๐บ๐ธ
TPI-Abuse
2026-09-21 01:36:41
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.252.194.100 (100.194.252.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.252.194.100 (100.194.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 21:36:33.073845 2026] [security2:error] [pid 28909:tid 28931] [client 35.252.194.100:58430] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thatspecial.com"] [uri "/admin/.env"] [unique_id "arCKIQBu0q6s2SRZeFAqYQAAARQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 01:01:26
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.252.194.100 (100.194.252.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.252.194.100 (100.194.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 21:01:22.989216 2026] [security2:error] [pid 3494:tid 3494] [client 35.252.194.100:49760] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||portlunchgroup.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "portlunchgroup.com"] [uri "/z9x8c7v6b5-debug-trigger-portlunchgroup.com"] [unique_id "arCB4jWs-AJQbr4pOSWXDgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 00:30:13
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.252.194.100 (100.194.252.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.252.194.100 (100.194.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 20:30:05.648028 2026] [security2:error] [pid 13205:tid 13205] [client 35.252.194.100:38542] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "test.fritsknuf.com"] [uri "/backend/.env"] [unique_id "arB6jQk2bGmIk37lxCj3_wAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-21 00:12:27
(4 hours ago)
20 attempts against mh-misbehave-ban on lunar
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-09-21 00:05:21
(4 hours ago)
Too many Status 40X (20)
Too many Status 50X (295)
Scanning/Probing (148)
Request Overload (315)
Brute-Force
Web App Attack
๐ฌ๐ง
WebNiraj
2026-09-21 00:00:50
(4 hours ago)
(cpanel) Failed cPanel login from 35.252.194.100 (US/United States/100.194.252.35.bc.googleuserconte ...
show more
(cpanel) Failed cPanel login from 35.252.194.100 (US/United States/100.194.252.35.bc.googleusercontent.com): 5 in the last 3600 secs [SIGMA]
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 23:44:12
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.252.194.100 (100.194.252.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.252.194.100 (100.194.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 19:44:05.628892 2026] [security2:error] [pid 15190:tid 15214] [client 35.252.194.100:40402] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.anthonydalessandro.com"] [uri "/.env.old"] [unique_id "arBvxfZwOhW-Odp13o1muQAAAJU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-20 23:30:04
(4 hours ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-09-20 23:07:17
(5 hours ago)
(mod_security) mod_security (id:243320) triggered by 35.252.194.100 (100.194.252.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:243320) triggered by 35.252.194.100 (100.194.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 19:07:10.431565 2026] [security2:error] [pid 25112:tid 25112] [client 35.252.194.100:40842] ModSecurity: Access denied with code 403 (phase 2). String match "/.profile" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6621"] [id "243320"] [rev "1"] [msg "COMODO WAF: Information disclosure vulnerability in Cloud Foundry PHP Buildpack (aka php-buildpack) before 4.3.18 and PHP Buildpack Cf-release before 242, as used in Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.6.38 and 1.7.x before 1.7.19 and other products (CVE-2016-6639)||www.theateroobleck.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.theateroobleck.com"] [uri "/.profile"] [unique_id "arBnHlzWyoHRAuf1PCApgQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-09-20 22:25:03
(5 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ซ๐ท
dynamix
2026-09-20 22:21:17
(6 hours ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-09-20 22:04:24
(6 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 22:02:08
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.252.194.100 (100.194.252.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.252.194.100 (100.194.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 18:02:01.612014 2026] [security2:error] [pid 9994:tid 9994] [client 35.252.194.100:39838] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.tolenaar.com"] [uri "/internal/.env"] [unique_id "arBX2ffvrbj7g76wcnrdFgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2026-09-20 21:53:02
(6 hours ago)
(modsecurity) srv104 ModSecurity 35.252.194.100 (US/United States/100.194.252.35.bc.googleuserconten ...
show more
(modsecurity) srv104 ModSecurity 35.252.194.100 (US/United States/100.194.252.35.bc.googleusercontent.com): 30 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 21:29:12
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.252.194.100 (100.194.252.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.252.194.100 (100.194.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 17:29:04.689916 2026] [security2:error] [pid 24021:tid 24021] [client 35.252.194.100:47982] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.restorationclinic1.com"] [uri "/.env.prod"] [unique_id "arBQIJ4EyJMf4Jn-AnAvfwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack