Anonymous
2026-09-04 03:14:28
(2 hours ago)
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: TW, Attack patterns: Word ...
show more
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: TW, Attack patterns: WordPress scanning, Backup file probing, Cloud secrets probing
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-03 15:36:06
(13 hours ago)
35.194.255.134 - - [03/Sep/2026:10:36:03 -0500] "GET /.env HTTP/1.1" 302 238 "-" "Mozilla/5.0 (Windo ...
show more
35.194.255.134 - - [03/Sep/2026:10:36:03 -0500] "GET /.env HTTP/1.1" 302 238 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" 172.71.218.52
35.194.255.134 - - [03/Sep/2026:10:36:03 -0500] "GET /.env.local HTTP/1.1" 302 244 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" 172.71.218.204
35.194.255.134 - - [03/Sep/2026:10:36:04 -0500] "GET /.env.production HTTP/1.1" 302 249 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" 172.71.218.204
35.194.255.134 - - [03/Sep/2026:10:36:04 -0500] "GET /.env.staging HTTP/1.1" 302 246 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" 172.71.218.204
35.194.255.134 - - [03/Sep/2026:10:36:04 -0500] "GET /.env.development HTTP/1.1" 302 250 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64)
...
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 15:03:58
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.194.255.134 (134.255.194.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.194.255.134 (134.255.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 11:03:53.731287 2026] [security2:error] [pid 11650:tid 11650] [client 35.194.255.134:55406] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.coolerboxes.greenlight.us"] [uri "/.git/config"] [unique_id "apmMWS2uh0UNhiZQlzXebAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
cmbplf
2026-09-03 13:15:45
(16 hours ago)
6.148 requests from abuseipdb.com blacklisted IP (9mos4w11h)
Brute-Force
Bad Web Bot
🇿🇦
conure.sh
2026-09-03 12:11:14
(17 hours ago)
csagent: score 19.9: secrets grab x2; 1 domain(s) in 5s
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 12:07:33
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.194.255.134 (134.255.194.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.194.255.134 (134.255.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 08:07:24.587914 2026] [security2:error] [pid 22001:tid 22001] [client 35.194.255.134:54400] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.cookerwars.windisfun.com"] [uri "/.env"] [unique_id "apli_AldQ9Uk5Ok-efCIBwAAAJM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 11:40:22
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.194.255.134 (134.255.194.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.194.255.134 (134.255.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 07:40:13.968446 2026] [security2:error] [pid 23506:tid 23506] [client 35.194.255.134:42108] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.cook-islands-boat-registration.com.boatregistrationdelaware.com"] [uri "/.git/config"] [unique_id "aplcnd1SLqAr5NHDHl2QOwAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 10:34:18
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.194.255.134 (134.255.194.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.194.255.134 (134.255.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 06:34:11.953376 2026] [security2:error] [pid 24756:tid 24756] [client 35.194.255.134:46344] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.conveyorizedovens.com.daveweisman.com"] [uri "/.git/config"] [unique_id "aplNI7UYJXsPk7culbUXiQAAAI8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
srtzero
2026-09-03 09:13:42
(20 hours ago)
35.194.255.134 - - [03/Sep/2026:11:13:41 +0200] "GET /.git/config HTTP/1.1" 404 1382 "-" "Mozilla/5. ...
show more
35.194.255.134 - - [03/Sep/2026:11:13:41 +0200] "GET /.git/config HTTP/1.1" 404 1382 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.194.255.134 - - [03/Sep/2026:11:13:41 +0200] "GET /.env.local HTTP/1.1" 404 1382 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.194.255.134 - - [03/Sep/2026:11:13:42 +0200] "GET /.env.production HTTP/1.1" 404 1382 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Port Scan
Bad Web Bot
Web App Attack
🇩🇪
BlueWire Hosting
2026-09-03 07:54:52
(21 hours ago)
High-confidence malicious configuration/VCS probe
Web App Attack
🇳🇱
Site.eu
2026-09-03 07:16:25
(22 hours ago)
Excessive multi-domain requests
Brute-Force
🇺🇸
TPI-Abuse
2026-09-03 06:22:39
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.194.255.134 (134.255.194.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.194.255.134 (134.255.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 02:22:35.130875 2026] [security2:error] [pid 4333:tid 4333] [client 35.194.255.134:44782] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.contrarianadvisors.royal-barbershop.com"] [uri "/.git/config"] [unique_id "apkSK3q73QWAliw7-3jRsgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-03 05:59:06
(23 hours ago)
Banned by Fail2Ban on server
Web App Attack
🇳🇿
Antinson
2026-09-03 04:51:29
(1 day ago)
Scraping with a high error ratio and request rate
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-03 04:41:07
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.194.255.134 (134.255.194.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.194.255.134 (134.255.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 00:41:00.277850 2026] [security2:error] [pid 29707:tid 29707] [client 35.194.255.134:43802] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.continuity.productions.theknowledgemaster.com"] [uri "/.git/config"] [unique_id "apj6XI9AEyPNUMCbU8c_SAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack