๐บ๐ธ
TPI-Abuse
2026-09-01 03:54:06
(51 minutes ago)
(mod_security) mod_security (id:210492) triggered by 35.228.89.154 (154.89.228.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.228.89.154 (154.89.228.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 23:53:58.048096 2026] [security2:error] [pid 2082:tid 2082] [client 35.228.89.154:57262] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lgbtqhistoryinaustin.org"] [uri "/wp-config.php~"] [unique_id "apZMVu8-5aBOkHNdBGAZMgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
poundawebsiteltd
2026-09-01 02:46:34
(1 hour ago)
Malicious activity in general-malicious. Evidence: (apache_probe) Failed Access (403/404) 35.228.89. ...
show more
Malicious activity in general-malicious. Evidence: (apache_probe) Failed Access (403/404) 35.228.89.154 (FI/Finland/[REDACTED_DOMAIN]): 20 in the last 3600 secs | UA: (apache_probe) Failed Access (403/404) 35.228.89.154 (FI/Finland/154.89.228.35.bc.googleusercontent.com): 20 in the last 3600 secs
show less
Brute-Force
Web App Attack
๐ฌ๐ง
consul.to
2026-09-01 02:35:21
(2 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 01:16:09
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.228.89.154 (154.89.228.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.228.89.154 (154.89.228.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 21:16:05.397433 2026] [security2:error] [pid 21725:tid 21725] [client 35.228.89.154:59806] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "djmrmusic.com"] [uri "/.env.example"] [unique_id "apYnVfYNHDtiQ_qboNmhAgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 00:22:22
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.228.89.154 (154.89.228.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.228.89.154 (154.89.228.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 20:22:18.515304 2026] [security2:error] [pid 20792:tid 20792] [client 35.228.89.154:55498] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.idahostem.org"] [uri "/wp-config.php.swp"] [unique_id "apYauvzvMmehLD58vbrG7wAAAF0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-01 00:12:40
(4 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐ต๐ฑ
mscode.pl
2026-08-31 23:48:00
(4 hours ago)
Triggered Cloudflare WAF (firewallManaged) from FI.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Pro ...
show more
Triggered Cloudflare WAF (firewallManaged) from FI.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/1.1 (GET method)
Zone: cms.mscode.pl
Endpoint: /wp-config.php.bak
UA: crusader-worker/1.0
show less
Bad Web Bot
Anonymous
2026-08-31 23:39:12
(5 hours ago)
35.228.89.154 - - [31/Aug/2026:23:39:11 +0000] "GET /actuator/env HTTP/1.1" 404 162 "-" "crusader-wo ...
show more
35.228.89.154 - - [31/Aug/2026:23:39:11 +0000] "GET /actuator/env HTTP/1.1" 404 162 "-" "crusader-worker/1.0"
35.228.89.154 - - [31/Aug/2026:23:39:11 +0000] "GET /.env.old HTTP/1.1" 404 162 "-" "crusader-worker/1.0"
...
show less
Web App Attack
๐บ๐ธ
n2nguyenn2nguyen
2026-08-31 22:56:15
(5 hours ago)
Blocked by YFC Security on https://brixzly.com โ type: directory_scan_attempts
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 22:21:53
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.228.89.154 (154.89.228.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.228.89.154 (154.89.228.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 18:21:45.196720 2026] [security2:error] [pid 14465:tid 14465] [client 35.228.89.154:54752] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.wbcsnet.com"] [uri "/.env"] [unique_id "apX-eahgzKeeYZrQ0zGS1wAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-08-31 22:20:06
(6 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ฉ๐ช
FD-IX
2026-08-31 22:13:42
(6 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-08-31 22:10:07
(6 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 22:06:05
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.228.89.154 (154.89.228.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.228.89.154 (154.89.228.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 18:05:56.834894 2026] [security2:error] [pid 6959:tid 6959] [client 35.228.89.154:49624] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "arkml.com"] [uri "/.env.save"] [unique_id "apX6xO6wABEbKZRGVEqwEQAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Aetherweb Ark
2026-08-31 21:03:43
(7 hours ago)
(mod_security) mod_security (id:949110) triggered by 35.228.89.154 (FI/Finland/154.89.228.35.bc.goog ...
show more
(mod_security) mod_security (id:949110) triggered by 35.228.89.154 (FI/Finland/154.89.228.35.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack