🇺🇸
TPI-Abuse
2026-09-08 13:12:50
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.231.175.155 (155.175.231.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.231.175.155 (155.175.231.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 09:12:42.374680 2026] [security2:error] [pid 10580:tid 10580] [client 35.231.175.155:6908] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.frenosilent.ar"] [uri "/@fs/.env"] [unique_id "aqAJymsSyeRpIlFl6JkvxwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 12:51:28
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.231.175.155 (155.175.231.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.231.175.155 (155.175.231.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 08:51:22.170080 2026] [security2:error] [pid 4599:tid 4599] [client 35.231.175.155:23154] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.ondakompun.com"] [uri "/@fs/src/.env"] [unique_id "aqAEyhkGPHlY6za_NEfNlwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇿
Antinson
2026-09-08 12:38:12
(1 day ago)
Scraping with a high error ratio and request rate
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-08 12:11:04
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.231.175.155 (155.175.231.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.231.175.155 (155.175.231.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 08:10:56.372098 2026] [security2:error] [pid 28252:tid 28252] [client 35.231.175.155:60852] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.albertawaterjet.com"] [uri "/@fs/.env.staging"] [unique_id "ap_7ULMvq_1CVxiVGqqfnwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Savvii
2026-09-08 12:03:06
(1 day ago)
20 attempts against mh-misbehave-ban on onion
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 11:53:40
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.231.175.155 (155.175.231.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.231.175.155 (155.175.231.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 07:53:33.935341 2026] [security2:error] [pid 2949:tid 2949] [client 35.231.175.155:37386] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.deanfountain.com"] [uri "/@fs/.env"] [unique_id "ap_3PY40FmiXpD-E-j1_YQAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 11:40:32
(1 day ago)
T: f2b 404 5x
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 10:00:46
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.231.175.155 (155.175.231.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.231.175.155 (155.175.231.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 06:00:37.194115 2026] [security2:error] [pid 22316:tid 22316] [client 35.231.175.155:50488] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lahamradio.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "ap_cxU9qU4GcAjAqIuPJ_AAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
updown.io
2026-09-08 09:57:12
(1 day ago)
{"level":"info","ts":1788861410.9703224,"logger":"http.log.access.log0","msg":"handled request","req ...
show more
{"level":"info","ts":1788861410.9703224,"logger":"http.log.access.log0","msg":"handled request","request":{"remote_ip":"35.231.175.155","remote_port":"58692","client_ip":"35.231.175.155","proto":"HTTP/1.1","method":"GET","host":"vdhb.status.updown.io","uri":"/","headers":{"Accept-Encoding":["gzip"],"User-Agent":["Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36"],"Accept":["*/*"]}},"bytes_read":0,"user_id":"","duration":0.000090583,"size":0,"status":308,"resp_headers":{"Content-Type":[],"Server":["Caddy"],"Connection":["close"],"Location":["https://vdhb.status.updown.io/"]}}
{"level":"info","ts":1788861413.7043862,"logger":"http.log.access.log0","msg":"handled request","request":{"remote_ip":"35.231.175.155","remote_port":"1092","client_ip":"35.231.175.155","proto":"HTTP/1.1","method":"GET","host":"vdhb.status.updown.io","uri":"/@fs/..%252f..%252f..%252f..%252f..%252fapp/.env?raw??","headers":{"User-Agent":["Mozilla/5.0 (Wi
...
show less
DDoS Attack
Web App Attack
Anonymous
2026-09-08 08:16:12
(1 day ago)
Bot / seems abusive / Apache connections: 32
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 08:07:33
(1 day ago)
35.231.175.155 - - [08/Sep/2026:05:07:32 -0300] "GET /@fs/root/.env?raw?? HTTP/1.1" 403 829 "https:/ ...
show more
35.231.175.155 - - [08/Sep/2026:05:07:32 -0300] "GET /@fs/root/.env?raw?? HTTP/1.1" 403 829 "https://blogmania.com.br/@fs/root/.env?raw??" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)"
35.231.175.155 - - [08/Sep/2026:05:07:32 -0300] "GET /@fs/.env?raw?? HTTP/1.1" 403 829 "https://blogmania.com.br/@fs/.env?raw??" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko; compatible; ChatGPT-User/1.0; +https://openai.com/bot) Chrome/120.0.1818.113 Safari/537.36 Edg/120.0.1818.113"
35.231.175.155 - - [08/Sep/2026:05:07:32 -0300] "GET /@fs/src/.env?raw?? HTTP/1.1" 403 829 "https://blogmania.com.br/@fs/src/.env?raw??" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; +https://www.anthropic.com/claude-user) Chrome/134.0.6079.181 Safari/537.36"
35.231.175.155 - - [08/Sep/2026:05:07:32 -0300] "GET /@fs/app/.env?raw?? HTTP/1.1" 403 829 "https://blogmania.com.br/@fs/app/
...
show less
Port Scan
🇺🇸
TPI-Abuse
2026-09-08 07:30:06
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.231.175.155 (155.175.231.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.231.175.155 (155.175.231.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 03:30:01.103221 2026] [security2:error] [pid 16586:tid 16586] [client 35.231.175.155:3302] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.janaia.com"] [uri "/@fs/.env"] [unique_id "ap-5eXO4S9UNp4YAl1bn7QAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
IRISIO
2026-09-08 07:19:13
(1 day ago)
scans/SQL injection/spam posts : 937 queries
Web App Attack
SQL Injection
🇳🇱
debestelapp
2026-09-08 07:10:12
(1 day ago)
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 06:26:29
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.231.175.155 (155.175.231.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.231.175.155 (155.175.231.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 02:26:21.727750 2026] [security2:error] [pid 12504:tid 12504] [client 35.231.175.155:15748] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.givemethemic.org"] [uri "/@fs/app/.env"] [unique_id "ap-qjd-4_jAeO85axIey1QAAACo"]
show less
Brute-Force
Bad Web Bot
Web App Attack