🇧🇪
cmbplf
2026-09-08 22:39:20
(4 hours ago)
317 requests with url.path *.aws/*
Brute-Force
Bad Web Bot
🇳🇱
homeshowdomain.nl
2026-09-08 22:02:41
(5 hours ago)
Auto-ban: >3000 req/min op 2026-09-08
Web App Attack
SSH
Hacking
🇺🇸
TPI-Abuse
2026-09-08 19:55:18
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.229.128.231 (231.128.229.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.128.231 (231.128.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 15:55:15.458002 2026] [security2:error] [pid 21911:tid 21911] [client 35.229.128.231:24746] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.auguststoten.com"] [uri "/@fs/root/.env"] [unique_id "aqBoIw95F1-hW4Va3yhc9gAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 19:13:20
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.229.128.231 (231.128.229.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.128.231 (231.128.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 15:13:12.142017 2026] [security2:error] [pid 6641:tid 6641] [client 35.229.128.231:7068] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.fernfield.com"] [uri "/@fs/.env"] [unique_id "aqBeSAZKhThO9AkDMZZl5wAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Savvii
2026-09-08 19:05:59
(8 hours ago)
20 attempts against mh_ha-misbehave-ban on pf102936
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-08 18:57:29
(8 hours ago)
Excessive multi-domain requests
Brute-Force
🇪🇸
pipeline.es
2026-09-08 18:52:42
(8 hours ago)
Web scanning / probing for vulnerable paths | URL: /@fs/app/aws-exports.js?raw?? | Evidence: viagens ...
show more
Web scanning / probing for vulnerable paths | URL: /@fs/app/aws-exports.js?raw?? | Evidence: viagenstavares.pt 35.229.128.231 - - [08/Sep/2026:20:51:35 +0200] \"GET /@fs/app/aws-exports.js?raw?? HTTP/1.1\" 404 22708 \"-\" \"Mozilla/5.0 (compatible; GPTBot/1.2; +https://openai.com/gptbot)\" GEOIP_COUNTRY_CODE=TW | ASN: GOOGLE-CLOUD-PLATFORM | Country: TW
show less
Port Scan
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 18:23:50
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.229.128.231 (231.128.229.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.128.231 (231.128.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 14:23:46.388521 2026] [security2:error] [pid 24627:tid 24627] [client 35.229.128.231:58480] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.qovintheloop.org"] [uri "/@fs/src/.env"] [unique_id "aqBSshPBy780OzsOibeXBgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
COMAITE
2026-09-08 18:00:07
(9 hours ago)
Common web attack from 35.229.128.231.
Web App Attack
Anonymous
2026-09-08 17:58:15
(9 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
🇳🇱
Site.eu
2026-09-08 17:46:42
(9 hours ago)
Excessive 404/403 errors
Brute-Force
🇳🇱
Savvii
2026-09-08 17:37:30
(10 hours ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
madeit
2026-09-08 17:08:18
(10 hours ago)
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 16:33:45
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.229.128.231 (231.128.229.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.128.231 (231.128.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 12:33:40.980365 2026] [security2:error] [pid 11571:tid 11571] [client 35.229.128.231:58886] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.dhappraisalservices.com"] [uri "/@fs/.env"] [unique_id "aqA45FeeVfm1Ysjohug_kwAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-09-08 16:25:02
(11 hours ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack