๐บ๐ธ
TPI-Abuse
2026-09-01 00:53:25
(3 minutes ago)
(mod_security) mod_security (id:210492) triggered by 35.200.72.138 (138.72.200.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.200.72.138 (138.72.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 20:53:20.958853 2026] [security2:error] [pid 11806:tid 11806] [client 35.200.72.138:51840] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "daydar.net"] [uri "/.env.backup"] [unique_id "apYiACr-VbKMkP2XngoDAQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-01 00:33:36
(23 minutes ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 00:29:33
(27 minutes ago)
(mod_security) mod_security (id:210492) triggered by 35.200.72.138 (138.72.200.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.200.72.138 (138.72.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 20:29:28.237872 2026] [security2:error] [pid 11761:tid 11761] [client 35.200.72.138:37196] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.southernreader.com"] [uri "/.env.dev"] [unique_id "apYcaEnfWR8dLWRapczO6QAAAEs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 00:14:20
(42 minutes ago)
(mod_security) mod_security (id:210492) triggered by 35.200.72.138 (138.72.200.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.200.72.138 (138.72.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 20:14:12.089993 2026] [security2:error] [pid 26456:tid 26456] [client 35.200.72.138:39378] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.blisseventboutique.com"] [uri "/.env.old"] [unique_id "apYY1Gbw4tnuN0nmWr8oNwAAAE8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
XICTRON
2026-08-31 23:55:06
(1 hour ago)
ModSecurity rule violation detected by Fail2Ban
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 23:52:26
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.200.72.138 (138.72.200.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.200.72.138 (138.72.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 19:52:17.974989 2026] [security2:error] [pid 3752:tid 3752] [client 35.200.72.138:43136] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "comobarbershop.com"] [uri "/wp-config.php.swp"] [unique_id "apYTsYNmWJ9h4v7QBJgTpwAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 22:46:36
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.200.72.138 (138.72.200.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.200.72.138 (138.72.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 18:46:29.541448 2026] [security2:error] [pid 10970:tid 10970] [client 35.200.72.138:46582] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bladesoflegend.com"] [uri "/.env.local"] [unique_id "apYERfyQ81TzwuUPcxt2NgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
maxpower
2026-08-31 22:45:45
(2 hours ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 35.200.72.138 (JP/Japan/138.72.200.35.bc ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 35.200.72.138 (JP/Japan/138.72.200.35.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 35.200.72.138 - - [01/Sep/2026:00:45:41 +0200] "GET /wp-config.php.bak HTTP/1.1" 200 12014 "-" "crusader-worker/1.0" "-" host=birreriadelcorso.it
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-08-31 22:20:22
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.200.72.138 (138.72.200.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.200.72.138 (138.72.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 18:20:16.314936 2026] [security2:error] [pid 10837:tid 10837] [client 35.200.72.138:46730] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.goepf.com"] [uri "/.env.prod"] [unique_id "apX-IOsOB6CfJiNcMyLr1gAAACw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-08-31 22:20:06
(2 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ฉ๐ช
Petros Stefanakis
2026-08-31 22:12:11
(2 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 35.200.72.138 (JP/Japan/138.72.200.35.b ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.200.72.138 (JP/Japan/138.72.200.35.bc.googleusercontent.com)
show less
SQL Injection
๐ฉ๐ช
raph
2026-08-31 21:37:36
(3 hours ago)
[Wordpress] crawler /wp-admin/*, /wp-content/*, etc.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 21:34:07
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.200.72.138 (138.72.200.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.200.72.138 (138.72.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 17:34:01.000147 2026] [security2:error] [pid 18227:tid 18227] [client 35.200.72.138:53160] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "agapeoffice.agapeaccountingllc.com"] [uri "/.env.old"] [unique_id "apXzSGsIwB-fG8fbIGqKNwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack