๐บ๐ธ
TPI-Abuse
2026-10-09 22:17:47
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.237.197.104 (104.197.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.237.197.104 (104.197.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 18:17:42.606742 2026] [security2:error] [pid 4324:tid 4324] [client 35.237.197.104:40248] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||danged.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "danged.com"] [uri "/z9x8c7v6b5-debug-trigger-danged.com"] [unique_id "asloBlOJ-FsDWNO8x5m64wAAAEo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-09 21:58:13
(1 day ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 21:47:49
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.237.197.104 (104.197.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.237.197.104 (104.197.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 17:47:44.900634 2026] [security2:error] [pid 24467:tid 24467] [client 35.237.197.104:52870] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||crowleywoodworking.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "crowleywoodworking.com"] [uri "/z9x8c7v6b5-debug-trigger-crowleywoodworking.com"] [unique_id "aslhAGJL_lr01GlgL7Zu7AAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-10-09 21:34:44
(1 day ago)
csagent: score 23.2: 404 noise floor x13, secrets grab x2; 1 domain(s) in 1s
Web App Attack
๐ง๐ช
cmbplf
2026-10-09 21:22:33
(1 day ago)
627 requests with url.path *.env
388 requests with url.path */@fs/*
114 requests with url.path */ ...
show more
627 requests with url.path *.env
388 requests with url.path */@fs/*
114 requests with url.path */proc/*
show less
Brute-Force
Bad Web Bot
๐ซ๐ท
Octopuce
2026-10-09 20:55:57
(1 day ago)
Aggressive web search of vulnerable pages: /_image?href=/../../../.env /openapi.json /api/openapi.js ...
show more
Aggressive web search of vulnerable pages: /_image?href=/../../../.env /openapi.json /api/openapi.json /swagger.json /api/v1/config/ ...
show less
Web App Attack
๐ฒ๐พ
Rizzy
2026-10-09 20:52:29
(1 day ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 20:17:01
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.237.197.104 (104.197.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.197.104 (104.197.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 16:16:55.638742 2026] [security2:error] [pid 32111:tid 32111] [client 35.237.197.104:42366] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "civilwarzone.com"] [uri "/public/.env"] [unique_id "aslLt-LSd_AjNY3CWUH4sQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-10-09 20:05:24
(1 day ago)
Too many Status 40X (12)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 20:01:49
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.237.197.104 (104.197.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.237.197.104 (104.197.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 16:01:43.115536 2026] [security2:error] [pid 25579:tid 25579] [client 35.237.197.104:59334] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||chrisbilder.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "chrisbilder.com"] [uri "/z9x8c7v6b5-debug-trigger-chrisbilder.com"] [unique_id "aslIJ_QCUkvvZ6fzEXHDiwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 19:45:43
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.237.197.104 (104.197.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.237.197.104 (104.197.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 15:45:37.771158 2026] [security2:error] [pid 2792:tid 2792] [client 35.237.197.104:59538] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||charmainecruz.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "charmainecruz.com"] [uri "/z9x8c7v6b5-debug-trigger-charmainecruz.com"] [unique_id "aslEYTryTfdlAPbwJDADFAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
rubixstudios
2026-10-09 19:26:02
(1 day ago)
Excessive HTTP requests consistent with automated attack behaviour detected by Imunify360
DDoS Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 19:18:28
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.237.197.104 (104.197.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.237.197.104 (104.197.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 15:18:21.351091 2026] [security2:error] [pid 29590:tid 29590] [client 35.237.197.104:41678] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||cathybermanmft.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "cathybermanmft.com"] [uri "/z9x8c7v6b5-debug-trigger-cathybermanmft.com"] [unique_id "ask9_aIk3-7W_PTrMvvK5QAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 18:20:55
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.237.197.104 (104.197.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.237.197.104 (104.197.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 14:20:50.243568 2026] [security2:error] [pid 26019:tid 26019] [client 35.237.197.104:32956] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bvisecurity.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bvisecurity.com"] [uri "/z9x8c7v6b5-debug-trigger-bvisecurity.com"] [unique_id "askwguO7DPqvBcRrzCPOKgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-10-09 18:19:55
(1 day ago)
Excessive multi-domain requests
Brute-Force