🇺🇸
factor1
2026-09-13 17:42:21
(2 minutes ago)
CrowdSec at apollo Reports Abuse
Web App Attack
Anonymous
2026-09-13 17:29:19
(15 minutes ago)
Aggressive web scan
Web App Attack
Anonymous
2026-09-13 17:02:18
(42 minutes ago)
(mod_security) mod_security triggered on hostname [redacted] 35.236.84.41 (US/United States/41.84.23 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.236.84.41 (US/United States/41.84.236.35.bc.googleusercontent.com)
show less
SQL Injection
🇺🇸
TPI-Abuse
2026-09-13 16:47:42
(57 minutes ago)
(mod_security) mod_security (id:210730) triggered by 35.236.84.41 (41.84.236.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.236.84.41 (41.84.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 12:47:35.713134 2026] [security2:error] [pid 7677:tid 7677] [client 35.236.84.41:57310] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||deckmasterscompany.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "deckmasterscompany.com"] [uri "/z9x8c7v6b5-debug-trigger-deckmasterscompany.com"] [unique_id "aqbTp8OGnde-j3A28cYiHQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 16:22:28
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.236.84.41 (41.84.236.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.84.41 (41.84.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 12:22:20.011122 2026] [security2:error] [pid 10845:tid 10845] [client 35.236.84.41:47144] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "deanandolsek.com"] [uri "/@fs/../.env"] [unique_id "aqbNvK3veUwILfFxKDclMAAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
debestelapp
2026-09-13 16:10:11
(1 hour ago)
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 16:00:43
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.236.84.41 (41.84.236.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.84.41 (41.84.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 12:00:39.129416 2026] [security2:error] [pid 25957:tid 25957] [client 35.236.84.41:47814] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dcsteven.com"] [uri "/.github/.env"] [unique_id "aqbIpz32nhcfLlji19cDqwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
dbmwebdesign
2026-09-13 15:50:07
(1 hour ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
🇺🇸
kosada.com
2026-09-13 15:39:32
(2 hours ago)
Repeated requests for suspicious nonexistent URLs, for example: /assets/manifest.json (HTTP/2.0 port ...
show more
Repeated requests for suspicious nonexistent URLs, for example: /assets/manifest.json (HTTP/2.0 port 443, user agent: "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36")
show less
Web App Attack
🇦🇹
penguin-solutions.at
2026-09-13 15:22:09
(2 hours ago)
Excessive 403/404 errors
...
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 15:14:58
(2 hours ago)
(mod_security) mod_security (id:210580) triggered by 35.236.84.41 (41.84.236.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210580) triggered by 35.236.84.41 (41.84.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 11:14:54.120972 2026] [security2:error] [pid 15179:tid 15179] [client 35.236.84.41:34376] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at ARGS:filename. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||davisound.com|F|2"] [data "Matched Data: proc/self/environ found within ARGS:filename: file:/proc/self/environ"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "davisound.com"] [uri "/__vite_rsc_findSourceMapURL"] [unique_id "aqa97urE_X7thEGZM-Ki3QAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-13 15:03:20
(2 hours ago)
OS File Access Attempt. Matched phrase ".aws/" at ARGS:filename. (930120-193)
Hacking
🇺🇸
TPI-Abuse
2026-09-13 14:58:32
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.236.84.41 (41.84.236.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.236.84.41 (41.84.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 10:58:28.702038 2026] [security2:error] [pid 17659:tid 17659] [client 35.236.84.41:59846] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||daviddholt.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "daviddholt.com"] [uri "/z9x8c7v6b5-debug-trigger-daviddholt.com"] [unique_id "aqa6FLLHBEUCLUKTuCVUggAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
ghostwarriors
2026-09-13 14:20:07
(3 hours ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 14:11:38
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.236.84.41 (41.84.236.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.236.84.41 (41.84.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 10:11:34.561849 2026] [security2:error] [pid 3255572:tid 3255684] [client 35.236.84.41:46858] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||dasperformance.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "dasperformance.com"] [uri "/rclone.conf"] [unique_id "aqavFr9cA1Q7C1SD2d-KjAAAAYs"]
show less
Brute-Force
Bad Web Bot
Web App Attack