๐บ๐ธ
TPI-Abuse
2026-09-21 06:14:20
(51 minutes ago)
(mod_security) mod_security (id:210492) triggered by 35.240.167.138 (138.167.240.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.240.167.138 (138.167.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 02:14:12.581485 2026] [security2:error] [pid 11526:tid 11526] [client 35.240.167.138:59048] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.lowrygroup.com"] [uri "/.env.bak"] [unique_id "arDLNMeSGOuLjLNIky2OPgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-21 06:07:51
(58 minutes ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-195)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 05:53:39
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 35.240.167.138 (138.167.240.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.240.167.138 (138.167.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 01:53:35.955715 2026] [security2:error] [pid 28352:tid 28352] [client 35.240.167.138:48572] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.lucid-hq.lucid-events.com|F|2"] [data ".lucid-hq.lucid-events.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.lucid-hq.lucid-events.com"] [uri "/z9x8c7v6b5-debug-trigger-www.lucid-hq.lucid-events.com"] [unique_id "arDGX8GuQLu10HMob4CNEAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 03:25:31
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.240.167.138 (138.167.240.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.240.167.138 (138.167.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 23:25:24.210309 2026] [security2:error] [pid 25187:tid 25187] [client 35.240.167.138:48236] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.joesteiner.com|F|2"] [data ".joesteiner.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.joesteiner.com"] [uri "/z9x8c7v6b5-debug-trigger-www.joesteiner.com"] [unique_id "arCjpGlICkOe355NOtx8jAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
dot.mg
2026-09-21 03:22:02
(3 hours ago)
Bad behaviour
Web Spam
Anonymous
2026-09-21 03:10:08
(3 hours ago)
| [Dangerous/Singapore] Aggressive IP 35.240.167.138 (~30 hits). Type: DoS Defender- Web server 400 ...
show more
| [Dangerous/Singapore] Aggressive IP 35.240.167.138 (~30 hits). Type: DoS Defender- Web server 400 error code
show less
Web App Attack
Hacking
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-09-21 02:51:04
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.240.167.138 (138.167.240.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.240.167.138 (138.167.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 22:50:59.437583 2026] [security2:error] [pid 10952:tid 10952] [client 35.240.167.138:34006] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.lucasdirtcareers.finishlineenterprisesllc.com"] [uri "/.git/HEAD"] [unique_id "arCbk6N0VXiI7MAstpFRsgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-21 02:01:54
(5 hours ago)
Blocked by ModSec and CSF
Port Scan
๐ณ๐ฑ
e.fierstra
2026-09-21 00:57:36
(6 hours ago)
excessive HTTP 404 errors
Bad Web Bot
๐ณ๐ฑ
BlueWire Hosting
2026-09-21 00:03:44
(7 hours ago)
Bad bot ignoring robot.txt
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-20 23:29:23
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.240.167.138 (138.167.240.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.240.167.138 (138.167.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 19:29:20.115172 2026] [security2:error] [pid 27424:tid 27424] [client 35.240.167.138:47550] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "machinetoolsjwk.com"] [uri "/agents/.env"] [unique_id "arBsUGtkPwuuIy0KLg3oGAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-09-20 21:15:04
(9 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ซ๐ท
dynamix
2026-09-20 20:44:10
(10 hours ago)
Multiple WAF Violations
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-20 20:39:05
(10 hours ago)
[ti-30al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apac ...
show more
[ti-30al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apache-404. Example: 35.240.167.138 - - [20/Sep/2026:22:39:04 +0200] "GET /config.json HTTP/2.0" 404 2004 "-" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)"
35.240.167.138 - - [20/Sep/2026:22:39:04 +0200] "GET /api/account HTTP/2.0" 404 2004 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )"
35.240.167.138 - - [20/Sep/2026:22:39:04 +0200] "GET /z9x8c7v6b5-debug-trigger-payment.maasdael.com HTTP/2.0" 404 2004 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
35.240.167.138 - - [20/Sep/2026:22:39:04 +0200] "GET /__/firebase/init.json HTTP/2.0" 404 2004 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexi
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 20:30:42
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.240.167.138 (138.167.240.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.240.167.138 (138.167.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 16:30:35.392801 2026] [security2:error] [pid 27481:tid 27481] [client 35.240.167.138:35866] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.lyounglaw.com"] [uri "/.git/HEAD"] [unique_id "arBCa4yjGxA0T2teHibcAwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack