๐ฉ๐ช
Bedios GmbH
2026-08-27 04:43:03
(1 hour ago)
Login credentials theft attempt
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-27 04:37:49
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.200.229.169 (169.229.200.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.200.229.169 (169.229.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 00:37:45.124442 2026] [security2:error] [pid 21285:tid 21285] [client 35.200.229.169:57676] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.calendar.freedomfactoryteam.com"] [uri "/.env.old"] [unique_id "ao-_GafOn8VGuMCg7sXJbQAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐บ
DZBOT
2026-08-27 04:35:50
(1 hour ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐ซ๐ท
dynamix
2026-08-27 03:16:28
(2 hours ago)
Multiple WAF Violations
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-08-27 02:43:55
(3 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐ฆ๐บ
AWW-Admin
2026-08-27 02:09:24
(3 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 35.200.229.169 (IN/India/169.229.200.35 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.200.229.169 (IN/India/169.229.200.35.bc.googleusercontent.com)
show less
SQL Injection
Anonymous
2026-08-27 02:03:22
(3 hours ago)
Auto-reported by Fail2Ban (NPM-Auth)
Web App Attack
๐ฉ๐ช
SCHAPPY
2026-08-27 01:37:10
(4 hours ago)
Brute-force attack to non-existent web resources, HTTP code 404.
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 01:26:47
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.200.229.169 (169.229.200.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.200.229.169 (169.229.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 21:26:44.734299 2026] [security2:error] [pid 12458:tid 12458] [client 35.200.229.169:42650] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.jamessummers.org"] [uri "/.env.production"] [unique_id "ao-SVK9f8PilwjmTUbsR1AAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-08-27 00:53:45
(4 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 00:50:53
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.200.229.169 (169.229.200.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.200.229.169 (169.229.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 20:50:47.379583 2026] [security2:error] [pid 4699:tid 4699] [client 35.200.229.169:57624] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.cwidisplays.com.ltscatering.com"] [uri "/wp-config.php.bak"] [unique_id "ao-J52naRXKx7LbiCFXmaAAAADc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-08-27 00:20:02
(5 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐ซ๐ท
masterguru
2026-08-27 00:01:47
(5 hours ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 35.200.229.169 (IN/India/169.229.200. ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 35.200.229.169 (IN/India/169.229.200.35.bc.googleusercontent.com): 2 in the last 3600 secs (0-196)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-26 23:31:11
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.200.229.169 (169.229.200.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.200.229.169 (169.229.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 19:31:06.222781 2026] [security2:error] [pid 8991:tid 8991] [client 35.200.229.169:51152] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "travelswithfriends.com"] [uri "/.env"] [unique_id "ao93OouXWcC666IdA9hUCgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-08-26 23:30:50
(6 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking