π«π·
IRISIO
2026-09-21 12:38:03
(6 hours ago)
scans/SQL injection/spam posts : 1820 queries
Web App Attack
SQL Injection
πΊπΈ
TPI-Abuse
2026-09-21 06:44:44
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.240.129.21 (21.129.240.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.240.129.21 (21.129.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 02:44:38.237801 2026] [security2:error] [pid 2311:tid 2311] [client 35.240.129.21:42000] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.johnmorogiello.com"] [uri "/dist../.env"] [unique_id "arDSVrX0w34eXbXMqSj-PwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
masterguru
2026-09-21 05:41:23
(13 hours ago)
Restricted File Access Attempt. Matched phrase "compose.yaml" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 05:33:22
(13 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.240.129.21 (21.129.240.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.240.129.21 (21.129.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 01:33:16.081590 2026] [security2:error] [pid 6701:tid 6701] [client 35.240.129.21:35438] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.jerryhetrick.com|F|2"] [data ".jerryhetrick.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.jerryhetrick.com"] [uri "/z9x8c7v6b5-debug-trigger-www.jerryhetrick.com"] [unique_id "arDBnDebvaelaGALqHhZvQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
updown.io
2026-09-21 05:09:30
(14 hours ago)
{"level":"info","ts":1789967365.6579182,"logger":"http.log.access.log1","msg":"handled request","req ...
show more
{"level":"info","ts":1789967365.6579182,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"35.240.129.21","remote_port":"43728","client_ip":"35.240.129.21","proto":"HTTP/2.0","method":"GET","host":"status.joerubin.com","uri":"/.env.example","headers":{"X-Nextjs-Data":["1"],"User-Agent":["Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)"],"Accept":["*/*"],"Cookie":["REDACTED"],"Accept-Encoding":["gzip"],"X-Middleware-Subrequest":["src/middleware:nowaf:src/middleware:src/middleware:src/middleware:src/middleware:middleware:middleware:nowaf:middleware:middleware:middleware:pages/_middleware"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"h2","server_name":"status.joerubin.com","ech":false}},"bytes_read":0,"user_id":"","duration":0.000238335,"size":0,"status":429,"resp_headers":{"Retry-After":["1"],"Server":["Caddy"],"Alt-Svc":["h3=\":443\"; ma=2592000"]}}
{"level":"info","ts":1789967365.66092,"logger":"http.log.access.log1
...
show less
DDoS Attack
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 04:27:10
(14 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.240.129.21 (21.129.240.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.240.129.21 (21.129.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 00:27:04.679276 2026] [security2:error] [pid 15513:tid 15513] [client 35.240.129.21:35520] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||paleopathologist.com|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "paleopathologist.com"] [uri "/ssl/server.key"] [unique_id "arCyGMa7CUYV5d04DFS_OAAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 04:02:56
(15 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.240.129.21 (21.129.240.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.240.129.21 (21.129.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 00:02:48.790032 2026] [security2:error] [pid 26551:tid 26551] [client 35.240.129.21:39648] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.jangamble.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.jangamble.com"] [uri "/rclone.conf"] [unique_id "arCsaFyRdVlVWLePlU0otgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
konseptit
2026-09-21 03:53:37
(15 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 35.240.129.21 (SG/Singapore/21.129.240. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.240.129.21 (SG/Singapore/21.129.240.35.bc.googleusercontent.com)
show less
SQL Injection
π©πͺ
ghostwarriors
2026-09-21 02:50:06
(16 hours ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
π©πͺ
yitzhaq
2026-09-21 02:41:14
(16 hours ago)
35.240.129.21 - - [21/Sep/2026:04:41:12 +0200] "GET /.env.production HTTP/2.0" 404 299 "-" "Mozilla/ ...
show more
35.240.129.21 - - [21/Sep/2026:04:41:12 +0200] "GET /.env.production HTTP/2.0" 404 299 "-" "Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)"
35.240.129.21 - - [21/Sep/2026:04:41:12 +0200] "GET /.env.backup HTTP/2.0" 403 303 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)"
35.240.129.21 - - [21/Sep/2026:04:41:12 +0200] "GET /.env.bak HTTP/2.0" 404 299 "-" "Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)"
35.240.129.21 - - [21/Sep/2026:04:41:12 +0200] "GET /api/.env/public/.env HTTP/2.0" 404 299 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)"
35.240.129.21 - - [21/Sep/2026:04:41:12 +0200] "GET /.env.old HTTP/2.0" 404 299 "-" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/)"
35.240.129.21 - - [21/Sep/2026:04:41:12 +0200] "GET /api/.env HTTP/2.0" 403 303 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email])"
35.240.1
show less
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-09-21 02:39:53
(16 hours ago)
(mod_security) mod_security (id:210580) triggered by 35.240.129.21 (21.129.240.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210580) triggered by 35.240.129.21 (21.129.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 22:39:45.999159 2026] [security2:error] [pid 17219:tid 17219] [client 35.240.129.21:54966] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at ARGS:vars[1][]. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||www.john-bell-associates.com|F|2"] [data "Matched Data: proc/self/environ found within ARGS:vars[1][]: /proc/self/environ"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "www.john-bell-associates.com"] [uri "/index.php"] [unique_id "arCY8YbYGnjlm9MPP17ZBAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Site.eu
2026-09-21 02:23:53
(16 hours ago)
Excessive multi-domain requests
Brute-Force
π©πͺ
filstal.org
2026-09-21 02:19:42
(16 hours ago)
Web exploit or injection attempt blocked by ModSecurity WAF.
SQL Injection
Web App Attack
π«π·
Stara
2026-09-21 02:11:16
(17 hours ago)
ModSecurity detected web attack - .env/config probing or SQLi/Code injection (Rule 949110)
Brute-Force
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 01:30:17
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.240.129.21 (21.129.240.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.240.129.21 (21.129.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 21:30:13.380049 2026] [security2:error] [pid 7036:tid 7036] [client 35.240.129.21:47844] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jitterbugswing.com"] [uri "/.env"] [unique_id "arCIpV-MBxW9-M2aWcIWagAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack