๐บ๐ธ
TPI-Abuse
2026-09-21 18:16:52
(11 minutes ago)
(mod_security) mod_security (id:210730) triggered by 35.247.180.87 (87.180.247.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.247.180.87 (87.180.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 14:16:45.947964 2026] [security2:error] [pid 529912:tid 529912] [client 35.247.180.87:52872] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||wooferhound.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "wooferhound.com"] [uri "/z9x8c7v6b5-debug-trigger-wooferhound.com"] [unique_id "arF0jTs0Y0DrlBL4wbiJ_gAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 17:30:10
(58 minutes ago)
(mod_security) mod_security (id:210730) triggered by 35.247.180.87 (87.180.247.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.247.180.87 (87.180.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 13:30:04.583862 2026] [security2:error] [pid 16567:tid 16567] [client 35.247.180.87:56856] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.wexfordcap.com|F|2"] [data ".wexfordcap.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.wexfordcap.com"] [uri "/z9x8c7v6b5-debug-trigger-mail.wexfordcap.com"] [unique_id "arFpnO53xA70WIDFM9sY1wAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 16:47:16
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.247.180.87 (87.180.247.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.247.180.87 (87.180.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 12:47:08.569399 2026] [security2:error] [pid 6975:tid 7162] [client 35.247.180.87:49218] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "anthonydalessandro.com"] [uri "/.git/HEAD"] [unique_id "arFfjGXN0yRc26kAdtB3kwAAAk8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2026-09-21 16:22:21
(2 hours ago)
(modsecurity) srv201 ModSecurity 35.247.180.87 (SG/Singapore/87.180.247.35.bc.googleusercontent.com) ...
show more
(modsecurity) srv201 ModSecurity 35.247.180.87 (SG/Singapore/87.180.247.35.bc.googleusercontent.com): 30 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
Anonymous
2026-09-21 16:05:09
(2 hours ago)
WAF repeated trigger detected by Fail2Ban
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 15:39:35
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.247.180.87 (87.180.247.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.247.180.87 (87.180.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 11:39:28.620061 2026] [security2:error] [pid 31891:tid 31891] [client 35.247.180.87:41170] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.billhoy.com"] [uri "/%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env"] [unique_id "arFPsBjmlnvhUxNt2k-n3wAAADA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 15:22:27
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.247.180.87 (87.180.247.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.247.180.87 (87.180.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 11:22:22.656319 2026] [security2:error] [pid 4580:tid 4580] [client 35.247.180.87:45412] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.weismaninfrared.com|F|2"] [data ".weismaninfrared.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.weismaninfrared.com"] [uri "/z9x8c7v6b5-debug-trigger-www.weismaninfrared.com"] [unique_id "arFLrru4kHyihuzvIDCs9wAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 14:57:13
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.247.180.87 (87.180.247.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.247.180.87 (87.180.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 10:57:08.194564 2026] [security2:error] [pid 10566:tid 10588] [client 35.247.180.87:38954] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.woadwellness.com"] [uri "/userfiles"] [unique_id "arFFxJlX9tNgdyQgd1vciwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-09-21 14:45:04
(3 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ฌ๐ง
consul.to
2026-09-21 14:40:55
(3 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 14:39:17
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.247.180.87 (87.180.247.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.247.180.87 (87.180.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 10:39:10.641906 2026] [security2:error] [pid 7185:tid 7185] [client 35.247.180.87:53362] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.wiknwax.com|F|2"] [data ".wiknwax.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.wiknwax.com"] [uri "/z9x8c7v6b5-debug-trigger-mail.wiknwax.com"] [unique_id "arFBjlfc7qzhgWaoOjjUWQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-21 14:29:12
(3 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐ฌ๐ง
Aetherweb Ark
2026-09-21 14:27:10
(4 hours ago)
(mod_security) mod_security (id:949110) triggered by 35.247.180.87 (SG/Singapore/87.180.247.35.bc.go ...
show more
(mod_security) mod_security (id:949110) triggered by 35.247.180.87 (SG/Singapore/87.180.247.35.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
๐บ๐ธ
NXTwoThou
2026-09-21 14:25:38
(4 hours ago)
/graphql
Web App Attack
๐ซ๐ท
dynamix
2026-09-21 14:19:43
(4 hours ago)
Multiple WAF Violations
Web App Attack