๐ฎ๐ช
tarlabs
2026-09-22 01:43:01
(3 days ago)
IP banned by Fail2Ban (traefik-404 jail)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 01:37:36
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 35.234.20.63 (63.20.234.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.234.20.63 (63.20.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 21:37:29.667010 2026] [security2:error] [pid 30317:tid 30317] [client 35.234.20.63:46156] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.djmrmusic.com|F|2"] [data ".djmrmusic.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.djmrmusic.com"] [uri "/z9x8c7v6b5-debug-trigger-www.djmrmusic.com"] [unique_id "arHb2aoJZRtpLdhd9E5QUAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 01:14:43
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.234.20.63 (63.20.234.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.234.20.63 (63.20.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 21:14:36.680603 2026] [security2:error] [pid 27500:tid 27500] [client 35.234.20.63:40324] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.handyrehab.com"] [uri "/.env.production"] [unique_id "arHWfO6q0-WpgbM_7nrQswAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
โจ
2026-09-22 00:12:11
(3 days ago)
Domain : drkevinkelly.com
Rule : env
2026-09-22 00:11:14 ***hidden-privacy*** GET /store/.env - 443 ...
show more
Domain : drkevinkelly.com
Rule : env
2026-09-22 00:11:14 ***hidden-privacy*** GET /store/.env - 443 - 35.234.20.63 HTTP/2 Mozilla/5.0 (compatible; Qwenbot/1.0; https://qwen.alibaba.com/) - www.drkevinkelly.com 404 0 2 1524 449 209 - -
show less
Hacking
SQL Injection
๐ฌ๐ง
thetomtaylor.co.uk
2026-09-21 23:08:00
(3 days ago)
Fail2Ban - [WAF]ModSecurity OWASP CRS rule violation on nginx-modsecurity ... [ice01,ice02]
Hacking
SQL Injection
Web App Attack
Anonymous
2026-09-21 22:40:05
(3 days ago)
| [Dangerous/Taiwan] Aggressive IP 35.234.20.63 (~30 hits). Type: DoS Defender- Web server 400 error ...
show more
| [Dangerous/Taiwan] Aggressive IP 35.234.20.63 (~30 hits). Type: DoS Defender- Web server 400 error code
show less
Web App Attack
Hacking
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-09-21 22:24:49
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.234.20.63 (63.20.234.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.234.20.63 (63.20.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 18:24:42.086411 2026] [security2:error] [pid 31030:tid 31030] [client 35.234.20.63:46194] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.dragonflytunes.com"] [uri "/docker/.env"] [unique_id "arGuqjRgq0C6tW5n_9yTowAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
thetomtaylor.co.uk
2026-09-21 22:07:01
(3 days ago)
Fail2Ban - [WAF]ModSecurity OWASP CRS rule violation on nginx-modsecurity ... [wa01,wa02]
Hacking
SQL Injection
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 21:23:22
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 35.234.20.63 (63.20.234.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.234.20.63 (63.20.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 17:23:15.542007 2026] [security2:error] [pid 20494:tid 20494] [client 35.234.20.63:46388] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||dewsales.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "dewsales.com"] [uri "/rclone.conf"] [unique_id "arGgQ9Y4PRq8KSbyY4bntgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
Burayot
2026-09-21 19:41:01
(3 days ago)
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 35.234.20.63 (TW/Taiwan/63.20.234.35 ...
show more
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 35.234.20.63 (TW/Taiwan/63.20.234.35.bc.googleusercontent.com): 2 in the last 3600 secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 18:33:08
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.234.20.63 (63.20.234.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.234.20.63 (63.20.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 14:33:02.786299 2026] [security2:error] [pid 3986:tid 3986] [client 35.234.20.63:37394] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.drowninglovers.com"] [uri "/utils/.env"] [unique_id "arF4Xid-4Kwd2AK5z1Q3BgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 17:45:33
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.234.20.63 (63.20.234.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.234.20.63 (63.20.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 13:45:26.266052 2026] [security2:error] [pid 29669:tid 29669] [client 35.234.20.63:42424] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.dougrhodes.com"] [uri "/config/.env"] [unique_id "arFtNp4qshlZo8ujPZNiwQAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 15:29:39
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 35.234.20.63 (63.20.234.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.234.20.63 (63.20.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 11:29:33.228632 2026] [security2:error] [pid 16101:tid 16101] [client 35.234.20.63:49564] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||disenowebprofesional.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "disenowebprofesional.com"] [uri "/z9x8c7v6b5-debug-trigger-disenowebprofesional.com"] [unique_id "arFNXYUb0yaRjqckzZCdVgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
ConsulHosting
2026-09-21 15:27:06
(3 days ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
๐ซ๐ท
dynamix
2026-09-21 15:19:48
(3 days ago)
Multiple WAF Violations
Web App Attack