๐บ๐ธ
TPI-Abuse
2026-09-22 01:52:25
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.233.93.132 (132.93.233.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.233.93.132 (132.93.233.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 21:52:19.961715 2026] [security2:error] [pid 7492:tid 7492] [client 35.233.93.132:42682] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.delicioushotspots.com"] [uri "/.git/HEAD"] [unique_id "arHfU0Ld1SQWOtN_AXGnIwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-09-21 23:56:43
(15 hours ago)
211 requests with url.path */@fs/*
Brute-Force
Bad Web Bot
๐ฉ๐ช
TheDjRider
2026-09-21 23:19:25
(16 hours ago)
CrowdSec detected Sensitive file or backup discovery attempt. Scenario: local/apache-sensitive-paths ...
show more
CrowdSec detected Sensitive file or backup discovery attempt. Scenario: local/apache-sensitive-paths. Automatic ban triggered. Detection time (UTC): 2026-09-21T23:19:24.580676331Z. Context: http_status=404
show less
Hacking
Web App Attack
๐ซ๐ท
demomodule
2026-09-21 21:40:59
(18 hours ago)
PrestaShop Security Module: suspicious probe path detected (/.git)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 21:39:41
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.233.93.132 (132.93.233.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.233.93.132 (132.93.233.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 17:39:35.601655 2026] [security2:error] [pid 6050:tid 6050] [client 35.233.93.132:40810] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.dentalcareop.com"] [uri "/.env.example"] [unique_id "arGkF_Ftvb6WxneDK2PB3gAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-21 20:14:30
(19 hours ago)
Aggressive web scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 19:36:40
(20 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.233.93.132 (132.93.233.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.233.93.132 (132.93.233.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 15:36:36.860795 2026] [security2:error] [pid 1473:tid 1473] [client 35.233.93.132:58146] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.derekvantreese.com|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.derekvantreese.com"] [uri "/ssl/localhost.key"] [unique_id "arGHRFoZsJbBOdCPeCRGOAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐พ
Rizzy
2026-09-21 19:10:30
(20 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 16:59:50
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.233.93.132 (132.93.233.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.233.93.132 (132.93.233.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 12:59:44.254908 2026] [security2:error] [pid 30975:tid 30975] [client 35.233.93.132:56362] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.devinfrymire.com"] [uri "/.env.bak"] [unique_id "arFigCZG8rsVUZjWt8cSxgAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-21 16:30:06
(23 hours ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 15:29:56
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.233.93.132 (132.93.233.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.233.93.132 (132.93.233.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 11:29:51.489825 2026] [security2:error] [pid 13606:tid 13846] [client 35.233.93.132:45970] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.dermatologybriargate.com|F|2"] [data ".dermatologybriargate.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.dermatologybriargate.com"] [uri "/z9x8c7v6b5-debug-trigger-www.dermatologybriargate.com"] [unique_id "arFNb3gIZfbgoBGRC7_dxgAAAIs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-21 15:22:38
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 15:12:20
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.233.93.132 (132.93.233.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.233.93.132 (132.93.233.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 11:12:15.690044 2026] [security2:error] [pid 18332:tid 18332] [client 35.233.93.132:37494] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.denniskirlin.com|F|2"] [data ".denniskirlin.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.denniskirlin.com"] [uri "/z9x8c7v6b5-debug-trigger-www.denniskirlin.com"] [unique_id "arFJT5G8avHHd9bGkjNbRAAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-09-21 14:40:04
(1 day ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 14:39:44
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.233.93.132 (132.93.233.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.233.93.132 (132.93.233.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 10:39:40.005395 2026] [security2:error] [pid 28915:tid 28915] [client 35.233.93.132:41624] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||dev.diarrheawolves.com|F|2"] [data ".diarrheawolves.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "dev.diarrheawolves.com"] [uri "/z9x8c7v6b5-debug-trigger-dev.diarrheawolves.com"] [unique_id "arFBrCt8i-5RyF1eiVpsMAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack