๐บ๐ธ
[email protected]
2026-09-01 10:10:54
(32 minutes ago)
Fail2Ban jail apache-json-scanners detected activity on 2026-09-01T10:10:54Z
Brute-Force
๐ซ๐ท
masterguru
2026-09-01 09:56:26
(46 minutes ago)
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .backup/ ...
show more
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .compositefont/ .config/ .conf/ .crt/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dist/ .dll/ .dos/ .dpkg-dist/ .drv/ .gadget/ .hta/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .inf/ .ini/ .jse/ .key/ .licx/ .lnk/ .log/ .mdb/ .msc/ .ocx/ .old/ .pass/ .pdb/ .pfx/ .pif/ .pem/ .pol/ .prf/ .printer/ .pwd/ .rdb/ .rdp/ .reg/ .resources/ .resx/ .scr/ .sct/ .shs/ .sql/ .swp/ .sys/ .tlb/ .tmp/ .url/ .vb/ .vbe/ .vbs/ .vbproj/ .vsdisco/ .vxd/ .webinfo/ .ws/ .wsc/ .wsf/ .wsh/ .xsd/ .xsx/" at TX:extension. (920440-195)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-01 09:49:20
(53 minutes ago)
(mod_security) mod_security (id:210492) triggered by 35.196.147.164 (164.147.196.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.196.147.164 (164.147.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 05:49:14.818179 2026] [security2:error] [pid 30388:tid 30388] [client 35.196.147.164:46212] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "solar.catking.net"] [uri "/.env.example"] [unique_id "apafmhs1Trgcov007t-ZUQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
[email protected]
2026-09-01 09:29:20
(1 hour ago)
Fail2Ban jail apache-json-scanners detected activity on 2026-09-01T09:29:20Z
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-01 09:15:43
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.196.147.164 (164.147.196.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.196.147.164 (164.147.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 05:15:37.185343 2026] [security2:error] [pid 25825:tid 25825] [client 35.196.147.164:43132] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sys.integratic.com.co"] [uri "/.env.bak"] [unique_id "apaXuV9YFRBh364vM6iuMwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 08:23:13
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.196.147.164 (164.147.196.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.196.147.164 (164.147.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 04:23:07.318204 2026] [security2:error] [pid 3619:tid 3619] [client 35.196.147.164:41100] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mediaservices.bccworldmedia.com"] [uri "/.env"] [unique_id "apaLa5kcEpSVgOtfZNaTtQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
mondor.ro
2026-09-01 07:46:22
(2 hours ago)
Cluster member 148.251.176.225 (DE/Germany/antares.webyouridea.ro) said, DENY 35.196.147.164, Reason ...
show more
Cluster member 148.251.176.225 (DE/Germany/antares.webyouridea.ro) said, DENY 35.196.147.164, Reason:[(mod_security) mod_security (id:210492) triggered by 35.196.147.164 (US/United States/164.147.196.35.bc.googleusercontent.com): 3 in the last 3600 secs]; Ports: *; Direction: inout; Trigger: LF_CLUSTER; Logs:
show less
Port Scan
Anonymous
2026-09-01 07:46:03
(2 hours ago)
Bot / scanning and/or hacking attempts: GET /wp-config.php~ HTTP/1.1
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 07:25:59
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.196.147.164 (164.147.196.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.196.147.164 (164.147.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 03:25:53.025727 2026] [security2:error] [pid 28931:tid 28931] [client 35.196.147.164:57344] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "zmgmt.net"] [uri "/.env.local"] [unique_id "apZ-ATXnhe7VZ8fYU4zQ7gAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
MBombeck
2026-09-01 06:52:39
(3 hours ago)
Fail2Ban/traefik-botsearch on apps-01: banned after 5 failures
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 06:04:04
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.196.147.164 (164.147.196.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.196.147.164 (164.147.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 02:03:59.370240 2026] [security2:error] [pid 226455:tid 226546] [client 35.196.147.164:41778] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.plumberw9.com"] [uri "/.env"] [unique_id "apZqz7AlSH7yQ6QV7T0XzQAAAMI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-09-01 05:07:44
(5 hours ago)
csagent: score 20.8: 404 noise floor x3, secrets grab x2; 1 domain(s) in 0s
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 05:06:54
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.196.147.164 (164.147.196.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.196.147.164 (164.147.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 01:06:45.739252 2026] [security2:error] [pid 588:tid 588] [client 35.196.147.164:40336] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.oldworldfineantiques.com"] [uri "/.env.local"] [unique_id "apZdZd0WDxSSxwcwxU6DzAAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-01 04:30:05
(6 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐ณ๐ฑ
MyGlobalFlowers
2026-09-01 04:11:40
(6 hours ago)
Multiple WAF Violations
Web App Attack