๐ช๐ธ
masterguru
2026-09-30 05:11:07
(21 hours ago)
Inbound Anomaly Score Exceeded (Total Score: 10). Operator GE matched 5 at TX:anomaly_score. (949110 ...
show more
Inbound Anomaly Score Exceeded (Total Score: 10). Operator GE matched 5 at TX:anomaly_score. (949110-122)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-30 04:31:55
(21 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.241.191.198 (198.191.241.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.241.191.198 (198.191.241.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 00:31:49.437283 2026] [security2:error] [pid 18218:tid 18218] [client 35.241.191.198:52856] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||eurosoni.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "eurosoni.com"] [uri "/z9x8c7v6b5-debug-trigger-eurosoni.com"] [unique_id "aryQtepXou0GcLeqVYX2fAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-30 04:05:03
(22 hours ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 02:54:18
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.241.191.198 (198.191.241.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.241.191.198 (198.191.241.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 22:54:16.881135 2026] [security2:error] [pid 22083:tid 22083] [client 35.241.191.198:48546] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.flyingdodopublications.com"] [uri "/.env.production"] [unique_id "arx52PPP-nFynXLi55al_QAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 02:00:43
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.241.191.198 (198.191.241.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.241.191.198 (198.191.241.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 22:00:38.755515 2026] [security2:error] [pid 19663:tid 19663] [client 35.241.191.198:46170] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||evelynkay.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "evelynkay.com"] [uri "/z9x8c7v6b5-debug-trigger-evelynkay.com"] [unique_id "arxtRsjqJRv8CIFm88a_tQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 00:54:45
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.241.191.198 (198.191.241.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.241.191.198 (198.191.241.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 20:54:41.147014 2026] [security2:error] [pid 2243:tid 2243] [client 35.241.191.198:47678] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ecodesarrollourbano.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ecodesarrollourbano.com"] [uri "/z9x8c7v6b5-debug-trigger-ecodesarrollourbano.com"] [unique_id "arxd0cN5hEwD5_UiKCfwWwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 00:37:08
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.241.191.198 (198.191.241.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.241.191.198 (198.191.241.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 20:37:01.574708 2026] [security2:error] [pid 29182:tid 29182] [client 35.241.191.198:37730] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.ic1surplus.com"] [uri "/.env"] [unique_id "arxZrXfulC_QxffUIG_wbgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-30 00:00:30
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
๐ฒ๐พ
Rizzy
2026-09-29 23:28:13
(1 day ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 23:10:18
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.241.191.198 (198.191.241.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.241.191.198 (198.191.241.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 19:10:14.454674 2026] [security2:error] [pid 31730:tid 31730] [client 35.241.191.198:48026] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||form-a-tool.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "form-a-tool.com"] [uri "/z9x8c7v6b5-debug-trigger-form-a-tool.com"] [unique_id "arxFVra31Lo8Gt8RmPZXsgAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-09-29 22:38:04
(1 day ago)
[WedSep3000:37:59.2679392026][security2:error][pid2858251:tid2858329][client35.241.191.198:0]ModSecu ...
show more
[WedSep3000:37:59.2679392026][security2:error][pid2858251:tid2858329][client35.241.191.198:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"cpcalendars.gustotondo.ch\"][uri\"/.env.old\"][unique_id\"arw9x21or3FeI-KpzdVMlwAAAMM\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 21:57:26
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.241.191.198 (198.191.241.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.241.191.198 (198.191.241.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 17:57:21.105070 2026] [security2:error] [pid 9884:tid 9884] [client 35.241.191.198:37188] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||icoinedthewordironesty.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "icoinedthewordironesty.com"] [uri "/z9x8c7v6b5-debug-trigger-icoinedthewordironesty.com"] [unique_id "arw0QaZKVtbodTchFxU9RgAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 21:19:22
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.241.191.198 (198.191.241.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.241.191.198 (198.191.241.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 17:19:19.402433 2026] [security2:error] [pid 21734:tid 21734] [client 35.241.191.198:34048] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.fritsknuf.com"] [uri "/backend/.env"] [unique_id "arwrVzkOsmUfDjkTSJyYxgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-09-29 21:04:07
(1 day ago)
[TueSep2923:04:05.2937912026][security2:error][pid1292021:tid1292103][client35.241.191.198:0]ModSecu ...
show more
[TueSep2923:04:05.2937912026][security2:error][pid1292021:tid1292103][client35.241.191.198:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"710\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"cpcalendars.eutecne.ch\"][uri\"/@fs/app/.env\"][unique_id\"arwnxfB-4PbL0hwwxgkydQAAAQM\"]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 20:59:52
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.241.191.198 (198.191.241.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.241.191.198 (198.191.241.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 16:59:45.346945 2026] [security2:error] [pid 25195:tid 25195] [client 35.241.191.198:33244] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "groz.net"] [uri "/images../.env"] [unique_id "arwmwRDa0Q__L_uJ8rdz4AAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack