🇧🇪
cmbplf
2026-09-12 23:11:47
(38 minutes ago)
13.719 requests from abuseipdb.com blacklisted IP (6mos2w4d)
Brute-Force
Bad Web Bot
🇺🇸
moppetto
2026-09-12 22:54:19
(56 minutes ago)
Node.js .env file credential scraping; GET /@fs/app/.env
Bad Web Bot
Hacking
🇺🇸
TPI-Abuse
2026-09-12 22:50:39
(59 minutes ago)
(mod_security) mod_security (id:210492) triggered by 35.201.180.18 (18.180.201.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.201.180.18 (18.180.201.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 18:50:34.644378 2026] [security2:error] [pid 17708:tid 17708] [client 35.201.180.18:60220] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "setx-law.com"] [uri "/%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env"] [unique_id "aqXXOrb-AKN-KW3_5EZeXAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇷
setupgr
2026-09-12 22:50:37
(59 minutes ago)
(mod_security) mod_security (id:11000011) triggered by 35.201.180.18 (TW/Taiwan/Taipei City/Taipei/- ...
show more
(mod_security) mod_security (id:11000011) triggered by 35.201.180.18 (TW/Taiwan/Taipei City/Taipei/-/[AS396982 Google LLC]): 1 in the last 86400 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Sun Sep 13 01:50:33.159527 2026] [security2:error] [pid 39194:tid 39214] [remote 35.201.180.18:41948] ModSecurity: Access denied with code 406 (phase 1). Matched phrase "googleusercontent.com" at REMOTE_HOST. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "141"] [id "11000011"] [msg "BLOCKED BAD DOMAIN: 18.180.201.35.bc.googleusercontent.com"] [severity "CRITICAL"] [hostname "setworldup365.com"] [uri "/"] [unique_id "aqXXOR-Py5xm_KjSCH9KxQAAVRM"]
show less
Port Scan
🇫🇷
Baking333
2026-09-12 22:38:06
(1 hour ago)
[redacted] 35.201.180.18 - - [12/Sep/2026:23:38:02 +0100] "GET /api/uploads/%2e%2e%2f%2e%2e%[redacte ...
show more
[redacted] 35.201.180.18 - - [12/Sep/2026:23:38:02 +0100] "GET /api/uploads/%2e%2e%2f%2e%2e%[redacted] HTTP/1.1" 404 516 0/157 "-" "Mozilla/5.0 (compatible; Google-Extended; +http://[redacted]/[redacted])" [redacted] 35.201.180.18 - - [12/Sep/2026:23:38:04 +0100] "GET /.dockerenv HTTP/1.1" 302 1554 0/218867 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; OAI-SearchBot/1.0; +https://[redacted]/searchbot)"
show less
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-12 22:29:08
(1 hour ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.git/config | 2026-09-12 22:29 UTC
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 22:24:17
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.201.180.18 (18.180.201.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.201.180.18 (18.180.201.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 18:24:11.393582 2026] [security2:error] [pid 16461:tid 16461] [client 35.201.180.18:54814] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "seshetmusic.com"] [uri "/.env.backup"] [unique_id "aqXRC-gFTFb1Kco4rLUozQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
thieuleu
2026-09-12 22:00:18
(1 hour ago)
Unauthorized connection attempt blocked by firewall policy. Web application hardening active.
Brute-Force
Exploited Host
🇺🇸
TPI-Abuse
2026-09-12 21:59:35
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.201.180.18 (18.180.201.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.201.180.18 (18.180.201.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 17:59:30.965520 2026] [security2:error] [pid 31589:tid 31589] [client 35.201.180.18:41786] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "serviciodepinturadecasas.com"] [uri "/%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env"] [unique_id "aqXLQo5RMqESgEaYZ0SZuQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
homeshowdomain.nl
2026-09-12 21:59:24
(1 hour ago)
Auto-ban: >3000 req/min op 2026-09-12
Web App Attack
SSH
Hacking
🇫🇷
dwmp
2026-09-12 21:43:15
(2 hours ago)
Url probing: /__vite_rsc_findSourceMapURL
Web App Attack
🇬🇧
consul.to
2026-09-12 21:39:39
(2 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇧🇪
madeit
2026-09-12 21:38:53
(2 hours ago)
Web App Attack
🇩🇪
Ha1fdan
2026-09-12 21:36:05
(2 hours ago)
[2026-09-12T21:36:00Z] 35.201.180.18 '<URI>'
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 21:22:48
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.201.180.18 (18.180.201.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.201.180.18 (18.180.201.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 17:22:41.662274 2026] [security2:error] [pid 24264:tid 24264] [client 35.201.180.18:33906] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||serranoscoffee.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "serranoscoffee.com"] [uri "/z9x8c7v6b5-debug-trigger-serranoscoffee.com"] [unique_id "aqXCoYfRPT-VxXbfIeCrHQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack