๐บ๐ธ
TPI-Abuse
2026-10-01 17:31:36
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.237.111.222 (222.111.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.111.222 (222.111.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 13:31:30.919086 2026] [security2:error] [pid 23702:tid 23721] [client 35.237.111.222:55554] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.honorac.com"] [uri "/.env.local"] [unique_id "ar6Y8n0MYlK8MNTmFskzkwAAAQ8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
middelkoopcc
2026-10-01 17:13:01
(3 days ago)
2026-10-01 19:11:02 GET /media../.env [301] && 2026-10-01 19:11:02 GET /files../.env [301] && 2026-1 ...
show more
2026-10-01 19:11:02 GET /media../.env [301] && 2026-10-01 19:11:02 GET /files../.env [301] && 2026-10-01 19:11:02 GET /static../.env [301] && 170 more within 20 minutes
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 16:49:14
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.237.111.222 (222.111.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.111.222 (222.111.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 12:49:06.808204 2026] [security2:error] [pid 9588:tid 9588] [client 35.237.111.222:33424] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.indigo17.com"] [uri "/.//.env"] [unique_id "ar6PAv4BdxorqoMRcXLy8wAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 16:19:44
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.237.111.222 (222.111.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.111.222 (222.111.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 12:19:39.971768 2026] [security2:error] [pid 9658:tid 9658] [client 35.237.111.222:52570] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.djmrmusic.com"] [uri "/.htpasswd"] [unique_id "ar6IGwagosnai7lrx1XgwwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 15:57:52
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 35.237.111.222 (222.111.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.237.111.222 (222.111.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 11:57:46.124596 2026] [security2:error] [pid 26851:tid 26984] [client 35.237.111.222:47698] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||djkirby.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "djkirby.com"] [uri "/z9x8c7v6b5-debug-trigger-djkirby.com"] [unique_id "ar6C-nsRa9pGRKta8tDVJgAAARU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-01 15:52:01
(3 days ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
Anonymous
2026-10-01 15:45:05
(3 days ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 14:27:51
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.237.111.222 (222.111.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.111.222 (222.111.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 10:27:47.757800 2026] [security2:error] [pid 28651:tid 28651] [client 35.237.111.222:52010] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "inmaine.us"] [uri "/media../.env"] [unique_id "ar5t43JiS8SOem8ZhvLeRQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 14:05:12
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.237.111.222 (222.111.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.111.222 (222.111.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 10:05:07.314539 2026] [security2:error] [pid 8415:tid 8415] [client 35.237.111.222:36134] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.d-sinema.com"] [uri "/img../.env"] [unique_id "ar5ok9evii0GbyU3Kt3NJQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 13:35:14
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.237.111.222 (222.111.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.111.222 (222.111.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 09:35:10.828707 2026] [security2:error] [pid 4106:tid 4106] [client 35.237.111.222:49538] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.desertalfas.org"] [uri "/.env.js"] [unique_id "ar5hjti_zDrz5QB4LKm95gAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 12:56:30
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.237.111.222 (222.111.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.111.222 (222.111.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 08:56:24.098905 2026] [security2:error] [pid 27233:tid 27233] [client 35.237.111.222:44830] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gdhlgroup.com"] [uri "/.env.js"] [unique_id "ar5YeCRl-d7DsEMmXYNP5QAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 12:03:54
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 35.237.111.222 (222.111.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.237.111.222 (222.111.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 08:03:51.184398 2026] [security2:error] [pid 18180:tid 18180] [client 35.237.111.222:39802] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||foxmm.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "foxmm.com"] [uri "/z9x8c7v6b5-debug-trigger-foxmm.com"] [unique_id "ar5MJy3JZ9wAWVMiLjrENAAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 11:47:45
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.237.111.222 (222.111.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.111.222 (222.111.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 07:47:37.236958 2026] [security2:error] [pid 4592:tid 4592] [client 35.237.111.222:39414] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.ehrlichmedia.com"] [uri "/public../.env"] [unique_id "ar5IWWt2o4KXTKRyA61RSgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 11:28:38
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.237.111.222 (222.111.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.111.222 (222.111.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 07:28:33.357463 2026] [security2:error] [pid 4700:tid 4700] [client 35.237.111.222:34802] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.flinthillsveterans.org"] [uri "/media../.env"] [unique_id "ar5D4eE13L9Yug6I7VtphwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
bazter.pro
2026-10-01 11:06:26
(3 days ago)
Fail2Ban: plesk-bot-aggressive - 15 failures
Port Scan
Bad Web Bot
Web App Attack