๐ฆ๐บ
paulshipley.com.au
2026-10-09 18:40:36
(1 hour ago)
[Sat Oct 10 05:40:36.131482 2026] [security2:error] [pid 689444] [client 35.215.243.27:52494] [clien ...
show more
[Sat Oct 10 05:40:36.131482 2026] [security2:error] [pid 689444] [client 35.215.243.27:52494] [client 35.215.243.27] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "support.paulshipley.com.au"] [uri "/"] [unique_id "ask1JO2kbp5KDuRi0hpoPAAAAAU"]
...
show less
Web App Attack
๐บ๐ธ
factor1
2026-10-09 18:03:08
(1 hour ago)
CrowdSec at apollo Reports Abuse
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 16:38:48
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.215.243.27 (27.243.215.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.215.243.27 (27.243.215.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 12:38:41.776027 2026] [security2:error] [pid 18829:tid 18829] [client 35.215.243.27:35014] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thebestproduct.guru"] [uri "/.git/config"] [unique_id "askYkcizD-_uLURWD-1tPwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-10-09 15:55:34
(4 hours ago)
Excessive multi-domain requests
Brute-Force
๐ฉ๐ช
expandmade.com
2026-10-09 14:38:54
(5 hours ago)
WAF triggered [09/Oct/2026:14:38:54 "GET /.env"]
Web App Attack
๐ฉ๐ช
thesimonmanuel
2026-10-09 13:21:37
(6 hours ago)
35.215.243.27 - - [09/Oct/2026:18:51:36 +0530] "GET /.git/config HTTP/1.1" 404 13392 "-" "Mozilla/5. ...
show more
35.215.243.27 - - [09/Oct/2026:18:51:36 +0530] "GET /.git/config HTTP/1.1" 404 13392 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
show less
Web App Attack
๐ฌ๐ง
consul.to
2026-10-09 11:50:50
(8 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-09 10:31:56
(9 hours ago)
[ti-04al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-04al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 35.215.243.27 - - [09/Oct/2026:12:31:48 +0200] "GET /.git/config HTTP/1.1" 301 532 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-10-09 09:45:22
(10 hours ago)
csagent: score 19.9: secrets grab x2; 1 domain(s) in 2s
Web App Attack
Anonymous
2026-10-09 06:05:14
(13 hours ago)
35.215.243.27 - - [09/Oct/2026:08:04:49 +0200] "GET /.git/config HTTP/1.1" 403 614 "-" "Mozilla/5.0 ...
show more
35.215.243.27 - - [09/Oct/2026:08:04:49 +0200] "GET /.git/config HTTP/1.1" 403 614 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.215.243.27 - - [09/Oct/2026:08:04:50 +0200] "GET /.env HTTP/1.1" 403 614 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.215.243.27 - - [09/Oct/2026:08:04:50 +0200] "GET /.env.local HTTP/1.1" 403 614 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.215.243.27 - - [09/Oct/2026:08:04:50 +0200] "GET /.env.production HTTP/1.1" 403 614 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.215.243.27 - - [09/Oct/2026:08:04:50 +0200] "GET /.env.staging HTTP/1.1" 403 614 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.215.243.27 - - [09/Oct/2026:08:04:51 +0200] "
...
show less
DDoS Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 06:01:14
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.215.243.27 (27.243.215.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.215.243.27 (27.243.215.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 02:01:07.599489 2026] [security2:error] [pid 22875:tid 22875] [client 35.215.243.27:57592] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "theateroobleck.com"] [uri "/.git/config"] [unique_id "asiDI3-_phWDRE_iHyVOCQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-09 05:51:13
(14 hours ago)
Bot / seems abusive / Apache connections: 22
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 03:03:04
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.215.243.27 (27.243.215.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.215.243.27 (27.243.215.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 23:02:57.238969 2026] [security2:error] [pid 22038:tid 22038] [client 35.215.243.27:42744] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "theartbrush.com"] [uri "/.git/config"] [unique_id "ashZYYdxshTPP-3aGIOeugAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 00:59:45
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.215.243.27 (27.243.215.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.215.243.27 (27.243.215.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 20:59:39.835258 2026] [security2:error] [pid 26293:tid 26293] [client 35.215.243.27:55298] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "theantidote.agency.gregorii.com"] [uri "/.git/config"] [unique_id "asg8e3M-7d9SbHChxzhhWAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
โจ
2026-10-08 23:58:05
(20 hours ago)
Domain : theamulet.org.uk
Rule : config
2026-10-08 23:56:04 79.171.39.6 GET /.git/config - 443 - 35. ...
show more
Domain : theamulet.org.uk
Rule : config
2026-10-08 23:56:04 79.171.39.6 GET /.git/config - 443 - 35.215.243.27 HTTP/1.1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 - theamulet.org.uk 404 8 0 1375 300 200 - -
show less
Hacking
SQL Injection