๐บ๐ธ
TPI-Abuse
2026-09-22 01:28:17
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 35.238.204.236 (236.204.238.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.238.204.236 (236.204.238.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 21:28:10.901409 2026] [security2:error] [pid 29578:tid 29578] [client 35.238.204.236:41678] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "newenglandchristmascards.com"] [uri "/.git/config"] [unique_id "arHZqnQHm-eHPvD2tOhDNwAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 00:56:08
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 35.238.204.236 (236.204.238.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.238.204.236 (236.204.238.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 20:56:04.433610 2026] [security2:error] [pid 18609:tid 18609] [client 35.238.204.236:43236] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||nesetsv.com|F|2"] [data ".axd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "nesetsv.com"] [uri "/elmah.axd"] [unique_id "arHSJEXdrKqTjNYSj_tfNAAAAD0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
netfactotum
2026-09-21 23:28:17
(5 days ago)
Hacking
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-09-21 20:20:09
(5 days ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 20:11:51
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 35.238.204.236 (236.204.238.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.238.204.236 (236.204.238.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 16:11:47.716400 2026] [security2:error] [pid 23138:tid 23138] [client 35.238.204.236:38548] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.jamesallenwalker.com|F|2"] [data ".jamesallenwalker.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.jamesallenwalker.com"] [uri "/z9x8c7v6b5-debug-trigger-www.jamesallenwalker.com"] [unique_id "arGPg7AgamAdPseMdgjNWgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
netman
2026-09-21 19:57:42
(5 days ago)
HTTP: 35.238.204.236 blocked because of 100 failures
...
DDoS Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 19:36:07
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 35.238.204.236 (236.204.238.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.238.204.236 (236.204.238.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 15:36:02.800136 2026] [security2:error] [pid 20443:tid 20443] [client 35.238.204.236:38508] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.netcastcorp.com"] [uri "/api/v1/.env"] [unique_id "arGHIikFUzjfBWfrXWLPPQAAADY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 18:42:10
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 35.238.204.236 (236.204.238.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.238.204.236 (236.204.238.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 14:42:05.005814 2026] [security2:error] [pid 26613:tid 26613] [client 35.238.204.236:52562] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.nextngnr.com"] [uri "/.env.example"] [unique_id "arF6ff2OtguxkO8Z_mrZnAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 17:37:45
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 35.238.204.236 (236.204.238.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.238.204.236 (236.204.238.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 13:37:42.170652 2026] [security2:error] [pid 17648:tid 17648] [client 35.238.204.236:34820] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.praemiumtech.com"] [uri "/build/.env"] [unique_id "arFrZiOZPFkvZgcAAL8XCgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-09-21 17:05:42
(5 days ago)
Too many Status 40X (21)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 16:22:43
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 35.238.204.236 (236.204.238.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.238.204.236 (236.204.238.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 12:22:39.254370 2026] [security2:error] [pid 5596:tid 5596] [client 35.238.204.236:45240] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.ncparanormalresearch.andrsn.com|F|2"] [data ".ncparanormalresearch.andrsn.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.ncparanormalresearch.andrsn.com"] [uri "/z9x8c7v6b5-debug-trigger-www.ncparanormalresearch.andrsn.com"] [unique_id "arFZz21F8vkG3KJE4htDYwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-21 16:05:09
(5 days ago)
WAF repeated trigger detected by Fail2Ban
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 15:42:24
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 35.238.204.236 (236.204.238.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.238.204.236 (236.204.238.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 11:42:19.067112 2026] [security2:error] [pid 10932:tid 10932] [client 35.238.204.236:45042] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.nchsfootballgolfouting.com"] [uri "/api/console/api_server"] [unique_id "arFQW62mfBcVwnKeq2frGgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-21 15:27:14
(5 days ago)
[ti-26al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-26al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 35.238.204.236 - - [21/Sep/2026:17:26:56 +0200] "GET /@fs/app/.env?raw?? HTTP/1.1" 404 2065 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
IndigoRidge
2026-09-21 15:18:12
(5 days ago)
[21/Sep/2026:11:18:11.574858 --0400] arFKs3VitvA-7wf@QKZ@pQAAABc 35.238.204.236 58398 205.233.18.17 ...
show more
[21/Sep/2026:11:18:11.574858 --0400] arFKs3VitvA-7wf@QKZ@pQAAABc 35.238.204.236 58398 205.233.18.17 7081
[21/Sep/2026:11:18:11.586879 --0400] arFKsxKuzJ@7EhmQMNNhoAAAA0Q 35.238.204.236 58414 205.233.18.17 7081
[21/Sep/2026:11:18:11.587199 --0400] arFKs5Q5WQUCqrU0kWrTtgAAAcw 35.238.204.236 58416 205.233.18.17 7081
[21/Sep/2026:11:18:11.761704 --0400] arFKs3VitvA-7wf@QKZ@pwAAAAQ 35.238.204.236 58424 205.233.18.17 7081
[21/Sep/2026:11:18:11.764968 --0400] arFKszq50VFlK4fBysqEIAAAApU 35.238.204.236 58426 205.233.18.17 7081
...
show less
Hacking