๐บ๐ธ
TPI-Abuse
2026-09-24 06:41:58
(20 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.231.84.193 (193.84.231.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.231.84.193 (193.84.231.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 02:41:53.445451 2026] [security2:error] [pid 9536:tid 9626] [client 35.231.84.193:45128] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.wwobb2.wwwhst.com|F|2"] [data ".wwobb2.wwwhst.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.wwobb2.wwwhst.com"] [uri "/z9x8c7v6b5-debug-trigger-www.wwobb2.wwwhst.com"] [unique_id "arTGMS5NSpcc2uzNSqYJAQAAAVA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
Christopher Hughes
2026-09-24 06:23:18
(20 hours ago)
35.231.84.193 - - [24/Sep/2026:07:23:18 +0100] "GET /backend/.env HTTP/2.0" 200 1455 "-" "Mozilla/5. ...
show more
35.231.84.193 - - [24/Sep/2026:07:23:18 +0100] "GET /backend/.env HTTP/2.0" 200 1455 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 06:18:07
(20 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.231.84.193 (193.84.231.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.231.84.193 (193.84.231.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 02:18:00.099058 2026] [security2:error] [pid 14718:tid 14718] [client 35.231.84.193:45378] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.ww-bbs.com|F|2"] [data ".ww-bbs.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.ww-bbs.com"] [uri "/z9x8c7v6b5-debug-trigger-www.ww-bbs.com"] [unique_id "arTAmGGqa5d6gbJdDAzhsgAAAEA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-24 04:55:01
(21 hours ago)
suspicious request in access.log
Web App Attack
๐ช๐ธ
robotstxt
2026-09-24 04:41:18
(22 hours ago)
35.231.84.193 - - [24/Sep/2026:04:41:12 +0000] "POST / HTTP/2.0" 403 24973 "-" "Mozilla/5.0 (compati ...
show more
35.231.84.193 - - [24/Sep/2026:04:41:12 +0000] "POST / HTTP/2.0" 403 24973 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)" "-" edge="35.231.84.193"
35.231.84.193 - - [24/Sep/2026:04:41:13 +0000] "GET /dist/manifest.json HTTP/2.0" 403 16172 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 Edg/153.0.0.0" "-" edge="35.231.84.193"
35.231.84.193 - - [24/Sep/2026:04:41:13 +0000] "GET /dist/.vite/manifest.json HTTP/2.0" 403 16172 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 Edg/153.0.0.0" "-" edge="35.231.84.193"
35.231.84.193 - - [24/Sep/2026:04:41:13 +0000] "GET /4bauhpyta4fpqaf6jvfg/ HTTP/2.0" 403 16891 "https://www.wpsysadmin.com/4bauhpyta4fpqaf6jvfg" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )" "-" edge="35.231.84.193"
35.231.84.193 - - [24/Sep/2026:04:
...
show less
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2026-09-24 03:34:04
(23 hours ago)
(modsecurity) srv101 ModSecurity 35.231.84.193 (US/United States/193.84.231.35.bc.googleusercontent. ...
show more
(modsecurity) srv101 ModSecurity 35.231.84.193 (US/United States/193.84.231.35.bc.googleusercontent.com): 30 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-24 03:02:32
(23 hours ago)
[ti-26al] Web exploit scanning: 2 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-26al] Web exploit scanning: 2 suspicious requests detected by fail2ban jail apache-scanner. Example: 35.231.84.193 - - [24/Sep/2026:05:02:23 +0200] "GET //.env HTTP/1.1" 301 569 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36; compatible; OAI-SearchBot/1.4; +https://openai.com/searchbot"
35.231.84.193 - - [24/Sep/2026:05:02:23 +0200] "GET /@fs/src/.env?raw?? HTTP/1.1" 301 597 "-" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)"
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-24 02:44:57
(1 day ago)
Aggressive web scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 23:44:33
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.231.84.193 (193.84.231.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.231.84.193 (193.84.231.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 19:44:25.325185 2026] [security2:error] [pid 11320:tid 11342] [client 35.231.84.193:49404] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.wp.havacubvision.com|F|2"] [data ".wp.havacubvision.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.wp.havacubvision.com"] [uri "/z9x8c7v6b5-debug-trigger-www.wp.havacubvision.com"] [unique_id "arRkWf1ds3dQqIfJIqnmSgAAAVQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
robotstxt
2026-09-23 22:28:06
(1 day ago)
35.231.84.193 - - [23/Sep/2026:22:27:30 +0000] "GET /dist/.vite/manifest.json HTTP/2.0" 403 36322 "h ...
show more
35.231.84.193 - - [23/Sep/2026:22:27:30 +0000] "GET /dist/.vite/manifest.json HTTP/2.0" 403 36322 "https://www.blimburnseeds.com/dist/.vite/manifest.json" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "35.231.84.193" edge="162.159.106.123"
35.231.84.193 - - [23/Sep/2026:22:27:30 +0000] "GET /.vite/manifest.json HTTP/2.0" 403 36322 "https://www.blimburnseeds.com/.vite/manifest.json" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "35.231.84.193" edge="162.159.106.183"
35.231.84.193 - - [23/Sep/2026:22:27:31 +0000] "GET /.env.save HTTP/2.0" 403 2 "https://www.blimburnseeds.com/.env.save" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)" "35.231.84.193" edge="104.22.118.25"
35.231.84.193 - - [23/Sep/2026:22:27:31 +0000] "GET /.env.prod HTTP/2.0" 403 2 "https://www.blimburnse
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 21:25:12
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.231.84.193 (193.84.231.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.231.84.193 (193.84.231.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 17:25:08.317070 2026] [security2:error] [pid 25652:tid 25652] [client 35.231.84.193:45086] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||amybeam.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "amybeam.com"] [uri "/z9x8c7v6b5-debug-trigger-amybeam.com"] [unique_id "arRDtMFc1PDLtUMHkngXDAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
robotstxt
2026-09-23 21:10:02
(1 day ago)
35.231.84.193 - - [23/Sep/2026:21:09:01 +0000] "GET /.vite/manifest.json HTTP/2.0" 403 36322 "-" "Mo ...
show more
35.231.84.193 - - [23/Sep/2026:21:09:01 +0000] "GET /.vite/manifest.json HTTP/2.0" 403 36322 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "35.231.84.193" edge="162.159.106.183"
35.231.84.193 - - [23/Sep/2026:21:09:04 +0000] "GET /.dockerenv HTTP/2.0" 403 2 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)" "35.231.84.193" edge="104.22.56.73"
35.231.84.193 - - [23/Sep/2026:21:09:05 +0000] "GET /.env.local?raw HTTP/2.0" 403 36322 "-" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/)" "35.231.84.193" edge="104.22.56.73"
35.231.84.193 - - [23/Sep/2026:21:09:05 +0000] "GET /.env.production?raw HTTP/2.0" 403 36322 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)" "35.231.84.193" edge="104.22.56.73"
35.231.84.193 - - [23/Sep/2026:21:09:05 +0000] "GET /.env.local?import&raw HTTP/2.0" 403 36322 "-" "Mozilla/5.0 (compatible; Gr
...
show less
Web App Attack
๐ซ๐ท
demomodule
2026-09-23 20:39:45
(1 day ago)
PrestaShop Security Module: suspicious probe path detected (/.env)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 20:35:42
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.231.84.193 (193.84.231.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.231.84.193 (193.84.231.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 16:35:35.454119 2026] [security2:error] [pid 9484:tid 9484] [client 35.231.84.193:41640] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||dockrockukiah.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "dockrockukiah.com"] [uri "/z9x8c7v6b5-debug-trigger-dockrockukiah.com"] [unique_id "arQ4F3OD55E7qw_P4thipQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 20:14:10
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.231.84.193 (193.84.231.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.231.84.193 (193.84.231.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 16:14:05.293337 2026] [security2:error] [pid 22702:tid 22702] [client 35.231.84.193:58580] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||fritsknuf.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "fritsknuf.com"] [uri "/z9x8c7v6b5-debug-trigger-fritsknuf.com"] [unique_id "arQzDXa59Ivs7t2jDfBVeAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack