Anonymous
2026-09-21 06:28:26
(1 week ago)
IP matched detection query 50 and more bad rqs apache.
Hacking
Bad Web Bot
Brute-Force
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-21 06:02:31
(1 week ago)
[ti-10al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-10al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 35.234.6.142 - - [21/Sep/2026:08:02:15 +0200] "GET /userfiles?path=../../../../.env HTTP/2.0" 404 1854 "-" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 05:40:35
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.234.6.142 (142.6.234.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.234.6.142 (142.6.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 01:40:30.339786 2026] [security2:error] [pid 15407:tid 15407] [client 35.234.6.142:37918] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.avrknives.com"] [uri "/@fs/app/.env"] [unique_id "arDDTjD_DaSPcWz2aYqV6AAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 05:13:44
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.234.6.142 (142.6.234.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.234.6.142 (142.6.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 01:13:37.021644 2026] [security2:error] [pid 14206:tid 14315] [client 35.234.6.142:56724] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.aisapy.com"] [uri "/agents/.env"] [unique_id "arC9AVM7tXT2LoZ3Yl4lTQAAAdQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐น๐ท
eryilmaz
2026-09-21 04:04:20
(1 week ago)
Automated attack blocked by eryilmaz WAF/defense engine (level 1, source: auto, path: /assets/edit-B ...
show more
Automated attack blocked by eryilmaz WAF/defense engine (level 1, source: auto, path: /assets/edit-BOCSMiId.js)
show less
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-21 03:57:55
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.234.6.142 (142.6.234.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.234.6.142 (142.6.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 23:57:50.060395 2026] [security2:error] [pid 12056:tid 12056] [client 35.234.6.142:34032] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.dragoldio.com"] [uri "/env/.env"] [unique_id "arCrPtbuBjNQRix4M2iTJQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
Burayot
2026-09-21 03:18:17
(1 week ago)
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 35.234.6.142 (TW/Taiwan/142.6.234.35 ...
show more
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 35.234.6.142 (TW/Taiwan/142.6.234.35.bc.googleusercontent.com): 2 in the last 3600 secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 00:37:01
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.234.6.142 (142.6.234.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.234.6.142 (142.6.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 20:36:58.014345 2026] [security2:error] [pid 4442:tid 4442] [client 35.234.6.142:33648] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.austintrauma.com"] [uri "/.env.backup"] [unique_id "arB8KmtWIC19j4G_H0W7TAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-20 23:29:28
(1 week ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-20 23:21:25
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.234.6.142 (142.6.234.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.234.6.142 (142.6.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 19:21:21.157049 2026] [security2:error] [pid 9801:tid 9801] [client 35.234.6.142:43394] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tremulant.com"] [uri "/.git/HEAD"] [unique_id "arBqcZWvoyVTl55xyDc3JwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 22:59:35
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.234.6.142 (142.6.234.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.234.6.142 (142.6.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 18:59:29.276904 2026] [security2:error] [pid 6831:tid 6831] [client 35.234.6.142:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.azdevco.com"] [uri "/.env.www"] [unique_id "arBlURSuso1Et0BpF-tSwgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 22:39:04
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.234.6.142 (142.6.234.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.234.6.142 (142.6.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 18:38:58.151132 2026] [security2:error] [pid 16332:tid 16332] [client 35.234.6.142:36848] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.pamplonaserviciotecnico.com"] [uri "/deploy/.env"] [unique_id "arBggrWDV3Xahgp1R3N5LAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-09-20 22:25:03
(1 week ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 22:08:21
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 35.234.6.142 (142.6.234.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.234.6.142 (142.6.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 18:08:16.059493 2026] [security2:error] [pid 17629:tid 17629] [client 35.234.6.142:49716] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.avalderlaw.com|F|2"] [data ".avalderlaw.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.avalderlaw.com"] [uri "/z9x8c7v6b5-debug-trigger-www.avalderlaw.com"] [unique_id "arBZUG8M-xk1uWosElu0JQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 21:46:41
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.234.6.142 (142.6.234.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.234.6.142 (142.6.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 17:46:35.442497 2026] [security2:error] [pid 3373942:tid 3373942] [client 35.234.6.142:56374] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.tonylai.com"] [uri "/admin/.env"] [unique_id "arBUO_uFbStGko0ihpoO6AAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack