๐บ๐ธ
TPI-Abuse
2026-09-17 10:34:38
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.224.225.39 (39.225.224.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.224.225.39 (39.225.224.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 06:34:30.266239 2026] [security2:error] [pid 31752:tid 31752] [client 35.224.225.39:36488] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thereddoorlounge.com"] [uri "/var/.env"] [unique_id "aqvCNoB47clKY_ZIlznVpwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-17 10:22:24
(1 hour ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
๐ฉ๐ช
niedson
2026-09-17 10:00:03
(1 hour ago)
Automated scanning for exposed secrets: repeated requests for multiple distinct credential paths (.e ...
show more
Automated scanning for exposed secrets: repeated requests for multiple distinct credential paths (.env variants, .git metadata, .ssh private keys, .aws/credentials). Unsolicited. Reported automatically.
show less
Web App Attack
๐ฌ๐ง
blik2108
2026-09-17 09:17:20
(2 hours ago)
35.224.225.39 - - [17/Sep/2026:09:17:16 +0000] "GET /build/manifest.json HTTP/1.1" 404 3431 "-" "Moz ...
show more
35.224.225.39 - - [17/Sep/2026:09:17:16 +0000] "GET /build/manifest.json HTTP/1.1" 404 3431 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36" "-"
35.224.225.39 - - [17/Sep/2026:09:17:16 +0000] "GET /rclone.conf HTTP/1.1" 404 3431 "-" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)" "-"
35.224.225.39 - - [17/Sep/2026:09:17:16 +0000] "GET /dist/.vite/manifest.json HTTP/1.1" 404 3431 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36" "-"
35.224.225.39 - - [17/Sep/2026:09:17:17 +0000] "GET /pipeline/.env HTTP/1.1" 404 3431 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ChatGPT-User/1.0; +https://openai.com/bot)" "-"
35.224.225.39 - - [17/Sep/2026:09:17:17 +0000] "GET /utils/.env HTTP/1.1" 404 3431 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)" "-"
35.224.225.39 - - [17/
...
show less
Web App Attack
Anonymous
2026-09-17 08:17:28
(3 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
Anonymous
2026-09-17 08:11:29
(3 hours ago)
Web Probe / Attack
Web App Attack
๐บ๐ธ
jormaster3k
2026-09-17 08:08:27
(3 hours ago)
Attack against Apache (too many 404s)
Web App Attack
๐ณ๐ฑ
Eric
2026-09-17 07:10:29
(4 hours ago)
[Thu Sep 17 07:10:28.692406 2026] [security2:error] [pid 1012634:tid 1012634] [client 35.224.225.39: ...
show more
[Thu Sep 17 07:10:28.692406 2026] [security2:error] [pid 1012634:tid 1012634] [client 35.224.225.39:0] [client 35.224.225.39] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "pop-the-slots.com"] [uri "/temp/.env"] [unique_id "aquSZHH5A_D9loQ0Yqkc1QAAABk"]
[Thu Sep 17 07:10:28.717399 2026] [security2:error] [pid 1012642:tid 1012642] [client 35.224.225.39:0] [client 35.224.225.39] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [se
...
show less
Hacking
Web App Attack
๐ง๐ช
voormedia
2026-09-17 06:23:26
(5 hours ago)
Accessed trap at '/.s3cfg'
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 06:09:28
(5 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.224.225.39 (39.225.224.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.224.225.39 (39.225.224.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 02:09:21.797125 2026] [security2:error] [pid 17438:tid 17438] [client 35.224.225.39:35524] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||notariapenco.cl|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "notariapenco.cl"] [uri "/server.key"] [unique_id "aquEEXeYsVaHa4xfCTsZCwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ณ
evicky2002
2026-09-17 06:00:05
(5 hours ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ณ๐ฑ
Savvii
2026-09-17 05:43:22
(6 hours ago)
20 attempts against mh-misbehave-ban on eris
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
Burayot
2026-09-17 05:25:24
(6 hours ago)
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 35.224.225.39 (US/United States/39.2 ...
show more
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 35.224.225.39 (US/United States/39.225.224.35.bc.googleusercontent.com): 1 in the last 3600 secs
show less
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-17 05:04:46
(6 hours ago)
20 attempts against mh-misbehave-ban on choy
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 04:48:38
(6 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.224.225.39 (39.225.224.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.224.225.39 (39.225.224.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 00:48:34.460656 2026] [security2:error] [pid 4800:tid 4800] [client 35.224.225.39:38786] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||manty.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "manty.com"] [uri "/z9x8c7v6b5-debug-trigger-manty.com"] [unique_id "aqtxImeQ6yJaXBleUQ1oRAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack