Anonymous
2026-09-16 18:18:46
(9 minutes ago)
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: AU, Attack patterns: Word ...
show more
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: AU, Attack patterns: WordPress scanning, Backup file probing, Cloud secrets probing
show less
Bad Web Bot
Web App Attack
๐ฎ๐น
CoreTech srl
2026-09-16 18:13:56
(13 minutes ago)
cloudlinux2 fail2ban: 2026-09-16 20:08:52,026 fail2ban.filter [1818]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-16 20:08:52,026 fail2ban.filter [1818]: INFO [plesk-modsecurity] Found 35.197.177.165 - 2026-09-16 20:08:52cloudlinux2 fail2ban: 2026-09-16 20:08:54,617 fail2ban.actions [1818]: NOTICE [plesk-modsecurity] Ban 35.197.177.165cloudlinux2 fail2ban: 2026-09-16 20:08:54,536 fail2ban.filter [1818]: INFO [plesk-modsecurity] Found 35.197.177.165 - 2026-09-16 20:08:54cloudlinux2 fail2ban: 2026-09-16 20:08:54,747 fail2ban.filter [1818]: INFO [recidive] Found 35.197.177.165 - 2026-09-16 20:08:54cloudlinux2 fail2ban: 2026-09-16 20:08:54,224 fail2ban.filter [1818]: INFO [plesk-modsecurity] Found 35.197.177.165 - 2026-09-16 20:08:54cloudlinux2 fail2ban: 2026-09-16 20:09:19,266 fail2ban.actions [1818]: NOTICE [plesk-modsecurity] Unban 104.28.222.46cloudlinux2 fail2ban: 2026-09-16 20:09:29,377 fail2ban.filter [1818]: INFO [plesk-modsecurity] Found 34.32.165.186 - 2026-09-16 20:09:29cloudlinux2 fail2ban: 2026-09-16 20:10:39,376
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 18:04:52
(22 minutes ago)
(mod_security) mod_security (id:210492) triggered by 35.197.177.165 (165.177.197.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.197.177.165 (165.177.197.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 14:04:46.409282 2026] [security2:error] [pid 8018:tid 8018] [client 35.197.177.165:38146] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.cityofhaleyville.com"] [uri "/.git/config"] [unique_id "aqraPgz0CcDv5Hh9loeguQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 17:43:47
(44 minutes ago)
(mod_security) mod_security (id:210492) triggered by 35.197.177.165 (165.177.197.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.197.177.165 (165.177.197.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 13:43:40.475276 2026] [security2:error] [pid 24570:tid 24595] [client 35.197.177.165:44150] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.cityfilms-lb.com.oplconnect.com"] [uri "/.git/config"] [unique_id "aqrVTEnnR5EP9u_4_ZzIowAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 15:51:37
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.197.177.165 (165.177.197.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.197.177.165 (165.177.197.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 11:51:33.507742 2026] [security2:error] [pid 17309:tid 17309] [client 35.197.177.165:35066] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.correo.gisur.com"] [uri "/.git/config"] [unique_id "aqq7BXrJabd6BwoXBmrupQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-16 15:47:02
(2 hours ago)
Bot / scanning and/or hacking attempts: GET /.env.dev HTTP/1.1, GET /.env HTTP/1.1, GET /.env.ci HTT ...
show more
Bot / scanning and/or hacking attempts: GET /.env.dev HTTP/1.1, GET /.env HTTP/1.1, GET /.env.ci HTTP/1.1, GET /.env.live HTTP/1.1, GET /.env.swp HTTP/1.1, GET /.env~ HTTP/1.1, GET /.env.stage HTTP/1.1, GET /.env1 HTTP/1.1, GET /.env.docker HTTP/1.1, GET /.env.preprod HTTP/1.1, GET /.env.dist HTTP/1.1, GET /.env.prod HTTP/1.1, GET /.env.uat HTTP/1.1
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 15:27:10
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.197.177.165 (165.177.197.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.197.177.165 (165.177.197.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 11:27:05.490293 2026] [security2:error] [pid 10595:tid 10595] [client 35.197.177.165:51294] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.circleway.org.morefrogs.com"] [uri "/.git/config"] [unique_id "aqq1SWnyeiMPbHecfGG3FgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-16 15:15:53
(3 hours ago)
[ti-04al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-04al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 35.197.177.165 - - [16/Sep/2026:17:15:37 +0200] "GET /.git/config HTTP/1.1" 301 433 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-16 14:43:20
(3 hours ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 14:31:28
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.197.177.165 (165.177.197.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.197.177.165 (165.177.197.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 10:31:22.805383 2026] [security2:error] [pid 28843:tid 28843] [client 35.197.177.165:55730] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.cinesonline.com.visionremota.info"] [uri "/.git/config"] [unique_id "aqqoOuZGjIcL7dYqqCQ96wAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-16 14:06:05
(4 hours ago)
Trying to access config files
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 13:47:07
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.197.177.165 (165.177.197.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.197.177.165 (165.177.197.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 09:47:01.451243 2026] [security2:error] [pid 8507:tid 8507] [client 35.197.177.165:42870] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.corporatepedals.vanemby.com"] [uri "/.git/config"] [unique_id "aqqd1YnhvsddpppYCfjyBwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 12:45:30
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.197.177.165 (165.177.197.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.197.177.165 (165.177.197.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 08:45:25.118126 2026] [security2:error] [pid 19420:tid 19420] [client 35.197.177.165:51418] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.cienmalos.hodlmoser.com"] [uri "/.git/config"] [unique_id "aqqPZQBpcPrfRYlhMOJosQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2026-09-16 09:53:21
(8 hours ago)
(modsecurity) srv201 ModSecurity 35.197.177.165 (AU/Australia/165.177.197.35.bc.googleusercontent.co ...
show more
(modsecurity) srv201 ModSecurity 35.197.177.165 (AU/Australia/165.177.197.35.bc.googleusercontent.com): 30 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐ฉ๐ช
LRob
2026-09-16 08:15:24
(10 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.git/config (+2 more) | 2026-09-16 08:15 UTC
show less
Hacking
Web App Attack