๐ฆ๐บ
user-01
2026-09-24 02:52:27
(2 days ago)
Multiple WAF violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 06:00:57
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 35.240.81.99 (99.81.240.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.240.81.99 (99.81.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 02:00:51.988043 2026] [security2:error] [pid 31175:tid 31175] [client 35.240.81.99:53382] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.owenbee.bridgital.com"] [uri "/%2e%2e/%2e%2e/%2e%2e/%2e%2e/.env"] [unique_id "arDIE9rY--nKu5ELrOgwlgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-09-21 05:58:37
(5 days ago)
csagent: score 21.8: 404 noise floor x7, secrets grab x2; 1 domain(s) in 1s
Web App Attack
๐บ๐ธ
masterguru
2026-09-21 05:22:53
(5 days ago)
COMODO WAF: URL file extension is restricted by policy. Match of "pmFromFile userdata_wl_extensions" ...
show more
COMODO WAF: URL file extension is restricted by policy. Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. (210730-169)
show less
Hacking
๐ช๐ธ
robotstxt
2026-09-21 03:16:38
(5 days ago)
35.240.81.99 - - [21/Sep/2026:03:16:33 +0000] "GET /public/plugins/alertlist/../../../../../../../.. ...
show more
35.240.81.99 - - [21/Sep/2026:03:16:33 +0000] "GET /public/plugins/alertlist/../../../../../../../../proc/self/cmdline HTTP/1.1" 400 193 "-" "-" "-" edge="35.240.81.99"
35.240.81.99 - - [21/Sep/2026:03:16:35 +0000] "GET /static/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fproc/self/environ HTTP/1.1" 400 193 "-" "-" "-" edge="35.240.81.99"
35.240.81.99 - - [21/Sep/2026:03:16:35 +0000] "GET /static/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fproc/self/environ HTTP/1.1" 400 193 "-" "-" "-" edge="35.240.81.99"
35.240.81.99 - - [21/Sep/2026:03:16:35 +0000] "GET /resources/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f.env HTTP/1.1" 400 193 "-" "-" "-" edge="35.240.81.99"
35.240.81.99 - - [21/Sep/2026:03:16:35 +0000] "GET /resources/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f.env HTTP/1.1" 400 193 "-" "-" "-" edge="35.240.81.99"
...
show less
Web Spam
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 02:43:36
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 35.240.81.99 (99.81.240.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.240.81.99 (99.81.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 22:43:27.434328 2026] [security2:error] [pid 29674:tid 29674] [client 35.240.81.99:45440] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.pierrebastin.com"] [uri "/@fs/src/.env"] [unique_id "arCZzyGyw71vrRfdwcH4pAAAAE8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 02:21:28
(5 days ago)
(mod_security) mod_security (id:243320) triggered by 35.240.81.99 (99.81.240.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:243320) triggered by 35.240.81.99 (99.81.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 22:21:25.273999 2026] [security2:error] [pid 28925:tid 28933] [client 35.240.81.99:51878] ModSecurity: Access denied with code 403 (phase 2). String match "/.profile" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6621"] [id "243320"] [rev "1"] [msg "COMODO WAF: Information disclosure vulnerability in Cloud Foundry PHP Buildpack (aka php-buildpack) before 4.3.18 and PHP Buildpack Cf-release before 242, as used in Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.6.38 and 1.7.x before 1.7.19 and other products (CVE-2016-6639)||www.oldpl8s.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.oldpl8s.com"] [uri "/.profile"] [unique_id "arCUpS0c0wa8yTB0LPyexQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 01:13:22
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 35.240.81.99 (99.81.240.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.240.81.99 (99.81.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 21:13:15.641149 2026] [security2:error] [pid 9892:tid 9892] [client 35.240.81.99:59698] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.oscarssons.com|F|2"] [data ".oscarssons.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.oscarssons.com"] [uri "/z9x8c7v6b5-debug-trigger-mail.oscarssons.com"] [unique_id "arCEq5x04Zmp73TU5-CLMQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 00:23:36
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 35.240.81.99 (99.81.240.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.240.81.99 (99.81.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 20:23:31.886926 2026] [security2:error] [pid 27125:tid 27125] [client 35.240.81.99:45646] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "orientaltb.com"] [uri "/backend/.env"] [unique_id "arB5A3DamaC1tAPTp4OnHgAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
robotstxt
2026-09-21 00:09:41
(5 days ago)
35.240.81.99 - - [21/Sep/2026:00:09:39 +0000] "GET /uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f.env ...
show more
35.240.81.99 - - [21/Sep/2026:00:09:39 +0000] "GET /uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f.env HTTP/1.1" 400 193 "-" "-" "-" edge="35.240.81.99"
35.240.81.99 - - [21/Sep/2026:00:09:39 +0000] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f.env HTTP/1.1" 400 193 "-" "-" "-" edge="35.240.81.99"
35.240.81.99 - - [21/Sep/2026:00:09:39 +0000] "GET /icons/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/proc/self/environ HTTP/1.1" 400 193 "-" "-" "-" edge="35.240.81.99"
35.240.81.99 - - [21/Sep/2026:00:09:39 +0000] "GET /public/plugins/grafana-clock-panel/../../../../../../../../proc/self/environ HTTP/1.1" 400 193 "-" "-" "-" edge="35.240.81.99"
35.240.81.99 - - [21/Sep/2026:00:09:39 +0000] "GET /static/../../../a/../../../../.env HTTP/1.1" 400 193 "-" "-" "-" edge="35.240.81.99"
...
show less
Web Spam
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 23:52:35
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 35.240.81.99 (99.81.240.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.240.81.99 (99.81.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 19:52:31.108180 2026] [security2:error] [pid 20227:tid 20227] [client 35.240.81.99:59884] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.ondakompun.com"] [uri "/@fs/app/.env"] [unique_id "arBxv_hHjVofwIfgeKvgXwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 22:38:27
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 35.240.81.99 (99.81.240.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.240.81.99 (99.81.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 18:38:18.767226 2026] [security2:error] [pid 28038:tid 28038] [client 35.240.81.99:41866] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.pagewideprinting.com|F|2"] [data ".pagewideprinting.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.pagewideprinting.com"] [uri "/z9x8c7v6b5-debug-trigger-mail.pagewideprinting.com"] [unique_id "arBgWmvKFRzerGH81Gr9igAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
RLDD
2026-09-20 22:37:42
(5 days ago)
WP probing for vulnerabilities -ove
Web App Attack
๐ฎ๐น
VHosting
2026-09-20 22:10:04
(5 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ซ๐ท
dynamix
2026-09-20 22:04:13
(5 days ago)
Multiple WAF Violations
Web App Attack