๐บ๐ธ
TPI-Abuse
2026-09-21 06:29:45
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.197.142.42 (42.142.197.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.197.142.42 (42.142.197.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 02:29:42.160728 2026] [security2:error] [pid 12680:tid 12680] [client 35.197.142.42:43642] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.mymuscles.com"] [uri "/api/v1/.env"] [unique_id "arDO1rHjqILQwN-P9zUsvQAAADE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 05:06:31
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.197.142.42 (42.142.197.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.197.142.42 (42.142.197.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 01:06:23.863792 2026] [security2:error] [pid 2479:tid 2580] [client 35.197.142.42:46534] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.omniuscorp.com"] [uri "/ai/.env"] [unique_id "arC7T68KEuwvjJLZpIAl2gAAAMs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฏ๐ต
syakesaba
2026-09-21 05:03:50
(1 day ago)
โ๏ธ This host failed 5 times connecting my WEB server. My contact: https://www.syakesaba.com/
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 03:58:54
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.197.142.42 (42.142.197.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.197.142.42 (42.142.197.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 23:58:49.998187 2026] [security2:error] [pid 7668:tid 7668] [client 35.197.142.42:46272] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.iyp-home.com"] [uri "/etc/.env"] [unique_id "arCreRyxoSsI2cgSxkUrTAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
CoreTech srl
2026-09-21 03:43:56
(1 day ago)
cloudlinux2 fail2ban: 2026-09-21 05:39:34,653 fail2ban.filter [1598]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-09-21 05:39:34,653 fail2ban.filter [1598]: INFO [plesk-wordpress] Found 70.52.178.40 - 2026-09-21 05:39:33cloudlinux2 fail2ban: 2026-09-21 05:39:53,286 fail2ban.filter [1598]: INFO [plesk-wordpress] Found 91.176.59.22 - 2026-09-21 05:39:51cloudlinux2 fail2ban: 2026-09-21 05:41:04,075 fail2ban.actions [1598]: NOTICE [plesk-modsecurity] Unban 34.174.18.5cloudlinux2 fail2ban: 2026-09-21 05:41:06,365 fail2ban.filter [1598]: INFO [plesk-wordpress] Found 142.111.152.159 - 2026-09-21 05:41:06cloudlinux2 fail2ban: 2026-09-21 05:42:51,409 fail2ban.actions [1598]: NOTICE [plesk-modsecurity] Unban 34.48.26.101cloudlinux2 fail2ban: 2026-09-21 05:43:34,681 fail2ban.filter [1598]: INFO [recidive] Found 35.197.142.42 - 2026-09-21 05:43:34cloudlinux2 fail2ban: 2026-09-21 05:43:34,190 fail2ban.filter [1598]: INFO [plesk-modsecurity] Found 35.197.142.42 - 2026-09-21 05:43:34cloudlinux2 fail2ban: 2026-09-21 05:43:34,216 fail2ban.fi
show less
Web App Attack
Anonymous
2026-09-21 03:16:23
(2 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-21 02:33:57
(2 days ago)
(mod_security) mod_security (id:243320) triggered by 35.197.142.42 (42.142.197.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:243320) triggered by 35.197.142.42 (42.142.197.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 22:33:53.861270 2026] [security2:error] [pid 31386:tid 31386] [client 35.197.142.42:42736] ModSecurity: Access denied with code 403 (phase 2). String match "/.profile" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6621"] [id "243320"] [rev "1"] [msg "COMODO WAF: Information disclosure vulnerability in Cloud Foundry PHP Buildpack (aka php-buildpack) before 4.3.18 and PHP Buildpack Cf-release before 242, as used in Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.6.38 and 1.7.x before 1.7.19 and other products (CVE-2016-6639)||orderthanksgivingcards.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "orderthanksgivingcards.com"] [uri "/.profile"] [unique_id "arCXkciMZfYFKZjS_iWcAgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
H24
2026-09-21 01:11:32
(2 days ago)
/.git/config /.git/HEAD /frontend/.env /var/.env /data/.env /services/.env /project/.env /private/.e ...
show more
/.git/config /.git/HEAD /frontend/.env /var/.env /data/.env /services/.env /project/.env /private/.env /tmp/.env /secrets.json
show less
Web App Attack
Anonymous
2026-09-21 00:37:38
(2 days ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐ฎ๐น
VHosting
2026-09-20 22:45:03
(2 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ช๐ธ
robotstxt
2026-09-20 22:22:26
(2 days ago)
35.197.142.42 - - [20/Sep/2026:22:22:01 +0000] "POST / HTTP/2.0" 403 22563 "-" "DuckAssistBot/1.1 (h ...
show more
35.197.142.42 - - [20/Sep/2026:22:22:01 +0000] "POST / HTTP/2.0" 403 22563 "-" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)" "-" edge="35.197.142.42"
35.197.142.42 - - [20/Sep/2026:22:22:01 +0000] "GET /z9x8c7v6b5-debug-trigger-oposiciones.monteroespinosaonline.com HTTP/2.0" 403 21209 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)" "-" edge="35.197.142.42"
35.197.142.42 - - [20/Sep/2026:22:22:01 +0000] "GET /.env.example HTTP/2.0" 403 21209 "-" "Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)" "-" edge="35.197.142.42"
35.197.142.42 - - [20/Sep/2026:22:22:01 +0000] "GET /.git/HEAD HTTP/2.0" 403 21209 "-" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)" "-" edge="35.197.142.42"
35.197.142.42 - - [20/Sep/2026:22:22:01 +0000] "GET /.gitlab-ci.yml HTTP/2.0" 403 21209 "-" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)" "-" edge="35.197.142.42"
...
show less
Web App Attack
๐ฉ๐ช
Bedios GmbH
2026-09-20 21:58:45
(2 days ago)
Wordpress hacking attempt
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 21:33:05
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.197.142.42 (42.142.197.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.197.142.42 (42.142.197.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 17:32:58.306026 2026] [security2:error] [pid 17696:tid 17696] [client 35.197.142.42:48928] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.orleansdartclub.com"] [uri "/env/.env"] [unique_id "arBRCiWW7Xbinv3daTm90QAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-20 20:54:11
(2 days ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
๐ซ๐ท
Allolatr
2026-09-20 19:40:27
(2 days ago)
Sep 20 21:40:27 [redacted] j443: ::ffff:35.197.142.42 openpgpkey.[redacted].com "GET /.aws/config HT ...
show more
Sep 20 21:40:27 [redacted] j443: ::ffff:35.197.142.42 openpgpkey.[redacted].com "GET /.aws/config HTTP/2.0" 400 154 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot" Sep 20 21:40:27 [redacted] j443: ::ffff:35.197.142.42 openpgpkey.[redacted].com "GET /.git-credentials HTTP/2.0" 400 154 "-" "Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)"
show less
Bad Web Bot
Web App Attack