๐บ๐ธ
TPI-Abuse
2026-07-24 10:12:11
(9 hours ago)
(mod_security) mod_security (id:210730) triggered by 95.179.134.148 (95.179.134.148.vultrusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 95.179.134.148 (95.179.134.148.vultrusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 06:12:07.719276 2026] [security2:error] [pid 3952913:tid 3952913] [client 95.179.134.148:51300] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||podbillspec.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "podbillspec.com"] [uri "/storage/logs/laravel-2026-07-21.log"] [unique_id "amM6d1zbBrvNOG4Y8U4OmQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 09:40:16
(10 hours ago)
(mod_security) mod_security (id:210730) triggered by 95.179.134.148 (95.179.134.148.vultrusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 95.179.134.148 (95.179.134.148.vultrusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 05:40:11.764354 2026] [security2:error] [pid 269020:tid 269067] [client 95.179.134.148:61535] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||paywithfortress.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "paywithfortress.com"] [uri "/storage/logs/laravel-2026-07-21.log"] [unique_id "amMy-6Q0ocjb3hrZgbTttQAAAY8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 08:38:31
(11 hours ago)
(mod_security) mod_security (id:210730) triggered by 95.179.134.148 (95.179.134.148.vultrusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 95.179.134.148 (95.179.134.148.vultrusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 04:38:24.699638 2026] [security2:error] [pid 2022108:tid 2022108] [client 95.179.134.148:64774] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||payrrip.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "payrrip.com"] [uri "/storage/logs/laravel-2026-07-21.log"] [unique_id "amMkgGlkrK_jkI5M8_y7kwAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 17:37:49
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 95.179.134.148 (95.179.134.148.vultrusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 95.179.134.148 (95.179.134.148.vultrusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 13:37:42.982729 2026] [security2:error] [pid 3196733:tid 3196733] [client 95.179.134.148:59711] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||billystuff.net|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "billystuff.net"] [uri "/storage/logs/laravel-2026-07-21.log"] [unique_id "amJRZimwV3kwtzk6mwnqqwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 17:21:51
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 95.179.134.148 (95.179.134.148.vultrusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 95.179.134.148 (95.179.134.148.vultrusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 13:21:47.578924 2026] [security2:error] [pid 2893249:tid 2893249] [client 95.179.134.148:62090] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||billyclouse.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "billyclouse.com"] [uri "/storage/logs/laravel-2026-07-21.log"] [unique_id "amJNq3B8v4Czy_CDdhm45gAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 17:05:28
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 95.179.134.148 (95.179.134.148.vultrusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 95.179.134.148 (95.179.134.148.vultrusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 13:05:21.517162 2026] [security2:error] [pid 2468664:tid 2468664] [client 95.179.134.148:63846] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||billswilliams.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "billswilliams.com"] [uri "/storage/logs/laravel-2026-07-21.log"] [unique_id "amJJ0Ru5jFf90zkwz--gPwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 15:12:09
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 95.179.134.148 (95.179.134.148.vultrusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 95.179.134.148 (95.179.134.148.vultrusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 11:12:06.580573 2026] [security2:error] [pid 3518575:tid 3518590] [client 95.179.134.148:57960] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||billgiegold.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "billgiegold.com"] [uri "/storage/logs/laravel-2026-07-21.log"] [unique_id "amIvRk7S4F3B6187ieOuCQAAAEk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 04:48:12
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 95.179.134.148 (95.179.134.148.vultrusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 95.179.134.148 (95.179.134.148.vultrusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 00:48:04.874029 2026] [security2:error] [pid 3034194:tid 3034194] [client 95.179.134.148:54231] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "picklebillystayandplay.com"] [uri "/.env"] [unique_id "amGdBEpj2-7BCt2k-NlhBwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 03:24:08
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 95.179.134.148 (95.179.134.148.vultrusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 95.179.134.148 (95.179.134.148.vultrusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 23:24:01.911097 2026] [security2:error] [pid 1650571:tid 1650608] [client 95.179.134.148:64636] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "paylessformedicine.com"] [uri "/.env"] [unique_id "amGJUe2NMqO7XscawdpzVAAAAEQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 00:21:20
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 95.179.134.148 (95.179.134.148.vultrusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 95.179.134.148 (95.179.134.148.vultrusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 20:21:13.247858 2026] [security2:error] [pid 1585945:tid 1585945] [client 95.179.134.148:59537] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "csmedicalbilling.com"] [uri "/.env"] [unique_id "amFeef8Jw8rONGqvg4aiNAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-22 23:07:38
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 95.179.134.148 (95.179.134.148.vultrusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 95.179.134.148 (95.179.134.148.vultrusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 19:07:30.555831 2026] [security2:error] [pid 1643577:tid 1643577] [client 95.179.134.148:52540] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "adampayments.com"] [uri "/.env"] [unique_id "amFNMmMLXmyQ-8v_bjk4qwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2026-07-22 23:06:17
(1 day ago)
IM360 WAF: Direct access to sensitive file or dotfile MV:/.env
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-22 22:46:49
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 95.179.134.148 (95.179.134.148.vultrusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 95.179.134.148 (95.179.134.148.vultrusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 18:46:42.459173 2026] [security2:error] [pid 1447153:tid 1447153] [client 95.179.134.148:59301] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "billfried.net"] [uri "/.env"] [unique_id "amFIUki8ksuW49cRK_Ac5gAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-22 20:21:26
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 95.179.134.148 (95.179.134.148.vultrusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 95.179.134.148 (95.179.134.148.vultrusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 16:21:22.116097 2026] [security2:error] [pid 1837056:tid 1837056] [client 95.179.134.148:59161] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||hotpay.co|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "hotpay.co"] [uri "/storage/logs/laravel-2026-07-21.log"] [unique_id "amEmQivK73ufPCtUXffCwQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack