2026-09-21 18:46:55
(4 days ago)
[ISILIA Protection v2.3] Tentative d'accรจs: /server/.env [RATE LIMITED - 1800s quarantine] | Pays: U ...
show more
[ISILIA Protection v2.3] Tentative d'accรจs: /server/.env [RATE LIMITED - 1800s quarantine] | Pays: US | UA: Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 17:52:04
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 35.231.145.245 (245.145.231.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.231.145.245 (245.145.231.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 13:51:56.852549 2026] [security2:error] [pid 13339:tid 13339] [client 35.231.145.245:43906] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.babyshowernapkins.com"] [uri "/.git/HEAD"] [unique_id "arFuvMMONWzzSCsADNKPGgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-21 16:05:06
(4 days ago)
WAF repeated trigger detected by Fail2Ban
Web App Attack
Anonymous
2026-09-21 15:28:01
(4 days ago)
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-21 15:06:39
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 35.231.145.245 (245.145.231.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.231.145.245 (245.145.231.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 11:06:34.862517 2026] [security2:error] [pid 15034:tid 15034] [client 35.231.145.245:35558] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.avmcyber.com|F|2"] [data ".avmcyber.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.avmcyber.com"] [uri "/z9x8c7v6b5-debug-trigger-www.avmcyber.com"] [unique_id "arFH-lDAQHZ1ISMPVPsAAgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 14:40:03
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 35.231.145.245 (245.145.231.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.231.145.245 (245.145.231.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 10:39:58.644160 2026] [security2:error] [pid 276543:tid 276543] [client 35.231.145.245:55380] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.azpinklimos.com|F|2"] [data ".azpinklimos.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.azpinklimos.com"] [uri "/z9x8c7v6b5-debug-trigger-mail.azpinklimos.com"] [unique_id "arFBvgug4cUBsawN3Dg7uwAAAEA"]
show less
Brute-Force
Bad Web Bot
Web App Attack