Anonymous
2026-09-16 00:24:39
(13 hours ago)
2026/09/16 00:24:35 [error] 199230#199230: *585274 [client 35.189.129.113] ModSecurity: Access denie ...
show more
2026/09/16 00:24:35 [error] 199230#199230: *585274 [client 35.189.129.113] ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Ge' with parameter `5' against variable `TX:BLOCKING_INBOUND_ANOMALY_SCORE' (Value: `5' ) [file "/usr/local/owasp-modsecurity-crs-4.11.0/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "222"] [id "949110"] [rev ""] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [data ""] [severity "0"] [ver "OWASP_CRS/4.29.0"] [maturity "0"] [accuracy "0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "machinexgh.com"] [uri "/.env"] [unique_id "178951827566.509806"] [ref ""], client: 35.189.129.113, server: machinexgh.com, request: "GET /.env HTTP/1.1", host: "machinexgh.com", referrer: "https://www.google.com/"
2026/09/16 00:24:37 [error] 199230#199230: *585274 [client 35.189.129.113] ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Ge' with parameter `5' against variable `TX:BLOCKING_INBOUND_ANOMALY_SCORE' (Value: `5' )
...
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-16 00:02:35
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.189.129.113 (113.129.189.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.189.129.113 (113.129.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 20:02:28.885627 2026] [security2:error] [pid 4399:tid 4399] [client 35.189.129.113:41712] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "machineryenchantress.com"] [uri "/.env"] [unique_id "aqnclMpEfIgIJfY9tv2qMgAAABo"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 21:51:00
(15 hours ago)
(mod_security) mod_security (id:949110) triggered by 35.189.129.113 (113.129.189.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:949110) triggered by 35.189.129.113 (113.129.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 17:50:55.291339 2026] [security2:error] [pid 14448:tid 14448] [client 35.189.129.113:46020] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "historycruisesbookings.com"] [uri "/.env"] [unique_id "aqm9vzJDFc0ljmkFx0xfqgAAAA0"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-15 21:11:08
(16 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-15 17:23:49
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.189.129.113 (113.129.189.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.189.129.113 (113.129.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 13:23:45.891748 2026] [security2:error] [pid 20662:tid 20662] [client 35.189.129.113:38262] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ekur-art.com"] [uri "/.env"] [unique_id "aql_IT3rvu6PRPy0eX-PZAAAAA4"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-15 15:55:57
(21 hours ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 15:05:53
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.189.129.113 (113.129.189.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.189.129.113 (113.129.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 11:05:46.593084 2026] [security2:error] [pid 13905:tid 13905] [client 35.189.129.113:39986] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "calebdavison.com"] [uri "/.env"] [unique_id "aqleyvjll2iZHlP0wekYwwAAAAk"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 11:09:11
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.189.129.113 (113.129.189.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.189.129.113 (113.129.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 07:09:05.924440 2026] [security2:error] [pid 25662:tid 25662] [client 35.189.129.113:34388] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bayoutown.org"] [uri "/.env"] [unique_id "aqknUcYvW35s7iO3_GfhHAAAAAw"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 10:44:29
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.189.129.113 (113.129.189.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.189.129.113 (113.129.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 06:44:24.106610 2026] [security2:error] [pid 17159:tid 17159] [client 35.189.129.113:33910] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bayareahiphopforever.org"] [uri "/.env"] [unique_id "aqkhiAFgTVKjYcXXGTolDQAAAAI"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
akasolutions.de
2026-09-15 09:07:26
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted] 35.189.129.113 (JP/Japan/113.129.189.35 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.189.129.113 (JP/Japan/113.129.189.35.bc.googleusercontent.com)
show less
SQL Injection
๐ฉ๐ช
gadix
2026-09-15 07:59:59
(1 day ago)
[15/Sep/2026:09:59:54.058464 +0200] aqj6-lDgVyqnJxnEl6rt8QAAAEY 35.189.129.113 57270 127.0.0.1 7081
...
show more
[15/Sep/2026:09:59:54.058464 +0200] aqj6-lDgVyqnJxnEl6rt8QAAAEY 35.189.129.113 57270 127.0.0.1 7081
[15/Sep/2026:09:59:58.548141 +0200] aqj6_lDgVyqnJxnEl6rt9AAAAFU 35.189.129.113 57308 127.0.0.1 7081
[15/Sep/2026:09:59:59.074454 +0200] aqj6_1DgVyqnJxnEl6rt9QAAAEI 35.189.129.113 57322 127.0.0.1 7081
...
show less
Web App Attack
๐ฌ๐ง
consul.to
2026-09-15 04:18:23
(1 day ago)
Web attack/malicious scanning detected
Web App Attack