๐บ๐ธ
TPI-Abuse
2026-08-28 19:03:24
(26 minutes ago)
(mod_security) mod_security (id:210492) triggered by 35.202.252.113 (113.252.202.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.202.252.113 (113.252.202.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 15:03:18.781873 2026] [security2:error] [pid 14748:tid 14748] [client 35.202.252.113:36570] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.suffecool.suffe.cool"] [uri "/.env"] [unique_id "apHbdti2_4ipbYjzXeC3qwAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 18:48:00
(41 minutes ago)
(mod_security) mod_security (id:210492) triggered by 35.202.252.113 (113.252.202.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.202.252.113 (113.252.202.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 14:47:54.342490 2026] [security2:error] [pid 30399:tid 30399] [client 35.202.252.113:47956] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "10bestsongs.com"] [uri "/wp-config.php.swp"] [unique_id "apHX2knnkfpJxB6U0LcRtwAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 18:11:45
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.202.252.113 (113.252.202.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.202.252.113 (113.252.202.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 14:11:40.628594 2026] [security2:error] [pid 18284:tid 18284] [client 35.202.252.113:45650] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "allworld.csennews.com"] [uri "/.env.dev"] [unique_id "apHPXHn0iUW4VvHSFRbPzQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
DEV-DNS
2026-08-28 18:03:36
(1 hour ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
๐ฎ๐น
CoreTech srl
2026-08-28 17:43:57
(1 hour ago)
cloudlinux2 fail2ban: 2026-08-28 19:39:37,538 fail2ban.actions [1478]: NOTICE [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-08-28 19:39:37,538 fail2ban.actions [1478]: NOTICE [plesk-modsecurity] Unban 34.48.202.98cloudlinux2 fail2ban: 2026-08-28 19:39:39,903 fail2ban.filter [1478]: INFO [plesk-wordpress] Found 103.159.37.173 - 2026-08-28 19:39:39cloudlinux2 fail2ban: 2026-08-28 19:39:50,162 fail2ban.actions [1478]: NOTICE [plesk-modsecurity] Unban 34.176.27.253cloudlinux2 fail2ban: 2026-08-28 19:39:53,376 fail2ban.actions [1478]: NOTICE [plesk-modsecurity] Unban 80.2.2.10cloudlinux2 fail2ban: 2026-08-28 19:41:10,303 fail2ban.filter [1478]: INFO [plesk-wordpress] Found 162.215.121.77 - 2026-08-28 19:41:10cloudlinux2 fail2ban: 2026-08-28 19:41:23,199 fail2ban.filter [1478]: INFO [plesk-modsecurity] Found 115.135.198.168 - 2026-08-28 19:41:22cloudlinux2 fail2ban: 2026-08-28 19:41:51,185 fail2ban.filter [1478]: INFO [plesk-modsecurity] Found 54.226.15.31 - 2026-08-28 19:41:51cloudlinux2 fail2ban: 2026-08-28 19:41:51,172 fail2ban.filter
show less
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-08-28 17:32:29
(1 hour ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 17:23:06
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.202.252.113 (113.252.202.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.202.252.113 (113.252.202.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 13:22:59.486190 2026] [security2:error] [pid 22778:tid 22778] [client 35.202.252.113:35434] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "oruguitas.org"] [uri "/.env.production"] [unique_id "apHD8y44VEs75wlFx6ZV9AAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
mediarama.com
2026-08-28 16:45:50
(2 hours ago)
Banned by Fail2Ban
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-08-28 16:27:42
(3 hours ago)
[28/Aug/2026:19:27:42 +0300] -- 35.202.252.113 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET ...
show more
[28/Aug/2026:19:27:42 +0300] -- 35.202.252.113 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /storage/logs/laravel.log HTTP/1.1
show less
Bad Web Bot
Web App Attack
Anonymous
2026-08-28 15:35:03
(3 hours ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 15:15:18
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.202.252.113 (113.252.202.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.202.252.113 (113.252.202.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 11:15:15.407140 2026] [security2:error] [pid 29481:tid 29481] [client 35.202.252.113:46740] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.xirin.net.owenmail.com"] [uri "/.env"] [unique_id "apGmA8TkoioUtyvR-XU2BgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-08-28 15:05:40
(4 hours ago)
Abuse Detected (9)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 14:48:07
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.202.252.113 (113.252.202.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.202.252.113 (113.252.202.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 10:48:02.856636 2026] [security2:error] [pid 19703:tid 19703] [client 35.202.252.113:56782] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.deepseasugar.com.lakesidedetectiveagency.com"] [uri "/.env"] [unique_id "apGfovWviPlGHCcrwJgz6QAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Feelautom
2026-08-28 14:40:04
(4 hours ago)
[FeelAutom Auto-Ban] PathScan: /.env.save (Score: 202)
Port Scan
๐ฉ๐ช
s@ch@
2026-08-28 14:15:02
(5 hours ago)
Jail: plesk-modsecurity | Web application attack (Plesk ModSecurity)
Web App Attack