๐บ๐ธ
TPI-Abuse
2026-09-21 05:06:28
(19 hours ago)
(mod_security) mod_security (id:243320) triggered by 35.236.173.209 (209.173.236.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:243320) triggered by 35.236.173.209 (209.173.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 01:06:24.446742 2026] [security2:error] [pid 22899:tid 22899] [client 35.236.173.209:44600] ModSecurity: Access denied with code 403 (phase 2). String match "/.profile" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6621"] [id "243320"] [rev "1"] [msg "COMODO WAF: Information disclosure vulnerability in Cloud Foundry PHP Buildpack (aka php-buildpack) before 4.3.18 and PHP Buildpack Cf-release before 242, as used in Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.6.38 and 1.7.x before 1.7.19 and other products (CVE-2016-6639)||www.turquoisetidestravel.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.turquoisetidestravel.com"] [uri "/.profile"] [unique_id "arC7ULFznbSGS3IByh0kBQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 04:31:50
(19 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.236.173.209 (209.173.236.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.236.173.209 (209.173.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 00:31:44.367948 2026] [security2:error] [pid 21128:tid 21128] [client 35.236.173.209:57836] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.clickbigdeals.com|F|2"] [data ".clickbigdeals.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.clickbigdeals.com"] [uri "/z9x8c7v6b5-debug-trigger-mail.clickbigdeals.com"] [unique_id "arCzMNMjjKidqQqxH3bUvQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-21 03:46:35
(20 hours ago)
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .backup/ ...
show more
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .compositefont/ .config/ .conf/ .crt/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dist/ .dll/ .dos/ .dpkg-dist/ .drv/ .gadget/ .hta/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .inf/ .ini/ .jse/ .key/ .licx/ .lnk/ .log/ .mdb/ .msc/ .ocx/ .old/ .pass/ .pdb/ .pfx/ .pif/ .pem/ .pol/ .prf/ .printer/ .pwd/ .rdb/ .rdp/ .reg/ .resources/ .resx/ .scr/ .sct/ .shs/ .sql/ .swp/ .sys/ .tlb/ .tmp/ .url/ .vb/ .vbe/ .vbs/ .vbproj/ .vsdisco/ .vxd/ .webinfo/ .ws/ .wsc/ .wsf/ .wsh/ .xsd/ .xsx/" at TX:extension. (920440-196)
show less
Hacking
๐ฌ๐ง
consul.to
2026-09-21 03:24:08
(20 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 01:00:53
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.236.173.209 (209.173.236.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.173.209 (209.173.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 21:00:49.930231 2026] [security2:error] [pid 10457:tid 10457] [client 35.236.173.209:35378] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.netcastcorp.com"] [uri "/.git/HEAD"] [unique_id "arCBwcT-IAsdbeRkSS3zvQAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 00:12:37
(23 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.236.173.209 (209.173.236.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.236.173.209 (209.173.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 20:12:30.992684 2026] [security2:error] [pid 1355:tid 1355] [client 35.236.173.209:44002] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.comicpreservation.com|F|2"] [data ".comicpreservation.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.comicpreservation.com"] [uri "/z9x8c7v6b5-debug-trigger-mail.comicpreservation.com"] [unique_id "arB2boAHvuKtfHypqK3MtQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
thieuleu
2026-09-20 23:41:07
(1 day ago)
Unauthorized connection attempt blocked by firewall policy. Web application hardening active.
Brute-Force
Exploited Host
๐ฉ๐ช
IVski.com
2026-09-20 23:25:36
(1 day ago)
IVski WAF | WordPress REST API probe - accessing /wp-json
Hacking
Brute-Force
Web App Attack
๐ฉ๐ช
netclix.gr
2026-09-20 22:54:55
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted] 35.236.173.209 (TW/Taiwan/209.173.236.3 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.236.173.209 (TW/Taiwan/209.173.236.35.bc.googleusercontent.com): (CF_ENABLE)
show less
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-09-20 22:50:06
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.236.173.209 (209.173.236.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.236.173.209 (209.173.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 18:49:58.649951 2026] [security2:error] [pid 19276:tid 19290] [client 35.236.173.209:60568] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.cmykdesign.com|F|2"] [data ".cmykdesign.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.cmykdesign.com"] [uri "/z9x8c7v6b5-debug-trigger-www.cmykdesign.com"] [unique_id "arBjFtl92C-N9XSG9E22qgAAAEw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 21:50:21
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.236.173.209 (209.173.236.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.173.209 (209.173.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 17:50:17.030285 2026] [security2:error] [pid 17580:tid 17580] [client 35.236.173.209:48650] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.combustionlogic.com"] [uri "/.htpasswd"] [unique_id "arBVGRIs-YGsJCqqRtYAlQAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 21:31:36
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.236.173.209 (209.173.236.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.173.209 (209.173.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 17:31:29.719368 2026] [security2:error] [pid 18252:tid 18252] [client 35.236.173.209:36526] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.colorwize.com"] [uri "/.env.local"] [unique_id "arBQsTIuo4i9N2EwSlSH3gAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-20 20:58:17
(1 day ago)
[ti-01ov] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 35. ...
show more
[ti-01ov] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 35.236.173.209 - - [20/Sep/2026:22:58:16 +0200] "GET /backend/.env HTTP/1.1" 301 603 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36; compatible; OAI-SearchBot/1.4; +https://openai.com/searchbot"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
nationaleventpros.com
2026-09-20 20:53:42
(1 day ago)
vulnerability scan
Web App Attack
๐ฎ๐น
VHosting
2026-09-20 20:50:03
(1 day ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack