๐ท๐ธ
pexodelic
2026-10-02 04:05:02
(3 days ago)
Automated report from web, SSH and FTP server logs: 642 requests probing for exposed secrets (.env, ...
show more
Automated report from web, SSH and FTP server logs: 642 requests probing for exposed secrets (.env, .git, config files). First reported 2026-10-01 12:35 UTC, last reported 2026-10-02 06:05 UTC; counts cover the current log rotation window.
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 15:14:56
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.243.104.58 (58.104.243.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.243.104.58 (58.104.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 11:14:50.445926 2026] [security2:error] [pid 24209:tid 24209] [client 35.243.104.58:52784] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.victotex.com"] [uri "/laravel/.env"] [unique_id "ar546mynKMNKGy9oO2fuDwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 14:57:17
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.243.104.58 (58.104.243.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.243.104.58 (58.104.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 10:57:14.305227 2026] [security2:error] [pid 29111:tid 29111] [client 35.243.104.58:33620] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.skyfall-estate.com"] [uri "/.htpasswd"] [unique_id "ar50ytxPIuPxljAoHQL1rwAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐พ
Rizzy
2026-10-01 14:53:51
(3 days ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 14:38:11
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 35.243.104.58 (58.104.243.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.243.104.58 (58.104.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 10:38:05.172462 2026] [security2:error] [pid 14543:tid 14543] [client 35.243.104.58:36042] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.title37.com|F|2"] [data ".title37.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.title37.com"] [uri "/z9x8c7v6b5-debug-trigger-www.title37.com"] [unique_id "ar5wTWQs3UMdBWKqa28E5wAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 14:16:59
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.243.104.58 (58.104.243.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.243.104.58 (58.104.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 10:16:55.682862 2026] [security2:error] [pid 27831:tid 27831] [client 35.243.104.58:57838] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.somehand.com"] [uri "/.htpasswd"] [unique_id "ar5rV4R1Yr-M5T_QDfn8jgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 14:01:39
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.243.104.58 (58.104.243.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.243.104.58 (58.104.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 10:01:35.496515 2026] [security2:error] [pid 14418:tid 14418] [client 35.243.104.58:54164] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.trilliantsolutions.com"] [uri "/.htpasswd"] [unique_id "ar5nvxAcvA6ZJCVhtbK40wAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-10-01 13:51:15
(3 days ago)
Excessive 404/403 errors
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-10-01 13:39:14
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.243.104.58 (58.104.243.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.243.104.58 (58.104.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 09:39:07.560417 2026] [security2:error] [pid 5841:tid 5841] [client 35.243.104.58:54848] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.transportdelivery.com"] [uri "/.git/config"] [unique_id "ar5iex0pOqIIsuABYL9f3gAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 13:12:07
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.243.104.58 (58.104.243.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.243.104.58 (58.104.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 09:12:03.083498 2026] [security2:error] [pid 28895:tid 28895] [client 35.243.104.58:51684] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.texasbordertours.com"] [uri "/img../.env"] [unique_id "ar5cI1i7rF1kFvtlOweN9gAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-10-01 13:06:35
(3 days ago)
Too many Status 40X (11)
Too many Status 50X (36)
Scanning/Probing (12)
Brute-Force
Web App Attack
Anonymous
2026-10-01 13:03:34
(3 days ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐ซ๐ท
dynamix
2026-10-01 13:00:30
(3 days ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-10-01 12:55:47
(3 days ago)
Blocked by ModSec and CSF
Port Scan
๐บ๐ธ
TPI-Abuse
2026-10-01 12:55:41
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.243.104.58 (58.104.243.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.243.104.58 (58.104.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 08:55:36.225023 2026] [security2:error] [pid 15427:tid 15497] [client 35.243.104.58:35676] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.thecomputergreek.com"] [uri "/.env.js"] [unique_id "ar5YSIgpWpTqiGMU8QMu2gAAAUo"]
show less
Brute-Force
Bad Web Bot
Web App Attack