๐บ๐ธ
TPI-Abuse
2026-09-22 17:08:19
(13 minutes ago)
(mod_security) mod_security (id:210492) triggered by 35.228.14.10 (10.14.228.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.228.14.10 (10.14.228.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 13:08:16.378855 2026] [security2:error] [pid 21654:tid 21654] [client 35.228.14.10:56234] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "simia.com"] [uri "/wp-config.php.swp"] [unique_id "arK2ABAuTbgF7XUCh0PjHwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 16:46:44
(35 minutes ago)
(mod_security) mod_security (id:210492) triggered by 35.228.14.10 (10.14.228.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.228.14.10 (10.14.228.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 12:46:37.631945 2026] [security2:error] [pid 29449:tid 29449] [client 35.228.14.10:56616] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rocketcityhotwheelers.com"] [uri "/.env.dev"] [unique_id "arKw7XJZkHkj_volZiEN0wAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
yvoictra
2026-09-22 16:23:12
(58 minutes ago)
Bloqueado automรกticamente por CrowdSec. Escenario: crowdsecurity/http-probing
Web App Attack
Anonymous
2026-09-22 16:00:14
(1 hour ago)
IP banned by Fail2Ban in jail nginx-abusive-ips
Web App Attack
Brute-Force
Bad Web Bot
๐ฉ๐ช
SwinT
2026-09-22 16:00:10
(1 hour ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
Anonymous
2026-09-22 15:29:26
(1 hour ago)
35.228.14.10 - - [22/Sep/2026:15:29:26 +0000] "GET /.env.local HTTP/1.1" 404 11755 "-" "crusader-wor ...
show more
35.228.14.10 - - [22/Sep/2026:15:29:26 +0000] "GET /.env.local HTTP/1.1" 404 11755 "-" "crusader-worker/1.0"
...
show less
Brute-Force
Web App Attack
Anonymous
2026-09-22 14:51:02
(2 hours ago)
35.228.14.10 mail.irwindalecycles.com - [22/Sep/2026:08:51:00 -0600] "GET /crusader-404-probe HTTP/1 ...
show more
35.228.14.10 mail.irwindalecycles.com - [22/Sep/2026:08:51:00 -0600] "GET /crusader-404-probe HTTP/1.1" 403 158 "-" "crusader-worker/1.0"\n35.228.14.10 mail.irwindalecycles.com - [22/Sep/2026:08:51:00 -0600] "GET /.env.local HTTP/1.1" 403 158 "-" "crusader-worker/1.0"\n35.228.14.10 mail.irwindalecycles.com - [22/Sep/2026:08:51:00 -0600] "GET /wp-config.php~ HTTP/1.1" 403 158 "-" "crusader-worker/1.0"\n35.228.14.10 mail.irwindalecycles.com - [22/Sep/2026:08:51:00 -0600] "GET /_ignition/health-check HTTP/1.1" 403 158 "-" "crusader-worker/1.0"\n35.228.14.10 mail.irwindalecycles.com - [22/Sep/2026:08:51:00 -0600] "GET /env HTTP/1.1" 403 158 "-" "crusader-worker/1.0"\n35.228.14.10 mail.irwindalecycles.com - [22/Sep/2026:08:51:00 -0600] "GET /.env.dev HTTP/1.1" 403 158 "-" "crusader-worker/1.0"\n35.228.14.10 mail.irwindalecycles.com - [22/Sep/2026:08:51:00 -0600] "GET /wp-config.php.swp HTTP/1.1" 403 158 "-" "crusader-worker/1.0"\n35.228.14.10 mail.irwindalecycles.com - [22/Sep/2026:08:51:00 -0600]
show less
DDoS Attack
Web App Attack
๐จ๐ญ
zynex
2026-09-22 14:25:21
(2 hours ago)
URL Probing: /wp-config.php.bak
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 14:13:00
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.228.14.10 (10.14.228.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.228.14.10 (10.14.228.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 10:12:53.509250 2026] [security2:error] [pid 29139:tid 29139] [client 35.228.14.10:42390] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "k2servicesinc.net"] [uri "/.env"] [unique_id "arKM5f-PTaguTJ1E0OHyHgAAADc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ฐ
HostingGroup
2026-09-22 14:01:55
(3 hours ago)
Automated malicious activity (Honeypot Trap) detected and blocked at the CDN edge by NordicCDN Shiel ...
show more
Automated malicious activity (Honeypot Trap) detected and blocked at the CDN edge by NordicCDN Shield. Offenses: 2. First blocked: 2026-09-22.
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
FD-IX
2026-09-22 13:58:26
(3 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-22 13:31:35
(3 hours ago)
[ti-06al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-06al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 35.228.14.10 - - [22/Sep/2026:15:31:14 +0200] "GET /.env.dev HTTP/1.1" 403 146 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
Web App Attack
๐จ๐ญ
Origon
2026-09-22 13:13:24
(4 hours ago)
http-sensitive-files - IP: 35.228.14.10 - time="2026-09-22T15:13:24+02:00" level=info msg="(555f66b ...
show more
http-sensitive-files - IP: 35.228.14.10 - time="2026-09-22T15:13:24+02:00" level=info msg="(555f66b4f6a74558bc11e3f93469658es8App0Mcc0TKEeje/crowdsec) crowdsecurity/http-sensitive-files by ip 35.228.14.10 (FI/396982) : 4h ban on Ip 35.228.14.10" module=db
show less
Web App Attack
๐ท๐บ
DZBOT
2026-09-22 12:14:54
(5 hours ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 11:45:38
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.228.14.10 (10.14.228.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.228.14.10 (10.14.228.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 07:45:33.412732 2026] [security2:error] [pid 6806:tid 6806] [client 35.228.14.10:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.distro.media"] [uri "/.env.bak"] [unique_id "arJqXZEnV7cuXQ47du9mdgAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack