๐บ๐ธ
TPI-Abuse
2026-09-22 01:39:17
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 35.234.57.138 (138.57.234.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.234.57.138 (138.57.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 21:39:12.302560 2026] [security2:error] [pid 18614:tid 18614] [client 35.234.57.138:45262] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.formationone.com.kooroshvaziri.com|F|2"] [data ".formationone.com.kooroshvaziri.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.formationone.com.kooroshvaziri.com"] [uri "/z9x8c7v6b5-debug-trigger-www.formationone.com.kooroshvaziri.com"] [unique_id "arHcQH_LQgm-ALRxnl4HuAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐น๐ญ
thaizone.com
2026-09-22 01:07:58
(1 week ago)
Hacking attempts against websites (D1) #1
Web App Attack
Hacking
๐ฌ๐ง
abivia
2026-09-22 00:58:12
(1 week ago)
Abivia WAF trigger: Rule scriptKiddies: Dot file access. uri: /.git-credentials
Hacking
๐ณ๐ฑ
Site.eu
2026-09-22 00:23:00
(1 week ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-22 00:05:30
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.234.57.138 (138.57.234.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.234.57.138 (138.57.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 20:05:22.312492 2026] [security2:error] [pid 30633:tid 30736] [client 35.234.57.138:42690] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.forestvalleyranch.com"] [uri "/.git/HEAD"] [unique_id "arHGQsbHdU-pqdnv8ZJAbgAAAQI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 23:31:53
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.234.57.138 (138.57.234.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.234.57.138 (138.57.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 19:31:50.020337 2026] [security2:error] [pid 30986:tid 30986] [client 35.234.57.138:53430] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.abecasis.com"] [uri "/.git/config"] [unique_id "arG-Ztjn9vsm2cuSKUtJyAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
middelkoopcc
2026-09-21 23:09:00
(1 week ago)
2026-09-22 01:07:40 GET /.aws/credentials [301] && 2026-09-22 01:07:40 GET /.env.backup [301] && 202 ...
show more
2026-09-22 01:07:40 GET /.aws/credentials [301] && 2026-09-22 01:07:40 GET /.env.backup [301] && 2026-09-22 01:07:40 GET /.aws/config [301] && 106 more within 20 minutes
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 22:43:04
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.234.57.138 (138.57.234.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.234.57.138 (138.57.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 18:42:56.375327 2026] [security2:error] [pid 9143:tid 9143] [client 35.234.57.138:60390] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.flightclaimservices.com"] [uri "/.git/config"] [unique_id "arGy8Bpkmi3OZhys-pSdpAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 20:54:46
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.234.57.138 (138.57.234.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.234.57.138 (138.57.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 16:54:37.677074 2026] [security2:error] [pid 11254:tid 11254] [client 35.234.57.138:59922] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.flyingwithstan.com"] [uri "/.env.js"] [unique_id "arGZjYBS0AdgG5AKoOjJQQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 17:17:53
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 35.234.57.138 (138.57.234.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.234.57.138 (138.57.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 13:17:47.983496 2026] [security2:error] [pid 18621:tid 18621] [client 35.234.57.138:42012] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.interforce.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.interforce.com"] [uri "/rclone.conf"] [unique_id "arFmu1ZDFN5NTCWSblaKZQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 16:41:18
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.234.57.138 (138.57.234.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.234.57.138 (138.57.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 12:41:10.855870 2026] [security2:error] [pid 23996:tid 23996] [client 35.234.57.138:55806] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.cajunfriedturkey.com"] [uri "/api/.env"] [unique_id "arFeJte0bLHzWJCIqDjr_AAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 15:39:33
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 35.234.57.138 (138.57.234.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.234.57.138 (138.57.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 11:39:25.104815 2026] [security2:error] [pid 752:tid 752] [client 35.234.57.138:35068] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.78cardsofthetarot-tarotmancy-tarot-cards-and-tarot-readings.com|F|2"] [data ".78cardsofthetarot-tarotmancy-tarot-cards-and-tarot-readings.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.78cardsofthetarot-tarotmancy-tarot-cards-and-tarot-readings.com"] [uri "/z9x8c7v6b5-debug-trigger-mail.78cardsofthetarot-tarotmancy-tarot-cards-and-tarot-readings.com"] [unique_id "arFPrWMtesH2vmi7vNPYwgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-21 15:29:33
(1 week ago)
23 attempts against mh-misbehave-ban on twig
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-09-21 15:25:09
(1 week ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 15:19:07
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 35.234.57.138 (138.57.234.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.234.57.138 (138.57.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 11:19:01.858178 2026] [security2:error] [pid 6540:tid 6540] [client 35.234.57.138:57504] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||rooksfamily.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "rooksfamily.com"] [uri "/z9x8c7v6b5-debug-trigger-rooksfamily.com"] [unique_id "arFK5UHIaJ8rETaLm0tNSgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack