๐บ๐ธ
TPI-Abuse
2026-10-08 08:33:14
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.219.250.1 (1.250.219.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.219.250.1 (1.250.219.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 04:33:11.410773 2026] [security2:error] [pid 27978:tid 27978] [client 35.219.250.1:48848] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "yerevanpress.am"] [uri "/.git/config"] [unique_id "asdVR6ObwMLi09b-0DWuqwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ardexter
2026-10-08 06:19:08
(3 hours ago)
Wordpress attack and DDOS
DDoS Attack
Web App Attack
๐ง๐ช
cmbplf
2026-10-08 04:25:55
(5 hours ago)
9.297 requests with url.path *.env
1.493 requests with url.path *phpinfo.php
262 requests with ur ...
show more
9.297 requests with url.path *.env
1.493 requests with url.path *phpinfo.php
262 requests with url.path *credentials.json
112 requests with url.path *.php.bak
show less
Brute-Force
Bad Web Bot
๐ณ๐ฑ
erwindecker
2026-10-08 04:06:50
(6 hours ago)
[08/Oct/2026:06:06:49 +0200] - 404 404 - GET https yellyfin.duckdns.org "/.git/config" [Client 35.21 ...
show more
[08/Oct/2026:06:06:49 +0200] - 404 404 - GET https yellyfin.duckdns.org "/.git/config" [Client 35.219.250.1] [Length 0] [Gzip -] [Sent-to 10.0.0.110] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-"
[08/Oct/2026:06:06:49 +0200] - 404 404 - GET https yellyfin.duckdns.org "/.env" [Client 35.219.250.1] [Length 0] [Gzip -] [Sent-to 10.0.0.110] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-"
[08/Oct/2026:06:06:49 +0200] - 404 404 - GET https yellyfin.duckdns.org "/.env.local" [Client 35.219.250.1] [Length 0] [Gzip -] [Sent-to 10.0.0.110] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-"
[08/Oct/2026:06:06:49 +0200] - 404 404 - GET https yellyfin.duckdns.org "/.env.production" [Client 35.219.250.1] [Length 0] [Gzip -] [Sent-to 10.0.0.110] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWe
...
show less
Port Scan
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 03:52:13
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.219.250.1 (1.250.219.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.219.250.1 (1.250.219.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 23:52:09.120490 2026] [security2:error] [pid 12705:tid 12729] [client 35.219.250.1:37330] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "yellowsunset.com.appraisalteam.net"] [uri "/.git/config"] [unique_id "ascTaa6gQf43GEi0orVAKAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-10-08 03:33:28
(6 hours ago)
Excessive multi-domain requests
Brute-Force
๐ณ๐ฑ
debestelapp
2026-10-08 03:25:09
(6 hours ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 02:14:07
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.219.250.1 (1.250.219.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.219.250.1 (1.250.219.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 22:14:02.213970 2026] [security2:error] [pid 24611:tid 24611] [client 35.219.250.1:40090] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "yellowbrickfoundation.com"] [uri "/.git/config"] [unique_id "asb8atswD3G_lXthQNxK8wAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
โจ
2026-10-08 02:00:15
(8 hours ago)
Domain : yellowanorak.com
Rule : env
2026-10-08 01:58:46 ***hidden-privacy*** GET /.env.local - 443 ...
show more
Domain : yellowanorak.com
Rule : env
2026-10-08 01:58:46 ***hidden-privacy*** GET /.env.local - 443 - 35.219.250.1 HTTP/1.1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 - yellowanorak.com 404 0 0 1667 299 30 - -
show less
Hacking
SQL Injection
๐จ๐ญ
4server
2026-10-08 01:35:24
(8 hours ago)
[ThuOct0803:35:18.1436972026][security2:error][pid101157:tid101176][client35.219.250.1:0]ModSecurity ...
show more
[ThuOct0803:35:18.1436972026][security2:error][pid101157:tid101176][client35.219.250.1:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".git\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"710\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"yellory.com.81-17-25-250.cpanel.site\"][uri\"/.git/config\"][unique_id\"asbzVo1lWcpY9-2dHiqvMgAAARE\"]
show less
Hacking
Web App Attack
๐ซ๐ท
โจ
2026-10-08 01:27:09
(8 hours ago)
Domain : yellingyin.com
Rule : hack
2026-10-08 01:25:49 ***hidden-privacy*** GET /.env.bak - 443 - 3 ...
show more
Domain : yellingyin.com
Rule : hack
2026-10-08 01:25:49 ***hidden-privacy*** GET /.env.bak - 443 - 35.219.250.1 HTTP/1.1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 - yellingyin.com 404 0 2 1560 295 29 - -
show less
Hacking
SQL Injection
Brute-Force
๐ซ๐ท
masterguru
2026-10-08 00:11:40
(10 hours ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 22:46:59
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.219.250.1 (1.250.219.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.219.250.1 (1.250.219.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 18:46:54.770359 2026] [security2:error] [pid 15422:tid 15422] [client 35.219.250.1:36312] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "yeejia.net"] [uri "/.git/config"] [unique_id "asbL3uNb5l58FkGbYKl12wAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-10-07 21:59:50
(12 hours ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-10-06.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-07 14:03:36
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.219.250.1 (1.250.219.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.219.250.1 (1.250.219.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 10:03:29.529737 2026] [security2:error] [pid 11028:tid 11028] [client 35.219.250.1:52592] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ycrlbasketball.com"] [uri "/.git/config"] [unique_id "asZRMYas2ZJ6WgfygWm_HwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack