๐บ๐ธ
TPI-Abuse
2026-09-22 01:30:29
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 35.236.150.56 (56.150.236.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.150.56 (56.150.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 21:30:26.183479 2026] [security2:error] [pid 13002:tid 13002] [client 35.236.150.56:46772] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.greatchristianadventure.com"] [uri "/store/.env"] [unique_id "arHaMp-V0jUZr8HkB3rlpwAAAF4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 00:57:46
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 35.236.150.56 (56.150.236.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.150.56 (56.150.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 20:57:42.295412 2026] [security2:error] [pid 28049:tid 28049] [client 35.236.150.56:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.grainavi.com"] [uri "/.git/config"] [unique_id "arHShvM8PJH1rKm72wjYUgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
gregoo23
2026-09-22 00:49:22
(5 days ago)
35.236.150.56 - - [22/Sep/2026:10:49:21 +1000] "GET /config.json HTTP/1.1" 404 70275 "-" "Mozilla/5. ...
show more
35.236.150.56 - - [22/Sep/2026:10:49:21 +1000] "GET /config.json HTTP/1.1" 404 70275 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)"
35.236.150.56 - - [22/Sep/2026:10:49:21 +1000] "GET /config.json.js HTTP/1.1" 404 70287 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)"
35.236.150.56 - - [22/Sep/2026:10:49:21 +1000] "GET /env.json HTTP/1.1" 404 70275 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 00:31:29
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 35.236.150.56 (56.150.236.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.150.56 (56.150.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 20:31:22.366925 2026] [security2:error] [pid 6972:tid 7136] [client 35.236.150.56:52526] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.windowtailors.com"] [uri "/.git/config"] [unique_id "arHMWsS2bjhzdx6Bg7s-cAAAANM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-09-21 23:05:24
(5 days ago)
Too many Status 40X (17)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 22:35:43
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 35.236.150.56 (56.150.236.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.236.150.56 (56.150.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 18:35:39.104468 2026] [security2:error] [pid 3946:tid 3946] [client 35.236.150.56:50550] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||googhoo.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "googhoo.com"] [uri "/rclone.conf"] [unique_id "arGxO_ID_ehdFKyrWKRefgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 19:21:28
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 35.236.150.56 (56.150.236.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.150.56 (56.150.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 15:21:20.651622 2026] [security2:error] [pid 28858:tid 28858] [client 35.236.150.56:60348] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.gmsdigita.com"] [uri "/web/.env"] [unique_id "arGDsJw1pEOqJnbH65_ebAAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 19:00:16
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 35.236.150.56 (56.150.236.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.150.56 (56.150.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 15:00:10.199615 2026] [security2:error] [pid 13808:tid 13808] [client 35.236.150.56:57094] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.gotdt.com"] [uri "/.env"] [unique_id "arF-uoPnMFLXUtIfycqb6wAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 18:10:26
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 35.236.150.56 (56.150.236.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.236.150.56 (56.150.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 14:10:21.709596 2026] [security2:error] [pid 5262:tid 5382] [client 35.236.150.56:41426] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.grdsys.com|F|2"] [data ".grdsys.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.grdsys.com"] [uri "/z9x8c7v6b5-debug-trigger-mail.grdsys.com"] [unique_id "arFzDcKWowl_gc4pyb8CeQAAAZA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 17:52:34
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 35.236.150.56 (56.150.236.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.150.56 (56.150.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 13:52:26.870441 2026] [security2:error] [pid 32559:tid 32559] [client 35.236.150.56:45086] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.steinmetzjewelers.com"] [uri "/.git/HEAD"] [unique_id "arFu2m7i1hBDGX4HfTOirQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 17:29:54
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 35.236.150.56 (56.150.236.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.150.56 (56.150.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 13:29:49.551547 2026] [security2:error] [pid 4510:tid 4510] [client 35.236.150.56:40784] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gkerby.com"] [uri "/.env.bak"] [unique_id "arFpjQZUn9VXPYnENw5VCQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฏ๐ต
ki3
2026-09-21 16:47:08
(5 days ago)
Fail2Ban: Web App Attacks and Forum Spam 35.236.150.56 1790009227.0(JST)
Web Spam
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 16:31:29
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 35.236.150.56 (56.150.236.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.236.150.56 (56.150.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 12:31:24.582941 2026] [security2:error] [pid 9543:tid 9543] [client 35.236.150.56:44966] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||grimone.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "grimone.com"] [uri "/z9x8c7v6b5-debug-trigger-grimone.com"] [unique_id "arFb3NnYgfg9ucCGDqUdlQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-21 16:30:10
(5 days ago)
Web attack/malicious scanning detected
Web App Attack
Anonymous
2026-09-21 15:37:14
(5 days ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking