🇺🇸
TPI-Abuse
2026-09-15 15:26:45
(7 minutes ago)
(mod_security) mod_security (id:210730) triggered by 35.196.107.124 (124.107.196.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.196.107.124 (124.107.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 11:26:38.104767 2026] [security2:error] [pid 17238:tid 17238] [client 35.196.107.124:59840] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||smallbizreorg.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "smallbizreorg.com"] [uri "/z9x8c7v6b5-debug-trigger-smallbizreorg.com"] [unique_id "aqljrgQz9tpk6NT9QhecvwAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇯🇵
bokumin.org
2026-09-15 15:14:07
(19 minutes ago)
[id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [uri "/"] [id "949110"] [msg " ...
show more
[id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [uri "/"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"]
show less
Web App Attack
🇺🇸
mnsf
2026-09-15 15:06:00
(28 minutes ago)
Scanning/Probing (17)
Brute-Force
Web App Attack
🇩🇪
konseptit
2026-09-15 15:01:08
(32 minutes ago)
(mod_security) mod_security triggered on hostname [redacted] 35.196.107.124 (US/United States/124.10 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.196.107.124 (US/United States/124.107.196.35.bc.googleusercontent.com)
show less
SQL Injection
🇺🇸
TPI-Abuse
2026-09-15 14:59:32
(34 minutes ago)
(mod_security) mod_security (id:210730) triggered by 35.196.107.124 (124.107.196.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.196.107.124 (124.107.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 10:59:26.995582 2026] [security2:error] [pid 500:tid 500] [client 35.196.107.124:38564] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||slusarczyk.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "slusarczyk.com"] [uri "/z9x8c7v6b5-debug-trigger-slusarczyk.com"] [unique_id "aqldTnWq70gXSlQ6nP-0lAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-15 14:34:25
(59 minutes ago)
(mod_security) mod_security (id:210492) triggered by 35.196.107.124 (124.107.196.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.196.107.124 (124.107.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 10:34:21.032776 2026] [security2:error] [pid 21367:tid 21367] [client 35.196.107.124:60850] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "slovenia-boat-registration.com"] [uri "/%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env"] [unique_id "aqlXbd-qVvPW7p_VtcmLJgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
BlueWire Hosting
2026-09-15 13:17:46
(2 hours ago)
High-confidence malicious configuration/VCS probe
Web App Attack
🇩🇪
conseilgouz
2026-09-15 13:09:22
(2 hours ago)
sle-17 : Block hidden directories=>/.astro/manifest.json(/)
Hacking
🇺🇸
Sling
2026-09-15 13:03:24
(2 hours ago)
Automated detection: IP accessed 8 sensitive endpoints within 30s on slingexe.com. Paths: /.env.exam ...
show more
Automated detection: IP accessed 8 sensitive endpoints within 30s on slingexe.com. Paths: /.env.example, /.env.local, /.env.production, /.npmrc, /docker-compose.yml, /pages/index.astro.mjs.map, /storage/logs/laravel.log, /config.json. UA: Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/).
show less
Web App Attack
Bad Web Bot
Hacking
🇳🇱
Mangelot Hosting
2026-09-15 13:02:52
(2 hours ago)
(wp_config_access) srv101 WordPress wp-config Scan 35.196.107.124 (US/United States/124.107.196.35.b ...
show more
(wp_config_access) srv101 WordPress wp-config Scan 35.196.107.124 (US/United States/124.107.196.35.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-15 13:01:01
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.196.107.124 (124.107.196.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.196.107.124 (124.107.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 09:00:53.454022 2026] [security2:error] [pid 12510:tid 12510] [client 35.196.107.124:52372] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||slimlaw.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "slimlaw.com"] [uri "/rclone.conf"] [unique_id "aqlBhVfuCTPTWXdbpz6XHAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FD-IX
2026-09-15 12:47:54
(2 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇧🇪
voormedia
2026-09-15 12:28:19
(3 hours ago)
Accessed trap at '/.git/HEAD'
Web App Attack
🇩🇪
MarkGGN
2026-09-15 12:18:29
(3 hours ago)
Web attack. 35.196.107.124 - - [15/Sep/2026:14:18:28 +0200] "GET /@fs/..%252f..%252f..%252f..%252f.. ...
show more
Web attack. 35.196.107.124 - - [15/Sep/2026:14:18:28 +0200] "GET /@fs/..%252f..%252f..%252f..%252f..%252froot/.env?raw?? HTTP/2.0" 444 0 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)"
35.196.107.124 - - [15/Sep/2026:14:18:28 +0200] "GET /@fs/app/.env?raw?? HTTP/2.0" 444 0 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)"
show less
Web App Attack
🇳🇱
Site.eu
2026-09-15 11:58:29
(3 hours ago)
Excessive multi-domain requests
Brute-Force