๐บ๐ธ
TPI-Abuse
2026-09-20 15:23:21
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.233.131.132 (132.131.233.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.233.131.132 (132.131.233.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 11:23:18.413286 2026] [security2:error] [pid 12033:tid 12033] [client 35.233.131.132:34066] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "furballrecords.com"] [uri "/.env.js"] [unique_id "aq_6Zkmay1wtnp29YN8N3wAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-20 15:16:45
(3 days ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
mnsf
2026-09-20 15:05:12
(3 days ago)
Too many Status 40X (15)
Scanning/Probing (13)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 14:44:18
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 35.233.131.132 (132.131.233.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.233.131.132 (132.131.233.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 10:44:14.287319 2026] [security2:error] [pid 31019:tid 31019] [client 35.233.131.132:54468] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||fulltime-life.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "fulltime-life.com"] [uri "/z9x8c7v6b5-debug-trigger-fulltime-life.com"] [unique_id "aq_xPmkynftQIG7-TgHZtAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 14:03:15
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 35.233.131.132 (132.131.233.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.233.131.132 (132.131.233.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 10:03:09.337941 2026] [security2:error] [pid 2903085:tid 2903085] [client 35.233.131.132:48916] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ftiptondds.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ftiptondds.com"] [uri "/z9x8c7v6b5-debug-trigger-ftiptondds.com"] [unique_id "aq_nnf-2LpXXUfFaaTRQywAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-20 14:02:05
(3 days ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-20 13:52:29
(3 days ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 13:44:18
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 35.233.131.132 (132.131.233.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.233.131.132 (132.131.233.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 09:44:12.490581 2026] [security2:error] [pid 2683:tid 2683] [client 35.233.131.132:42772] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ferienwohnung-buchen.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ferienwohnung-buchen.com"] [uri "/z9x8c7v6b5-debug-trigger-ferienwohnung-buchen.com"] [unique_id "aq_jLANgsfLCEuhAHEAaxwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-20 13:40:56
(3 days ago)
Excessive 404/403 errors
Brute-Force
๐ฉ๐ช
dbmwebdesign
2026-09-20 13:35:30
(3 days ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
๐ฎ๐น
VHosting
2026-09-20 13:25:04
(3 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
robotstxt
2026-09-20 13:21:25
(3 days ago)
35.233.131.132 - - [20/Sep/2026:13:20:45 +0000] "GET /.env.js HTTP/2.0" 403 2 "-" "Mozilla/5.0 (comp ...
show more
35.233.131.132 - - [20/Sep/2026:13:20:45 +0000] "GET /.env.js HTTP/2.0" 403 2 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)" "35.233.131.132" edge="104.22.148.30"
35.233.131.132 - - [20/Sep/2026:13:20:45 +0000] "GET /.aws/credentials HTTP/2.0" 403 36265 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36" "35.233.131.132" edge="104.22.160.57"
35.233.131.132 - - [20/Sep/2026:13:20:45 +0000] "GET /.aws/config HTTP/2.0" 403 36265 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36; compatible; OAI-SearchBot/1.4; +https://openai.com/searchbot" "35.233.131.132" edge="104.22.160.57"
35.233.131.132 - - [20/Sep/2026:13:20:46 +0000] "GET /.env.example HTTP/2.0" 403 2 "-" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)" "35.233.131.132" edge="104.22.160.57"
35.233.131.132 - - [20/Sep/2026:13:20:46 +0000] "GET /.env.backup HTTP/2.0" 403 2 "-" "Mozilla/5.0 (c
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 13:09:20
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 35.233.131.132 (132.131.233.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.233.131.132 (132.131.233.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 09:09:13.058259 2026] [security2:error] [pid 22907:tid 22907] [client 35.233.131.132:41596] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||agenesis7.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "agenesis7.com"] [uri "/z9x8c7v6b5-debug-trigger-agenesis7.com"] [unique_id "aq_a-aWNfxjNzj2VUClQGgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack