๐บ๐ธ
TPI-Abuse
2026-09-20 15:28:39
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 35.224.60.85 (85.60.224.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.224.60.85 (85.60.224.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 11:28:32.095044 2026] [security2:error] [pid 13054:tid 13054] [client 35.224.60.85:52304] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "holisticbuildingexperience.com"] [uri "/web/.env"] [unique_id "aq_7oPBfOpiU-6e2sMJpEgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-20 14:54:39
(2 weeks ago)
Aggressive web scan
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-20 14:42:07
(2 weeks ago)
[ti-22al] Web exploit scanning: 2 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-22al] Web exploit scanning: 2 suspicious requests detected by fail2ban jail apache-scanner. Example: 35.224.60.85 - - [20/Sep/2026:16:42:03 +0200] "GET /@fs/src/.env?raw?? HTTP/2.0" 404 240404 "-" "Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 14:41:56
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 35.224.60.85 (85.60.224.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.224.60.85 (85.60.224.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 10:41:49.495043 2026] [security2:error] [pid 30577:tid 30577] [client 35.224.60.85:50120] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "footballxp.com"] [uri "/infra/.env"] [unique_id "aq_wrZCjbLrEKl5ezgAQKQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
MBombeck
2026-09-20 14:34:35
(2 weeks ago)
Fail2Ban/traefik-botsearch on apps-01: banned after 5 failures
Web App Attack
Anonymous
2026-09-20 14:30:03
(2 weeks ago)
CrowdSec decision: crowdsecurity/http-admin-interface-probing (origin: crowdsec)
Web App Attack
๐ช๐ธ
robotstxt
2026-09-20 14:04:29
(2 weeks ago)
35.224.60.85 - - [20/Sep/2026:14:04:16 +0000] "GET /.aws/credentials HTTP/2.0" 403 26793 "-" "Mozill ...
show more
35.224.60.85 - - [20/Sep/2026:14:04:16 +0000] "GET /.aws/credentials HTTP/2.0" 403 26793 "-" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" "-" edge="35.224.60.85"
35.224.60.85 - - [20/Sep/2026:14:04:17 +0000] "GET /scripts/.env HTTP/2.0" 403 26793 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] )" "-" edge="35.224.60.85"
35.224.60.85 - - [20/Sep/2026:14:04:17 +0000] "GET /frontend/.env HTTP/2.0" 403 26793 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)" "-" edge="35.224.60.85"
35.224.60.85 - - [20/Sep/2026:14:04:18 +0000] "GET /.aws/config HTTP/2.0" 403 26793 "-" "Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)" "-" edge="35.224.60.85"
35.224.60.85 - - [20/Sep/2026:14:04:18 +0000] "GET /.git/config HTTP/2.0" 403 26791 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.
...
show less
Web App Attack
๐ซ๐ท
demomodule
2026-09-20 13:57:00
(2 weeks ago)
PrestaShop Security Module: suspicious probe path detected (/.env)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 13:54:15
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 35.224.60.85 (85.60.224.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.224.60.85 (85.60.224.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 09:54:11.298214 2026] [security2:error] [pid 5934:tid 5939] [client 35.224.60.85:36714] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||davidchapa.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "davidchapa.com"] [uri "/z9x8c7v6b5-debug-trigger-davidchapa.com"] [unique_id "aq_lg3dtCEIx02CpOfyTIwAAAEM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-09-20 13:42:31
(2 weeks ago)
Walking a list of paths that do not exist (scanning) | method: GET | path: /actuator/loggers (+6 mor ...
show more
Walking a list of paths that do not exist (scanning) | method: GET | path: /actuator/loggers (+6 more) | 2026-09-20 13:42 UTC
show less
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 13:28:52
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 35.224.60.85 (85.60.224.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.224.60.85 (85.60.224.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 09:28:46.335609 2026] [security2:error] [pid 26564:tid 26564] [client 35.224.60.85:35498] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||cevhersys.com|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "cevhersys.com"] [uri "/server.key"] [unique_id "aq_fjn4M6bvSHUSpda2D2QAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-20 13:27:19
(2 weeks ago)
Blocked by ModSec and CSF
Port Scan
๐บ๐ธ
TPI-Abuse
2026-09-20 13:11:26
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 35.224.60.85 (85.60.224.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.224.60.85 (85.60.224.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 09:11:22.856859 2026] [security2:error] [pid 29641:tid 29641] [client 35.224.60.85:44910] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bookingsouthafrica.com"] [uri "/.env.backup"] [unique_id "aq_bem-RMMn66rK_Y2SlHAAAACw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-20 13:06:48
(2 weeks ago)
35.224.60.85 - - [20/Sep/2026:13:06:47 +0000] "-" 400 166 "-" "-"
35.224.60.85 - - [20/Sep/2026:13:0 ...
show more
35.224.60.85 - - [20/Sep/2026:13:06:47 +0000] "-" 400 166 "-" "-"
35.224.60.85 - - [20/Sep/2026:13:06:47 +0000] "-" 400 166 "-" "-"
35.224.60.85 - - [20/Sep/2026:13:06:47 +0000] "-" 400 166 "-" "-"
...
show less
Brute-Force
๐ซ๐ท
GabrielJST
2026-09-20 12:57:09
(2 weeks ago)
(mod_security) mod_security triggered on hostname [redacted] 35.224.60.85 (US/United States/85.60.22 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.224.60.85 (US/United States/85.60.224.35.bc.googleusercontent.com): (CF_ENABLE)
show less
SQL Injection