🇺🇸
TPI-Abuse
2026-09-06 02:10:21
(19 minutes ago)
(mod_security) mod_security (id:210492) triggered by 35.198.22.146 (146.22.198.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.198.22.146 (146.22.198.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:10:13.264806 2026] [security2:error] [pid 23102:tid 23102] [client 35.198.22.146:33532] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "shopauto.cbmanufacturing.com"] [uri "/wp-config.php.swp"] [unique_id "apzLhe-wFIT6SyCrGM8iAQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-06 02:00:42
(29 minutes ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 01:47:01
(42 minutes ago)
(mod_security) mod_security (id:210492) triggered by 35.198.22.146 (146.22.198.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.198.22.146 (146.22.198.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:46:53.501438 2026] [security2:error] [pid 19086:tid 19086] [client 35.198.22.146:44362] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "froemel.biz"] [uri "/.env.example"] [unique_id "apzGDcmZEskFZh2ykklcsQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-09-06 01:05:48
(1 hour ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
🇫🇷
dynamix
2026-09-06 01:01:46
(1 hour ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 00:57:47
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.198.22.146 (146.22.198.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.198.22.146 (146.22.198.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:57:42.941344 2026] [security2:error] [pid 14524:tid 14524] [client 35.198.22.146:48420] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ticmatopografiaeingenieria.com"] [uri "/.env.example"] [unique_id "apy6hn2Ynt-H-nuQCYD7yAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 00:36:42
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.198.22.146 (146.22.198.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.198.22.146 (146.22.198.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:36:34.513879 2026] [security2:error] [pid 3508626:tid 3508626] [client 35.198.22.146:47390] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "histbase.com"] [uri "/.env.production"] [unique_id "apy1kqfIgoOF7z8cebaU2gAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
andypiper
2026-09-06 00:32:43
(1 hour ago)
CrowdSec ban for crowdsecurity/netgear-router-bruteforce
Brute-Force
Web App Attack
🇬🇧
andypiper
2026-09-06 00:17:33
(2 hours ago)
CrowdSec ban for homelab/caddy-cross-host-sensitive-probing
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 23:48:28
(2 hours ago)
(mod_security) mod_security (id:949110) triggered by 35.198.22.146 (146.22.198.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:949110) triggered by 35.198.22.146 (146.22.198.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:48:23.280700 2026] [security2:error] [pid 16108:tid 16108] [client 35.198.22.146:54020] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "hamiltonbookings.com"] [uri "/.env.old"] [unique_id "apyqR8iOkJZGHA2_K8rFlwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
iNetWorker
2026-09-05 23:38:31
(2 hours ago)
trolling for resource vulnerabilities
Web App Attack
Anonymous
2026-09-05 22:15:53
(4 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇳🇱
homeshowdomain.nl
2026-09-05 22:01:06
(4 hours ago)
Auto-ban: >3000 req/min op 2026-09-05
Web App Attack
SSH
Hacking
Anonymous
2026-09-05 21:36:33
(4 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
🇩🇪
FeG Deutschland
2026-09-05 21:17:04
(5 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack