๐บ๐ธ
TPI-Abuse
2026-09-21 06:04:33
(4 minutes ago)
(mod_security) mod_security (id:210492) triggered by 35.237.176.168 (168.176.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.176.168 (168.176.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 02:04:26.616298 2026] [security2:error] [pid 18134:tid 18134] [client 35.237.176.168:48390] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.spyasociados.com"] [uri "/.env.local"] [unique_id "arDI6gm9CJdmYZytRscRFAAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
creoline GmbH
2026-09-21 05:27:44
(40 minutes ago)
[WAF] Multiple suspicious HTTP requests has been blocked
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 04:47:55
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.237.176.168 (168.176.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.176.168 (168.176.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 00:47:51.300012 2026] [security2:error] [pid 9842:tid 9842] [client 35.237.176.168:33066] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.countrysideinnkingston.com"] [uri "/.git/HEAD"] [unique_id "arC29xeHKydQ2JxPH1r05QAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 04:21:50
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.237.176.168 (168.176.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.176.168 (168.176.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 00:21:44.349187 2026] [security2:error] [pid 13037:tid 13037] [client 35.237.176.168:35812] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "crucialpins.com"] [uri "/docker/.env"] [unique_id "arCw2CT_Ll8M09ICi1JNuQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 03:58:25
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.237.176.168 (168.176.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.176.168 (168.176.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 23:58:19.433974 2026] [security2:error] [pid 2885:tid 2885] [client 35.237.176.168:33920] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.csmedicalbilling.com"] [uri "/.env.js"] [unique_id "arCrW4mP0yPu3VY7_Yt5_wAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
bazter.pro
2026-09-21 02:33:47
(3 hours ago)
Fail2Ban: plesk-bot-aggressive - 15 failures
Port Scan
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 02:12:41
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.237.176.168 (168.176.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.237.176.168 (168.176.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 22:12:36.022503 2026] [security2:error] [pid 3631227:tid 3631227] [client 35.237.176.168:35570] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.techlinks.com|F|2"] [data ".techlinks.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.techlinks.com"] [uri "/z9x8c7v6b5-debug-trigger-www.techlinks.com"] [unique_id "arCSlAL8QpE1oxe6_Oay5AAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 00:33:00
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.237.176.168 (168.176.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.176.168 (168.176.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 20:32:53.093162 2026] [security2:error] [pid 24843:tid 24843] [client 35.237.176.168:41358] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.saltcityprint.com"] [uri "/src/.env"] [unique_id "arB7NeUn7quTic3Uo5eksQAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-09-21 00:05:21
(6 hours ago)
Too many Status 40X (11)
Brute-Force
Web App Attack
๐ฉ๐ช
bazter.pro
2026-09-20 23:29:14
(6 hours ago)
Fail2Ban: apache-ratelimit - 20 failures
Port Scan
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 23:28:11
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.237.176.168 (168.176.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.176.168 (168.176.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 19:28:03.798098 2026] [security2:error] [pid 7291:tid 7291] [client 35.237.176.168:46024] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.cottrel.com"] [uri "/.env.live"] [unique_id "arBsAy_TXI6M6R89jk55CgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 23:03:29
(7 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.237.176.168 (168.176.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.237.176.168 (168.176.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 19:03:23.422790 2026] [security2:error] [pid 27013:tid 27013] [client 35.237.176.168:46442] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||cuddliesforkids.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "cuddliesforkids.com"] [uri "/z9x8c7v6b5-debug-trigger-cuddliesforkids.com"] [unique_id "arBmO8gFJREwIfQ0JthaWwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 22:15:14
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.237.176.168 (168.176.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.176.168 (168.176.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 18:15:03.311114 2026] [security2:error] [pid 30899:tid 30899] [client 35.237.176.168:33874] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.creativejazz.arsenaultartistmanagement.com"] [uri "/backend/.env"] [unique_id "arBa5-41nFk5lC3bNHxDzwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-09-20 21:30:03
(8 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
Anonymous
2026-09-20 21:23:42
(8 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking