๐ซ๐ท
Octopuce
2026-10-01 00:19:18
(29 minutes ago)
Aggressive web search of vulnerable pages: /openapi.json /api/openapi.json /swagger.json /static../. ...
show more
Aggressive web search of vulnerable pages: /openapi.json /api/openapi.json /swagger.json /static../.env /media../.env ...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 00:11:28
(37 minutes ago)
(mod_security) mod_security (id:210492) triggered by 35.203.23.56 (56.23.203.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.203.23.56 (56.23.203.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 20:11:24.038068 2026] [security2:error] [pid 26595:tid 26675] [client 35.203.23.56:54508] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.g3-contracting.com"] [uri "/files../.env"] [unique_id "ar2lLCI-wqx3-qcST_NQQwAAAQQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
IVski.com
2026-09-30 23:19:19
(1 hour ago)
IVski WAF | Next.js Server Action probe
Hacking
Brute-Force
Web App Attack
๐ง๐ช
cmbplf
2026-09-30 22:39:14
(2 hours ago)
430 requests with url.path *.env
Brute-Force
Bad Web Bot
Anonymous
2026-09-30 22:13:33
(2 hours ago)
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: CA, Attack patterns: Back ...
show more
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: CA, Attack patterns: Backup file probing, Cloud secrets probing, Directory traversal
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-30 21:45:20
(3 hours ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-30 16:13:41
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.203.23.56 (56.23.203.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.203.23.56 (56.23.203.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 12:13:37.339551 2026] [security2:error] [pid 28587:tid 28587] [client 35.203.23.56:34260] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "garrelsms.com"] [uri "/.htpasswd"] [unique_id "ar01MaTflwM5QgG09Khl_gAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-30 15:33:04
(9 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 15:04:27
(9 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.203.23.56 (56.23.203.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.203.23.56 (56.23.203.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 11:04:22.629307 2026] [security2:error] [pid 10192:tid 10192] [client 35.203.23.56:58664] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||support.robtown.com|F|2"] [data ".robtown.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "support.robtown.com"] [uri "/z9x8c7v6b5-debug-trigger-support.robtown.com"] [unique_id "ar0k9uTpmTcw0C_6coVXrAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-30 14:59:30
(9 hours ago)
Aggressive web scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 13:47:14
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.203.23.56 (56.23.203.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.203.23.56 (56.23.203.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 09:47:05.740615 2026] [security2:error] [pid 2084:tid 2084] [client 35.203.23.56:36928] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.gdg1.com"] [uri "/assets../.env"] [unique_id "ar0S2YfOBj2Ri58zGy0k8QAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-30 13:35:56
(11 hours ago)
Web application attack detected.
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-30 13:15:00
(11 hours ago)
[ti-07al] Web exploit scanning: 2 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-07al] Web exploit scanning: 2 suspicious requests detected by fail2ban jail apache-scanner. Example: 35.203.23.56 - - [30/Sep/2026:15:14:57 +0200] "GET /public../.env HTTP/1.1" 404 2050 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
IndigoRidge
2026-09-30 12:45:18
(12 hours ago)
35.203.23.56 - - [30/Sep/2026:08:45:17 -0400] "GET /media../.env HTTP/1.1" 404 5521 "-" "Mozilla/5.0 ...
show more
35.203.23.56 - - [30/Sep/2026:08:45:17 -0400] "GET /media../.env HTTP/1.1" 404 5521 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )"
35.203.23.56 - - [30/Sep/2026:08:45:17 -0400] "GET /static../.env HTTP/1.1" 404 5521 "-" "Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)"
35.203.23.56 - - [30/Sep/2026:08:45:17 -0400] "GET /api/.env/public/.env HTTP/1.1" 404 5521 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 12:33:15
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.203.23.56 (56.23.203.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.203.23.56 (56.23.203.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 08:33:12.122103 2026] [security2:error] [pid 17795:tid 17795] [client 35.203.23.56:40808] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.garnetcreek.com"] [uri "/.env.js"] [unique_id "ar0BiAFHF_KCvu8UjEHGJwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack