🇮🇳
evicky2002
2026-08-31 00:01:03
(27 minutes ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
🇹🇷
muratkaya665
2026-08-30 03:15:53
(21 hours ago)
IPS Attack Blocked by server.mura******.com.tr Fortigate-80E. Attack Name: Spring.Boot.Actuator.Unau ...
show more
IPS Attack Blocked by server.mura******.com.tr Fortigate-80E. Attack Name: Spring.Boot.Actuator.Unauthorized.Access. Dest Port: 80. Service: HTTP. Message: applications3: Spring.Boot.Actuator.Unauthorized.Access.
show less
Hacking
🇺🇸
TPI-Abuse
2026-08-29 03:30:05
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.229.90.92 (92.90.229.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.90.92 (92.90.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 23:29:57.499178 2026] [security2:error] [pid 2046:tid 2046] [client 35.229.90.92:56360] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.leositalianice.royal-barbershop.com"] [uri "/wp-config.php~"] [unique_id "apJSNbkx0KfoJlX1tJnflgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 02:51:20
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.229.90.92 (92.90.229.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.90.92 (92.90.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 22:51:14.101483 2026] [security2:error] [pid 9592:tid 9592] [client 35.229.90.92:34158] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.emhelectric.com.pjvcds.com"] [uri "/.env.dev"] [unique_id "apJJIgYV6KMXitEdfavn7AAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-08-29 02:34:21
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 02:10:53
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.229.90.92 (92.90.229.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.90.92 (92.90.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 22:10:46.343636 2026] [security2:error] [pid 25846:tid 25857] [client 35.229.90.92:34268] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.chris.abney.info"] [uri "/.env.bak"] [unique_id "apI_prZMKQC7UXpuqgs1kgAAAMk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
Saec
2026-08-29 02:10:01
(1 day ago)
Jarvis auto-ban: CF top attacker on saec.me (26 hits, US)
Port Scan
Web App Attack
🇺🇸
mnsf
2026-08-29 00:08:30
(2 days ago)
Abuse Detected (9)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 23:15:45
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.229.90.92 (92.90.229.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.90.92 (92.90.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 19:15:37.547678 2026] [security2:error] [pid 9577:tid 9577] [client 35.229.90.92:33934] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.altoshp.ingberinteriors.com"] [uri "/.env.bak"] [unique_id "apIWmeOaHW1LgNGlb4sn6gAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
debestelapp
2026-08-28 22:40:13
(2 days ago)
Web App Attack
🇩🇪
raph
2026-08-28 22:18:58
(2 days ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
🇳🇱
homeshowdomain.nl
2026-08-28 22:01:08
(2 days ago)
Auto-ban: >3000 req/min op 2026-08-28
Web App Attack
SSH
Hacking
🇦🇺
paulshipley.com.au
2026-08-28 22:00:25
(2 days ago)
[Sat Aug 29 08:00:24.723652 2026] [security2:error] [pid 667962] [client 35.229.90.92:57242] [client ...
show more
[Sat Aug 29 08:00:24.723652 2026] [security2:error] [pid 667962] [client 35.229.90.92:57242] [client 35.229.90.92] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "furst.com.au"] [uri "/.env.prod"] [unique_id "apIE-F0Heij1SsNNZQrRhQAAABE"]
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 21:59:02
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.229.90.92 (92.90.229.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.90.92 (92.90.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 17:58:53.901852 2026] [security2:error] [pid 26528:tid 26528] [client 35.229.90.92:39656] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.mail.emelecsrl.com"] [uri "/wp-config.php.swp"] [unique_id "apIEndZjcKrR-4Btz3GKoAAAACw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 21:11:24
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.229.90.92 (92.90.229.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.90.92 (92.90.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 17:11:17.043693 2026] [security2:error] [pid 3152:tid 3152] [client 35.229.90.92:51950] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.maps.marat.info"] [uri "/wp-config.php~"] [unique_id "apH5dZSaC7bluayzT3bw4wAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack