🇳🇱
Savvii
2026-09-06 23:15:18
(1 day ago)
20 attempts against mh-misbehave-ban on kiwi
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 22:39:12
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.237.176.128 (128.176.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.176.128 (128.176.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 18:39:07.454623 2026] [security2:error] [pid 6621:tid 6621] [client 35.237.176.128:36714] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.terrybeachmusic.com"] [uri "/.env.example"] [unique_id "ap3ri1qnEtVSVEYY5KP3NAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 21:21:14
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.237.176.128 (128.176.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.176.128 (128.176.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 17:21:06.341820 2026] [security2:error] [pid 2245:tid 2245] [client 35.237.176.128:46746] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.the-burkes.us"] [uri "/userfiles"] [unique_id "ap3ZQtbtQIQo-1mil5sdWQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-06 21:08:34
(2 days ago)
Excessive multi-domain requests
Brute-Force
🇳🇱
Savvii
2026-09-06 20:57:13
(2 days ago)
20 attempts against mh_ha-misbehave-ban on ec102950
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Savvii
2026-09-06 19:18:23
(2 days ago)
20 attempts against mh-misbehave-ban on guava
Brute-Force
Bad Web Bot
Web App Attack
🇫🇮
Shaik Sai Meera
2026-09-06 18:50:11
(2 days ago)
IM360 WAF: Hidden file access
Brute-Force
🇺🇸
TPI-Abuse
2026-09-06 18:11:37
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.237.176.128 (128.176.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.176.128 (128.176.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 14:11:31.518968 2026] [security2:error] [pid 14882:tid 14882] [client 35.237.176.128:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.theabstractpress.com"] [uri "/@fs/../.env"] [unique_id "ap2s067_bUc5ZNpWFH-GwAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 16:33:01
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.237.176.128 (128.176.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.176.128 (128.176.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 12:32:55.920607 2026] [security2:error] [pid 18825:tid 18825] [client 35.237.176.128:44836] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aquatech-ind.com"] [uri "/api/.env/public/.env"] [unique_id "ap2Vt2-pJc2KcU23Sg4BxgAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 15:15:17
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 35.237.176.128 (128.176.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.237.176.128 (128.176.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 11:15:10.351216 2026] [security2:error] [pid 10766:tid 10899] [client 35.237.176.128:43934] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||yubasutterphotography.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "yubasutterphotography.com"] [uri "/z9x8c7v6b5-debug-trigger-yubasutterphotography.com"] [unique_id "ap2Dfkx-o8Ys5f7FgpiMRAAAAUY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-06 15:10:32
(2 days ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 14:53:43
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.237.176.128 (128.176.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.176.128 (128.176.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 10:53:37.783654 2026] [security2:error] [pid 3522:tid 3522] [client 35.237.176.128:53922] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.anchorroots.com"] [uri "/img../.env"] [unique_id "ap1-cdGJDPoSZ42rWkjUxQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 14:15:40
(2 days ago)
Multiple web server 400 error codes from same source ip
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 14:01:28
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 35.237.176.128 (128.176.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.237.176.128 (128.176.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 10:01:21.497811 2026] [security2:error] [pid 22796:tid 22796] [client 35.237.176.128:53910] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.abuscalledfreedom.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.abuscalledfreedom.com"] [uri "/rclone.conf"] [unique_id "ap1yMUBN4v2ApqSWiN48BgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 13:42:57
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.237.176.128 (128.176.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.176.128 (128.176.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 09:42:49.780632 2026] [security2:error] [pid 31386:tid 31386] [client 35.237.176.128:33008] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.beckersystems.net"] [uri "/public../.env"] [unique_id "ap1t2fO6N2RAoS5Nuzt6JwAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack