๐บ๐ธ
TPI-Abuse
2026-09-21 23:48:47
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.247.173.238 (238.173.247.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.247.173.238 (238.173.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 19:48:44.366185 2026] [security2:error] [pid 19136:tid 19136] [client 35.247.173.238:44780] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.web-sitebuilder.com"] [uri "/services/.env"] [unique_id "arHCXO2sxmKsKIxUgt2D2gAAADg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-21 22:46:45
(10 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 20:46:54
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.247.173.238 (238.173.247.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.247.173.238 (238.173.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 16:46:48.271228 2026] [security2:error] [pid 5357:tid 5357] [client 35.247.173.238:55640] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.weddingcp.com"] [uri "/@fs/app/.env"] [unique_id "arGXuOUq223P--nB9IfdZgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
poundawebsiteltd
2026-09-21 18:57:07
(13 hours ago)
Malicious activity in general-malicious. Evidence: (apache_probe) Failed Access (403/404) 35.247.173 ...
show more
Malicious activity in general-malicious. Evidence: (apache_probe) Failed Access (403/404) 35.247.173.238 (SG/Singapore/[REDACTED_DOMAIN]): 20 in the last 3600 secs | UA: (apache_probe) Failed Access (403/404) 35.247.173.238 (SG/Singapore/238.173.247.35.bc.googleusercontent.com): 20 in the last 3600 secs
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 18:26:01
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.247.173.238 (238.173.247.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.247.173.238 (238.173.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 14:25:54.609799 2026] [security2:error] [pid 10567:tid 10675] [client 35.247.173.238:60756] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.psychclinicforchange.com"] [uri "/.env.example"] [unique_id "arF2sqwQYSIoQZ0rFuLBgwAAAE0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-09-21 18:05:19
(14 hours ago)
Scanning/Probing (11)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 17:41:52
(15 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.247.173.238 (238.173.247.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.247.173.238 (238.173.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 13:41:47.881215 2026] [security2:error] [pid 4925:tid 4925] [client 35.247.173.238:53986] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||waggonerfinancial.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "waggonerfinancial.com"] [uri "/z9x8c7v6b5-debug-trigger-waggonerfinancial.com"] [unique_id "arFsW1v5Ib3gYR3-CaaBsQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-21 17:12:14
(15 hours ago)
[ti-01al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-01al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 35.247.173.238 - - [21/Sep/2026:19:12:09 +0200] "GET /.aws/credentials HTTP/1.1" 404 2110 "-" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/)"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 15:23:39
(17 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.247.173.238 (238.173.247.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.247.173.238 (238.173.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 11:23:35.961040 2026] [security2:error] [pid 328822:tid 328822] [client 35.247.173.238:51746] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.waterarchitecture.com|F|2"] [data ".waterarchitecture.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.waterarchitecture.com"] [uri "/z9x8c7v6b5-debug-trigger-mail.waterarchitecture.com"] [unique_id "arFL946xnkbGuCD1PACQVQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
rsa
2026-09-21 15:21:00
(17 hours ago)
GET /icons/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/proc/self/environ HTTP
DDoS Attack
Exploited Host
Web App Attack
๐ฒ๐พ
Rizzy
2026-09-21 15:01:48
(17 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ณ๐ฑ
ConsulHosting
2026-09-21 14:52:36
(17 hours ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
Anonymous
2026-09-21 14:49:56
(17 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 14:41:37
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.247.173.238 (238.173.247.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.247.173.238 (238.173.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 10:41:31.028718 2026] [security2:error] [pid 6973:tid 7212] [client 35.247.173.238:55762] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.wbwstudio.com"] [uri "/userfiles"] [unique_id "arFCG-nGAoDSm12nz2RXGAAAAYs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 14:26:16
(18 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.247.173.238 (238.173.247.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.247.173.238 (238.173.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 10:26:10.937093 2026] [security2:error] [pid 26250:tid 26270] [client 35.247.173.238:35478] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||wasula.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "wasula.com"] [uri "/z9x8c7v6b5-debug-trigger-wasula.com"] [unique_id "arE-ghCBaSEmDeYab75qmwAAAUI"]
show less
Brute-Force
Bad Web Bot
Web App Attack