🇺🇸
infra-monitor
2026-09-07 03:00:05
(1 hour ago)
Automated ban via infra-monitor: mgmt-path-probe, wp-sensitive-paths, suspicious-probe, +6 more
Port Scan
Bad Web Bot
Web App Attack
Anonymous
2026-09-07 02:25:36
(2 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 02:06:26
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.189.207.86 (86.207.189.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.189.207.86 (86.207.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 22:06:20.800494 2026] [security2:error] [pid 26495:tid 26495] [client 35.189.207.86:38796] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "needtoorder.us"] [uri "/@fs/app/.env.production"] [unique_id "ap4cHBxyCZeosaN2qJZvgwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 01:24:44
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.189.207.86 (86.207.189.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.189.207.86 (86.207.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 21:24:38.796216 2026] [security2:error] [pid 10562:tid 10562] [client 35.189.207.86:56818] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.rimbey.us|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.rimbey.us"] [uri "/rclone.conf"] [unique_id "ap4SVkkXV7II2nNhDR0D-gAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 00:56:55
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.189.207.86 (86.207.189.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.189.207.86 (86.207.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 20:56:50.090517 2026] [security2:error] [pid 29520:tid 29546] [client 35.189.207.86:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.mindgardens.com"] [uri "/.env"] [unique_id "ap4L0r23YQ-tHnhiXmGJxgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
ConsulHosting
2026-09-07 00:53:04
(3 hours ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
🇺🇸
Starburst SysOp Team
2026-09-06 23:31:58
(5 hours ago)
(mod_security-custom) mod_security (id:210730) triggered by 35.189.207.86 (BE/Belgium/Brussels Capit ...
show more
(mod_security-custom) mod_security (id:210730) triggered by 35.189.207.86 (BE/Belgium/Brussels Capital/Brussels/86.207.189.35.bc.googleusercontent.com/[AS396982 GOOGLE-CLOUD-PLATFORM]): 1 in the last 3600 secs (0-srv1)
show less
Hacking
🇫🇷
Catalin Negru
2026-09-06 23:01:33
(5 hours ago)
Recidive ban by fail2ban on server.blackbit.ro
Brute-Force
🇩🇪
abuse-detection
2026-09-06 21:32:53
(7 hours ago)
Web security detection (http-sensitive-probe); path=/__vite_rsc_findSourceMapURL; status=301
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 20:35:17
(8 hours ago)
(mod_security) mod_security (id:210580) triggered by 35.189.207.86 (86.207.189.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210580) triggered by 35.189.207.86 (86.207.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 16:35:11.280475 2026] [security2:error] [pid 12345:tid 12345] [client 35.189.207.86:55078] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at ARGS:path. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||www.vjrott.com|F|2"] [data "Matched Data: proc/self/environ found within ARGS:path: /proc/self/environ"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "www.vjrott.com"] [uri "/api/fs/read"] [unique_id "ap3Ofwy1jKL4qjdq7f--rAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
bazter.pro
2026-09-06 20:08:01
(8 hours ago)
Fail2Ban: plesk-bot-aggressive - 15 failures
Port Scan
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 20:06:34
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.189.207.86 (86.207.189.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.189.207.86 (86.207.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 16:06:26.607540 2026] [security2:error] [pid 30105:tid 30105] [client 35.189.207.86:42482] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.growtowork.com"] [uri "/img../.env"] [unique_id "ap3HwoA4XckhctvVNYA9BgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Octopuce
2026-09-06 19:50:58
(8 hours ago)
Aggressive web search of vulnerable pages: /_nuxt/../.env /static../.env /media../.env /static//.env ...
show more
Aggressive web search of vulnerable pages: /_nuxt/../.env /static../.env /media../.env /static//.env /static//app/.env ...
show less
Web App Attack
🇳🇱
Site.eu
2026-09-06 19:32:58
(9 hours ago)
Excessive multi-domain requests
Brute-Force
🇵🇱
strefapi_com
2026-09-06 19:10:50
(9 hours ago)
Brute-force, web
...
Hacking
Brute-Force
Web App Attack