๐ณ๐ฑ
Savvii
2026-08-29 01:45:25
(3 minutes ago)
20 attempts against mh_ha-misbehave-ban on ethyl
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 01:16:33
(32 minutes ago)
(mod_security) mod_security (id:210492) triggered by 35.198.198.45 (45.198.198.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.198.198.45 (45.198.198.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 21:16:26.878630 2026] [security2:error] [pid 15439:tid 15439] [client 35.198.198.45:47864] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.suralcopensioendesk.com"] [uri "/@fs/src/.env"] [unique_id "apIy6nuZ2no8WRg2Hhk_xwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-08-29 01:04:20
(44 minutes ago)
Excessive multi-domain requests
Brute-Force
Anonymous
2026-08-29 00:54:51
(53 minutes ago)
Aggressive web scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 00:36:14
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.198.198.45 (45.198.198.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.198.198.45 (45.198.198.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 20:36:07.052365 2026] [security2:error] [pid 576:tid 576] [client 35.198.198.45:24326] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.manb.org"] [uri "/@fs/.env.development"] [unique_id "apIpd-k8Zlf9-55qNEY2BQAAAJM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Octopuce
2026-08-29 00:23:33
(1 hour ago)
Aggressive web search of vulnerable pages: /.env.local /.env /core/.env /server/.env /web/.env ...
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 00:17:55
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.198.198.45 (45.198.198.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.198.198.45 (45.198.198.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 20:17:51.195727 2026] [security2:error] [pid 13361:tid 13361] [client 35.198.198.45:35652] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.brownweddinginvitations.net"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "apIlLwB2BuvA8DEHy4OV8wAAADE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-08-29 00:12:44
(1 hour ago)
Scanning/Probing (26)
Brute-Force
Web App Attack
๐ฎ๐น
VHosting
2026-08-29 00:00:12
(1 hour ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ซ๐ท
dynamix
2026-08-28 23:58:13
(1 hour ago)
Multiple WAF Violations
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-08-28 23:51:50
(1 hour ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐บ๐ธ
TAY
2026-08-28 23:49:13
(1 hour ago)
35.198.198.45 - - [29/Aug/2026:07:48:57 +0800] "GET /@fs/../.env?raw?? HTTP/1.1" 301 6217 "-" "Mozil ...
show more
35.198.198.45 - - [29/Aug/2026:07:48:57 +0800] "GET /@fs/../.env?raw?? HTTP/1.1" 301 6217 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:105.15) Gecko/20100101 Firefox/105.15; compatible; ChatGPT-User/1.0; +https://openai.com/bot"
35.198.198.45 - - [29/Aug/2026:07:48:57 +0800] "GET /@fs/../../.env?raw?? HTTP/1.1" 301 6224 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko; compatible; GrokBot/1.0; +https://x.ai/grokbot) Chrome/120.0.3636.115 Safari/537.36"
35.198.198.45 - - [29/Aug/2026:07:49:12 +0800] "GET /@fs/../../../../../root/.env?raw?? HTTP/1.1" 301 1006 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)"
35.198.198.45 - - [29/Aug/2026:07:49:12 +0800] "GET /@fs/var/www/html/wp-config.php?raw?? HTTP/1.1" 301 999 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexity-user)"
35.198.198.45 - - [29/Aug/2026:07:49:13 +0800] "GET /@fs/.
...
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-28 23:14:29
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.198.198.45 (45.198.198.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.198.198.45 (45.198.198.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 19:14:22.769328 2026] [security2:error] [pid 6988:tid 6988] [client 35.198.198.45:36592] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.whengarbotalks.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "apIWTnrfLRLh-qsau-iEwQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
updown.io
2026-08-28 23:11:53
(2 hours ago)
{"level":"info","ts":1787958663.4996283,"logger":"http.log.access.log0","msg":"handled request","req ...
show more
{"level":"info","ts":1787958663.4996283,"logger":"http.log.access.log0","msg":"handled request","request":{"remote_ip":"35.198.198.45","remote_port":"60368","client_ip":"35.198.198.45","proto":"HTTP/1.1","method":"GET","host":"ywdj.status.updown.io","uri":"/","headers":{"User-Agent":["Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"],"Accept":["*/*"],"Accept-Encoding":["gzip"]}},"bytes_read":0,"user_id":"","duration":0.000097887,"size":0,"status":308,"resp_headers":{"Location":["https://ywdj.status.updown.io/"],"Content-Type":[],"Server":["Caddy"],"Connection":["close"]}}
{"level":"info","ts":1787958672.5768516,"logger":"http.log.access.log0","msg":"handled request","request":{"remote_ip":"35.198.198.45","remote_port":"32546","client_ip":"35.198.198.45","proto":"HTTP/1.1","method":"GET","host":"ywdj.status.updown.io","uri":"/@fs/..%252f..%252f..%252f..%252f..%252froot/.env?raw??","headers":{"Accept-Encoding":["gzip"],"User
...
show less
DDoS Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 22:58:08
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.198.198.45 (45.198.198.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.198.198.45 (45.198.198.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 18:58:00.700434 2026] [security2:error] [pid 2261:tid 2261] [client 35.198.198.45:14922] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.worshipconcert.com"] [uri "/@fs/root/.env"] [unique_id "apISeCwV0XfbODfMrqTk_wAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack