๐บ๐ธ
TPI-Abuse
2026-09-22 00:01:53
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.236.128.139 (139.128.236.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.236.128.139 (139.128.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 20:01:49.230311 2026] [security2:error] [pid 31036:tid 31036] [client 35.236.128.139:49804] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.furballaudio.com|F|2"] [data ".furballaudio.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.furballaudio.com"] [uri "/z9x8c7v6b5-debug-trigger-www.furballaudio.com"] [unique_id "arHFbUPrCQ22zaIDgedlSQAAADc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 23:33:59
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.236.128.139 (139.128.236.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.128.139 (139.128.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 19:33:54.077329 2026] [security2:error] [pid 8517:tid 8542] [client 35.236.128.139:52138] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.m3sxa.com"] [uri "/.env.js"] [unique_id "arG-4me8CTWTIbhP1u4qVAAAAJc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-21 23:16:29
(1 day ago)
[ti-07al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-07al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 35.236.128.139 - - [22/Sep/2026:01:16:29 +0200] "GET /.env.backup HTTP/1.1" 404 2050 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 23:02:00
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.236.128.139 (139.128.236.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.128.139 (139.128.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 19:01:54.138882 2026] [security2:error] [pid 9676:tid 9676] [client 35.236.128.139:35494] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.gervais-family.com"] [uri "/.env.js"] [unique_id "arG3YuHsEXK67POUXYt5wgAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 22:20:28
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.236.128.139 (139.128.236.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.236.128.139 (139.128.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 18:20:24.428747 2026] [security2:error] [pid 28759:tid 28759] [client 35.236.128.139:35500] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.garysgates.com|F|2"] [data ".garysgates.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.garysgates.com"] [uri "/z9x8c7v6b5-debug-trigger-www.garysgates.com"] [unique_id "arGtqLLIJnkjo8CpPoRo1AAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-21 22:09:14
(1 day ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
NewGastroline
2026-09-21 20:17:21
(1 day ago)
Malicious request blocked by CrowdSec on gastro-prod1.boreus.de
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 20:11:28
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.236.128.139 (139.128.236.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.128.139 (139.128.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 16:11:23.349689 2026] [security2:error] [pid 665760:tid 665760] [client 35.236.128.139:44600] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.geo-modal.com"] [uri "/.env.production"] [unique_id "arGPa1GsYJAEMQzXJ4cOcgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 19:36:44
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.236.128.139 (139.128.236.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.128.139 (139.128.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 15:36:35.576510 2026] [security2:error] [pid 3552:tid 3552] [client 35.236.128.139:44656] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.geriking.com"] [uri "/.env.js"] [unique_id "arGHQ1F3kgks8jYzXPxEyQAAADw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 18:21:56
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.236.128.139 (139.128.236.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.236.128.139 (139.128.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 14:21:48.994356 2026] [security2:error] [pid 11287:tid 11287] [client 35.236.128.139:46526] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||gamepart.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "gamepart.com"] [uri "/z9x8c7v6b5-debug-trigger-gamepart.com"] [unique_id "arF1vNeMKzd7Q08aa7HeRwAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 17:55:12
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.236.128.139 (139.128.236.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.128.139 (139.128.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 13:55:05.020904 2026] [security2:error] [pid 32517:tid 32517] [client 35.236.128.139:45988] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.ftwwx.com"] [uri "/config/.env"] [unique_id "arFveXfptpnedWv597gkHQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-21 17:05:02
(1 day ago)
crowdsecurity/http-cve-2021-41773
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 17:01:22
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.236.128.139 (139.128.236.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.128.139 (139.128.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 13:01:14.135837 2026] [security2:error] [pid 8523:tid 8523] [client 35.236.128.139:55018] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gdg1.com"] [uri "/.git/HEAD"] [unique_id "arFi2naPP4UhxkCEpo6qUAAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 15:40:55
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.236.128.139 (139.128.236.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.128.139 (139.128.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 11:40:50.506591 2026] [security2:error] [pid 2565:tid 2565] [client 35.236.128.139:44676] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.garthp.com"] [uri "/@fs/.env"] [unique_id "arFQAikt04CqgjQhRyss0gAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
CoreTech srl
2026-09-21 15:38:51
(1 day ago)
cloudlinux2 fail2ban: 2026-09-21 17:34:37,766 fail2ban.filter [1598]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-21 17:34:37,766 fail2ban.filter [1598]: INFO [plesk-modsecurity] Found 154.192.169.83 - 2026-09-21 17:34:37cloudlinux2 fail2ban: 2026-09-21 17:34:48,670 fail2ban.actions [1598]: NOTICE [plesk-modsecurity] Ban 154.192.169.83cloudlinux2 fail2ban: 2026-09-21 17:34:48,677 fail2ban.filter [1598]: INFO [recidive] Found 154.192.169.83 - 2026-09-21 17:34:48cloudlinux2 fail2ban: 2026-09-21 17:34:48,391 fail2ban.filter [1598]: INFO [plesk-modsecurity] Found 154.192.169.83 - 2026-09-21 17:34:48cloudlinux2 fail2ban: 2026-09-21 17:36:20,609 fail2ban.filter [1598]: INFO [plesk-wordpress] Found 142.93.146.244 - 2026-09-21 17:36:19cloudlinux2 fail2ban: 2026-09-21 17:36:17,182 fail2ban.actions [1598]: NOTICE [plesk-wordpress] Unban 142.93.146.244cloudlinux2 fail2ban: 2026-09-21 17:36:56,275 fail2ban.filter [1598]: INFO [plesk-wordpress] Found 142.93.146.244 - 2026-09-21 17:36:55cloudlinux2 fail2ban: 2026-09-21 17:37:22,125 fai
show less
Web App Attack