๐บ๐ธ
TPI-Abuse
2026-09-21 06:25:09
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.237.204.84 (84.204.237.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.204.84 (84.204.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 02:25:04.686104 2026] [security2:error] [pid 17317:tid 17317] [client 35.237.204.84:37722] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "denvercitymotorparts.com"] [uri "/.env.js"] [unique_id "arDNwBXA1gCUeCVzUK47zQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-21 06:23:58
(3 days ago)
Excessive multi-domain requests
Brute-Force
๐ณ๐ฑ
Alt255
2026-09-21 04:34:31
(3 days ago)
[ti-22al] Web exploit scanning: 3 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-22al] Web exploit scanning: 3 suspicious requests detected by fail2ban jail apache-scanner. Example: 35.237.204.84 - - [21/Sep/2026:06:34:28 +0200] "GET /config/.env HTTP/2.0" 403 32 "-" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 04:11:30
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.237.204.84 (84.204.237.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.204.84 (84.204.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 00:11:21.845447 2026] [security2:error] [pid 23453:tid 23453] [client 35.237.204.84:56828] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "darrenj.com"] [uri "/public/.env"] [unique_id "arCuaUMnZiJFE-RCKd25igAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 03:44:15
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 35.237.204.84 (84.204.237.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.237.204.84 (84.204.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 23:44:11.246547 2026] [security2:error] [pid 24445:tid 24544] [client 35.237.204.84:54054] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||dermatologycolorado.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "dermatologycolorado.com"] [uri "/z9x8c7v6b5-debug-trigger-dermatologycolorado.com"] [unique_id "arCoC1AozzHTg-vN7scBlAAAANg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 03:28:42
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.237.204.84 (84.204.237.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.204.84 (84.204.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 23:28:36.027965 2026] [security2:error] [pid 10093:tid 10093] [client 35.237.204.84:34578] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.delicioushotspots.com"] [uri "/src/.env"] [unique_id "arCkZBb0PIqx04AxvqLUWwAAAD8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
dbmwebdesign
2026-09-21 03:20:33
(3 days ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
๐ซ๐ท
Stara
2026-09-21 03:09:29
(3 days ago)
ModSecurity detected web attack - .env/config probing or SQLi/Code injection (Rule 949110)
Brute-Force
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 02:58:52
(3 days ago)
(mod_security) mod_security (id:210580) triggered by 35.237.204.84 (84.204.237.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210580) triggered by 35.237.204.84 (84.204.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 22:58:47.888748 2026] [security2:error] [pid 11482:tid 11482] [client 35.237.204.84:54256] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at ARGS:vars[1][]. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||mail.revelatorium.com|F|2"] [data "Matched Data: proc/self/environ found within ARGS:vars[1][]: /proc/self/environ"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "mail.revelatorium.com"] [uri "/index.php"] [unique_id "arCdZ_8eAn6RNGgzYLBX3gAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 02:14:05
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.237.204.84 (84.204.237.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.204.84 (84.204.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 22:14:00.039674 2026] [security2:error] [pid 25507:tid 25507] [client 35.237.204.84:35366] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cosplayculture.com"] [uri "/.env.backup"] [unique_id "arCS6LYHG5UaY82oPUuF6QAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 01:24:01
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.237.204.84 (84.204.237.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.204.84 (84.204.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 21:23:55.036029 2026] [security2:error] [pid 29083:tid 29083] [client 35.237.204.84:47460] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.ltscatering.com"] [uri "/.env.js"] [unique_id "arCHK228FdARzY9-LEoHFwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-21 00:29:27
(3 days ago)
[ti-12al] Web exploit scanning: 4 suspicious requests detected by fail2ban jail <name>. Example: 35. ...
show more
[ti-12al] Web exploit scanning: 4 suspicious requests detected by fail2ban jail <name>. Example: 35.237.204.84 - - \[21/Sep/2026:02:29:22 +0200\] "GET /.aws/config HTTP/2.0" 404 1863 "-" "Mozilla/5.0 \(compatible\; Kimi-SearchBot/1.0\; +https://kimi.ai/\)"
35.237.204.84 - - \[21/Sep/2026:02:29:22 +0200\] "GET /.git/config HTTP/2.0" 404 1863 "-" "Mozilla/5.0 AppleWebKit/537.36 \(KHTML, like Gecko\; compatible\; Perplexity-User/1.0\; +https://perplexity.ai/perplexitybot\)"
35.237.204.84 - - \[21/Sep/2026:02:29:22 +0200\] "GET /packages/.env HTTP/2.0" 404 1863 "-" "Mozilla/5.0 AppleWebKit/537.36 \(KHTML, like Gecko\)\; compatible\; ChatGPT-User/1.0\; +https://openai.com/bot"
35.237.204.84 - - \[21/Sep/2026:02:29:22 +0200\] "GET /.aws/credentials HTTP/2.0" 404 1863 "-" "Mozilla/5.0 \(Macintosh\; In
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-20 22:56:34
(3 days ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
Anonymous
2026-09-20 22:55:46
(3 days ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 22:53:26
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.237.204.84 (84.204.237.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.204.84 (84.204.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 18:53:21.806645 2026] [security2:error] [pid 23369:tid 23369] [client 35.237.204.84:52596] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.dentistholidaycards.com"] [uri "/.env"] [unique_id "arBj4eVSAxE4Eks4qW38MAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack