๐บ๐ธ
TPI-Abuse
2026-10-02 15:19:41
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 35.187.78.138 (138.78.187.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.187.78.138 (138.78.187.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 11:19:38.867861 2026] [security2:error] [pid 20455:tid 20455] [client 35.187.78.138:53496] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mympizzas.com.mx"] [uri "/.htpasswd"] [unique_id "ar_LilKXaIMwUcKg0H4q4gAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 12:21:35
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 35.187.78.138 (138.78.187.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.187.78.138 (138.78.187.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 08:21:27.455840 2026] [security2:error] [pid 8172:tid 8172] [client 35.187.78.138:45066] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.calentadoresdemexico.com.mx"] [uri "/assets../.env"] [unique_id "ar-hx3i9oM4TXgRqkG__2QAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 10:51:30
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 35.187.78.138 (138.78.187.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.187.78.138 (138.78.187.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 06:51:26.720578 2026] [security2:error] [pid 615:tid 615] [client 35.187.78.138:46992] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.ecuablue.farm|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.ecuablue.farm"] [uri "/server.key"] [unique_id "ar-MrlpwcXlWvMF9wGbNEQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 10:20:35
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 35.187.78.138 (138.78.187.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.187.78.138 (138.78.187.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 06:20:30.569001 2026] [security2:error] [pid 10955:tid 10955] [client 35.187.78.138:52170] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.lightningbug.farm"] [uri "/.htpasswd"] [unique_id "ar-FbqIvwRTN_b6MP7xJUAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
macrob
2026-10-02 10:17:13
(5 days ago)
2026/10/02 10:17:12 [error] 2231818#2231818: *8167670 access forbidden by rule, client: 35.187.78.13 ...
show more
2026/10/02 10:17:12 [error] 2231818#2231818: *8167670 access forbidden by rule, client: 35.187.78.138, server: binixo.mx, request: "GET /media../.env HTTP/2.0", host: "binixo.mx", referrer: "https://www.binixo.mx/media../.env"
2026/10/02 10:17:12 [error] 2231818#2231818: *8167670 access forbidden by rule, client: 35.187.78.138, server: binixo.mx, request: "GET /files../.env HTTP/2.0", host: "binixo.mx", referrer: "https://www.binixo.mx/files../.env"
2026/10/02 10:17:12 [error] 2231818#2231818: *8167670 access forbidden by rule, client: 35.187.78.138, server: binixo.mx, request: "GET /assets../.env HTTP/2.0", host: "binixo.mx", referrer: "https://www.binixo.mx/assets../.env"
...
show less
Web App Attack
๐ฉ๐ช
updown.io
2026-10-02 10:08:57
(5 days ago)
{"level":"info","ts":1790935736.3246667,"logger":"http.log.access.log1","msg":"handled request","req ...
show more
{"level":"info","ts":1790935736.3246667,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"35.187.78.138","remote_port":"38184","client_ip":"35.187.78.138","proto":"HTTP/2.0","method":"GET","host":"status.shoemaker.farm","uri":"/0oadb5eika2dm5sazy5s","headers":{"Accept":["*/*"],"X-Middleware-Subrequest":["src/middleware:nowaf:src/middleware:src/middleware:src/middleware:src/middleware:middleware:middleware:nowaf:middleware:middleware:middleware:pages/_middleware"],"X-Nextjs-Data":["1"],"User-Agent":["Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36"],"Accept-Encoding":["gzip"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"h2","server_name":"status.shoemaker.farm","ech":false}},"bytes_read":0,"user_id":"","duration":0.000110471,"size":0,"status":429,"resp_headers":{"Server":["Caddy"],"Alt-Svc":["h3=\":443\"; ma=2592000"],"Retry-After":["1"]}}
{"level":"info","ts":1790935736.3268867,"logger":"http.log
...
show less
DDoS Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 09:34:34
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 35.187.78.138 (138.78.187.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.187.78.138 (138.78.187.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 05:34:27.748711 2026] [security2:error] [pid 25651:tid 25651] [client 35.187.78.138:33576] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.radiofamilia.com.mx"] [uri "/static//.env"] [unique_id "ar96o-1OKd5VfRCTySowzgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
rzk
2026-10-02 07:42:03
(5 days ago)
CrowdSec scenario: crowdsecurity/http-sensitive-files. Banned by Koru Cloud platform after multi-eve ...
show more
CrowdSec scenario: crowdsecurity/http-sensitive-files. Banned by Koru Cloud platform after multi-event detection. ASN: GOOGLE-CLOUD-PLATFORM. Country: BE. Timestamp: 2026-10-02T07:42:03+00:00.
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 07:08:53
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 35.187.78.138 (138.78.187.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.187.78.138 (138.78.187.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 03:08:49.690544 2026] [security2:error] [pid 28070:tid 28070] [client 35.187.78.138:35548] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.sendera.mx"] [uri "/.htpasswd"] [unique_id "ar9YgVPSGeUsN7kqCwkTCQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-02 05:47:05
(5 days ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-10-02 05:23:55
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 35.187.78.138 (138.78.187.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.187.78.138 (138.78.187.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 01:23:49.842344 2026] [security2:error] [pid 30201:tid 30201] [client 35.187.78.138:48018] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "elgarage.elpais.mx"] [uri "/static//home/user/.env"] [unique_id "ar8_5Rlyb3TZhhYenigXhAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-10-02 04:39:11
(5 days ago)
Web attack/malicious scanning detected
Web App Attack
Anonymous
2026-10-02 04:29:42
(5 days ago)
(mod_security) mod_security triggered on hostname [redacted] 35.187.78.138 (BE/Belgium/138.78.187.35 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.187.78.138 (BE/Belgium/138.78.187.35.bc.googleusercontent.com)
show less
SQL Injection
๐บ๐ธ
OceanTreasure
2026-10-02 03:42:07
(5 days ago)
tcp/8443; Unsolicited SYN to a port that has never been offered on this address (closed, no service ...
show more
tcp/8443; Unsolicited SYN to a port that has never been offered on this address (closed, no service ever) @ 2026-10-02T03:37:42Z
show less
Port Scan