๐บ๐ธ
TPI-Abuse
2026-09-21 05:50:35
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.236.132.106 (106.132.236.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.132.106 (106.132.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 01:50:31.522820 2026] [security2:error] [pid 8877:tid 8877] [client 35.236.132.106:40998] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bfpsamoa.com"] [uri "/@fs/src/.env"] [unique_id "arDFp8nVVNwnH800ydcijAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 05:32:22
(1 week ago)
(mod_security) mod_security (id:210580) triggered by 35.236.132.106 (106.132.236.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210580) triggered by 35.236.132.106 (106.132.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 01:32:14.472114 2026] [security2:error] [pid 9920:tid 9920] [client 35.236.132.106:49064] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at ARGS:vars[1][]. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||www.bigredgraphicdesign.com|F|2"] [data "Matched Data: proc/self/environ found within ARGS:vars[1][]: /proc/self/environ"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "www.bigredgraphicdesign.com"] [uri "/index.php"] [unique_id "arDBXrH1nr7NcUQtfO5G4wAAADc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Apache
2026-09-21 05:05:40
(1 week ago)
(mod_security) mod_security (id:930130) triggered by 35.236.132.106 (TW/Taiwan/106.132.236.35.bc.goo ...
show more
(mod_security) mod_security (id:930130) triggered by 35.236.132.106 (TW/Taiwan/106.132.236.35.bc.googleusercontent.com): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 04:07:36
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.236.132.106 (106.132.236.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.132.106 (106.132.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 00:07:30.792134 2026] [security2:error] [pid 29113:tid 29113] [client 35.236.132.106:33336] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.birdlovesfish.com.lakesidedetectiveagency.com"] [uri "/userfiles"] [unique_id "arCtggy40m8esaTcHXhcuAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 03:52:35
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.236.132.106 (106.132.236.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.132.106 (106.132.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 23:52:29.876224 2026] [security2:error] [pid 370:tid 370] [client 35.236.132.106:48264] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.royal-barbershop.com"] [uri "/private/.env"] [unique_id "arCp_emu9-v1rft2N39V1AAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 02:58:59
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 35.236.132.106 (106.132.236.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.236.132.106 (106.132.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 22:58:54.557993 2026] [security2:error] [pid 13067:tid 13067] [client 35.236.132.106:60828] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.bonegym.com|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.bonegym.com"] [uri "/host.key"] [unique_id "arCdbrQFlnaU1EoIIFVyYwAAAEU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-21 02:54:54
(1 week ago)
Excessive multi-domain requests
Brute-Force
๐ช๐ธ
robotstxt
2026-09-21 02:49:04
(1 week ago)
35.236.132.106 - - [21/Sep/2026:02:48:40 +0000] "GET /webpack-stats.json HTTP/2.0" 403 7739 "-" "Moz ...
show more
35.236.132.106 - - [21/Sep/2026:02:48:40 +0000] "GET /webpack-stats.json HTTP/2.0" 403 7739 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "-" edge="35.236.132.106"
35.236.132.106 - - [21/Sep/2026:02:48:40 +0000] "GET /static/manifest.json HTTP/2.0" 403 7739 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "-" edge="35.236.132.106"
35.236.132.106 - - [21/Sep/2026:02:48:40 +0000] "GET /.git/config HTTP/2.0" 403 8419 "-" "Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)" "-" edge="35.236.132.106"
35.236.132.106 - - [21/Sep/2026:02:48:40 +0000] "GET /dist/manifest.json HTTP/2.0" 403 7739 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "-" edge="35.236.132.106"
35.236.132.106 - - [21/Sep/2026:02:48:40 +0000] "GET /.env.stage HTTP/2.0" 403 8419 "-" "Mozilla/5.0 (comp
...
show less
Web App Attack
๐ช๐ธ
robotstxt
2026-09-21 02:23:41
(1 week ago)
35.236.132.106 - - [21/Sep/2026:02:22:38 +0000] "GET /.env.php.bak HTTP/2.0" 403 189 "-" "Mozilla/5. ...
show more
35.236.132.106 - - [21/Sep/2026:02:22:38 +0000] "GET /.env.php.bak HTTP/2.0" 403 189 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)"
35.236.132.106 - - [21/Sep/2026:02:22:38 +0000] "GET /config/.env.php HTTP/2.0" 403 197 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36; compatible; OAI-SearchBot/1.4; +https://openai.com/searchbot"
35.236.132.106 - - [21/Sep/2026:02:22:39 +0000] "GET /wp/.env HTTP/2.0" 403 189 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)"
35.236.132.106 - - [21/Sep/2026:02:22:39 +0000] "GET /storage/.env HTTP/2.0" 403 189 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)"
35.236.132.106 - - [21/Sep/2026:02:22:39 +0000] "GET /.env.swp HTTP/2.0" 403 189 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 00:34:07
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.236.132.106 (106.132.236.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.132.106 (106.132.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 20:34:02.536291 2026] [security2:error] [pid 560:tid 560] [client 35.236.132.106:39130] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.alessiaalessandra.com"] [uri "/.env.production"] [unique_id "arB7eurhVUupbYm_XtcCYAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 00:12:24
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.236.132.106 (106.132.236.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.132.106 (106.132.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 20:12:19.889257 2026] [security2:error] [pid 29095:tid 29095] [client 35.236.132.106:45618] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.boat-registration-croatia.com"] [uri "/.git/config"] [unique_id "arB2Y_GqM0Zwk0ETghOSpQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-09-21 00:05:22
(1 week ago)
Too many Status 40X (11)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 23:12:04
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.236.132.106 (106.132.236.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.132.106 (106.132.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 19:11:56.853187 2026] [security2:error] [pid 9796:tid 9796] [client 35.236.132.106:32878] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.bocafloorsusa.digitalmarketing-group.com"] [uri "/.env.example"] [unique_id "arBoPF9JWxxs_k-VKrkrFAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-20 23:04:17
(1 week ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 22:51:29
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 35.236.132.106 (106.132.236.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.236.132.106 (106.132.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 18:51:23.927633 2026] [security2:error] [pid 28925:tid 28951] [client 35.236.132.106:50504] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.juantrece.com|F|2"] [data ".juantrece.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.juantrece.com"] [uri "/z9x8c7v6b5-debug-trigger-www.juantrece.com"] [unique_id "arBjay0c0wa8yTB0LPyNyQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack