๐บ๐ธ
mnsf
2026-09-30 05:05:30
(1 day ago)
Too many Status 40X (14)
Too many Status 50X (146)
Scanning/Probing (54)
Request Overload (160)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 04:20:37
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.247.147.253 (253.147.247.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.247.147.253 (253.147.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 00:20:30.860951 2026] [security2:error] [pid 31392:tid 31392] [client 35.247.147.253:58482] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "robtown.com"] [uri "/.env.bak"] [unique_id "aryODjot1Y7IReMfo3hq2wAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 03:26:33
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.247.147.253 (253.147.247.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.247.147.253 (253.147.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 23:26:25.861712 2026] [security2:error] [pid 17486:tid 17486] [client 35.247.147.253:32832] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.socconstruction.com"] [uri "/frontend/.env"] [unique_id "aryBYZOloMnr_Rce7FIc-gAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 02:38:44
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.247.147.253 (253.147.247.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.247.147.253 (253.147.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 22:38:39.020150 2026] [security2:error] [pid 5529:tid 5529] [client 35.247.147.253:57128] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.papapizza.pizza"] [uri "/build/.env"] [unique_id "arx2L__xlTRgfhL3WzRdjQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 02:01:39
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.247.147.253 (253.147.247.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.247.147.253 (253.147.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 22:01:33.214373 2026] [security2:error] [pid 13038:tid 13038] [client 35.247.147.253:43868] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.rgvatvrepair.com"] [uri "/.env.prod"] [unique_id "arxtff1vZOPkW-PcQZSYRQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 00:54:11
(1 day ago)
(mod_security) mod_security (id:210580) triggered by 35.247.147.253 (253.147.247.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210580) triggered by 35.247.147.253 (253.147.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 20:54:05.921882 2026] [security2:error] [pid 715:tid 715] [client 35.247.147.253:52274] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at ARGS:apis. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||riverflow.com|F|2"] [data "Matched Data: proc/self/environ found within ARGS:apis: ../../../../../../proc/self/environ"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "riverflow.com"] [uri "/api/console/api_server"] [unique_id "arxdrfVuj7C1SpRSgn8OPgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-30 00:48:09
(1 day ago)
[ti-07al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-07al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 35.247.147.253 - - [30/Sep/2026:02:47:59 +0200] "GET /phpinfo.php HTTP/1.1" 403 485 "-" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 00:09:44
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.247.147.253 (253.147.247.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.247.147.253 (253.147.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 20:09:37.056909 2026] [security2:error] [pid 8807:tid 8807] [client 35.247.147.253:55422] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.pamelalambert.com"] [uri "/.env.local"] [unique_id "arxTQaSmCZrwHw4ojWIycgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-29 22:36:49
(2 days ago)
[ns41.kdns.gr] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/.env.example | /.env.prod ...
show more
[ns41.kdns.gr] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/.env.example | /.env.production | /.env.local
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 22:25:48
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.247.147.253 (253.147.247.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.247.147.253 (253.147.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 18:25:43.285669 2026] [security2:error] [pid 25742:tid 25742] [client 35.247.147.253:32940] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.southshorestreetrods.com"] [uri "/web/.env"] [unique_id "arw656icU1IBSVe8MJBMHgAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-29 22:17:03
(2 days ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 21:08:00
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.247.147.253 (253.147.247.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.247.147.253 (253.147.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 17:07:57.391105 2026] [security2:error] [pid 26570:tid 26586] [client 35.247.147.253:35892] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.rodela.com"] [uri "/%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env"] [unique_id "arworYdC_FusltgLC_It0gAAAMY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 20:12:29
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 35.247.147.253 (253.147.247.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.247.147.253 (253.147.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 16:12:21.342958 2026] [security2:error] [pid 22644:tid 22644] [client 35.247.147.253:59304] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||parkhan.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "parkhan.com"] [uri "/z9x8c7v6b5-debug-trigger-parkhan.com"] [unique_id "arwbpRXFOqrGIz1wv3A0kwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 19:41:14
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.247.147.253 (253.147.247.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.247.147.253 (253.147.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 15:41:07.120191 2026] [security2:error] [pid 21338:tid 21338] [client 35.247.147.253:43160] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.sicktracks.com"] [uri "/.env"] [unique_id "arwUU5usg4QYnDVB7KieEwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐พ
Rizzy
2026-09-29 18:57:49
(2 days ago)
Multiple WAF Violations
Brute-Force
Web App Attack