🇫🇷
masterguru
2026-09-20 15:31:39
(21 hours ago)
Restricted File Access Attempt. Matched phrase "config.json" at REQUEST_FILENAME. (930130-196)
Hacking
Web App Attack
🇫🇷
dynamix
2026-09-20 15:18:12
(22 hours ago)
Multiple WAF Violations
Web App Attack
🇬🇧
Apache
2026-09-20 15:17:36
(22 hours ago)
(mod_security) mod_security (id:930100) triggered by 35.240.178.84 (SG/Singapore/84.178.240.35.bc.go ...
show more
(mod_security) mod_security (id:930100) triggered by 35.240.178.84 (SG/Singapore/84.178.240.35.bc.googleusercontent.com): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
🇫🇷
Stara
2026-09-20 15:16:02
(22 hours ago)
ModSecurity detected web attack - .env/config probing or SQLi/Code injection (Rule 949110)
Brute-Force
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-20 15:06:41
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.240.178.84 (84.178.240.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.240.178.84 (84.178.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 11:06:34.461377 2026] [security2:error] [pid 28744:tid 28744] [client 35.240.178.84:45036] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "owenmail.com"] [uri "/admin/.env"] [unique_id "aq_2erhS2o3qkvVx3MqkcgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-20 14:50:54
(22 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.240.178.84 (84.178.240.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.240.178.84 (84.178.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 10:50:50.873870 2026] [security2:error] [pid 15544:tid 15567] [client 35.240.178.84:46248] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||moogoob.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "moogoob.com"] [uri "/z9x8c7v6b5-debug-trigger-moogoob.com"] [unique_id "aq_yymhLy5D-2KUzPcB-QAAAANU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-20 14:33:25
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.240.178.84 (84.178.240.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.240.178.84 (84.178.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 10:33:21.072730 2026] [security2:error] [pid 6782:tid 6782] [client 35.240.178.84:33440] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "leadek.com"] [uri "/web/.env"] [unique_id "aq_usTxuH2HPVrMao9WNhwAAACo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-20 14:17:15
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.240.178.84 (84.178.240.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.240.178.84 (84.178.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 10:17:08.410757 2026] [security2:error] [pid 26876:tid 26876] [client 35.240.178.84:60064] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "imagesbyaubrey.com"] [uri "/.env.example"] [unique_id "aq_q5M5cl0PeJl46bnx6hAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-20 14:01:33
(23 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.240.178.84 (84.178.240.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.240.178.84 (84.178.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 10:01:26.054224 2026] [security2:error] [pid 28870:tid 28870] [client 35.240.178.84:38520] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||galaxyretro.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "galaxyretro.com"] [uri "/z9x8c7v6b5-debug-trigger-galaxyretro.com"] [unique_id "aq_nNq-_cVuNtgUdVtxx7gAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇲🇾
Rizzy
2026-09-20 13:55:04
(23 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
🇩🇪
TheDjRider
2026-09-20 13:52:57
(23 hours ago)
CrowdSec detected Web application reconnaissance. Scenario: crowdsecurity/http-probing. Automatic ba ...
show more
CrowdSec detected Web application reconnaissance. Scenario: crowdsecurity/http-probing. Automatic ban triggered. Detection time (UTC): 2026-09-20T13:52:46.904405268Z. Context: http_status=403, http_status=404
show less
Web App Attack
🇨🇦
polycoda
2026-09-20 13:42:53
(23 hours ago)
AutoBlock: 🎯 Vulnerability Scanner (Non Decay-Based) - 📡 Port Scan (Non Decay-Based) - ❌ Excessive 4 ...
show more
AutoBlock: 🎯 Vulnerability Scanner (Non Decay-Based) - 📡 Port Scan (Non Decay-Based) - ❌ Excessive 40X Errors (Decay-Based)
show less
Port Scan
Hacking
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-20 13:40:51
(23 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.240.178.84 (84.178.240.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.240.178.84 (84.178.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 09:40:44.849826 2026] [security2:error] [pid 31097:tid 31097] [client 35.240.178.84:53570] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||combustionlogic.com|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "combustionlogic.com"] [uri "/ssl/server.key"] [unique_id "aq_iXOTCmW-O0E7b2KCLtQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-09-20 13:35:04
(23 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-20 13:24:34
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.240.178.84 (84.178.240.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.240.178.84 (84.178.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 09:24:28.603044 2026] [security2:error] [pid 11591:tid 11591] [client 35.240.178.84:56592] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||austingrammer.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "austingrammer.com"] [uri "/z9x8c7v6b5-debug-trigger-austingrammer.com"] [unique_id "aq_ejNw3nsCrrbVj4AhVMQAAAC4"]
show less
Brute-Force
Bad Web Bot
Web App Attack