๐ฟ๐ฆ
conure.sh
2026-09-22 12:04:02
(17 hours ago)
csagent: score 21.2: 404 noise floor x5, secrets grab x2; 1 domain(s) in 9s
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 01:42:20
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.231.75.213 (213.75.231.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.231.75.213 (213.75.231.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 21:42:13.600273 2026] [security2:error] [pid 2550:tid 2586] [client 35.231.75.213:33650] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.conservativelabor.com"] [uri "/.env.bak"] [unique_id "arHc9Ww5U9bdOYh5AD0mbQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 00:08:06
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.231.75.213 (213.75.231.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.231.75.213 (213.75.231.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 20:07:46.310084 2026] [security2:error] [pid 28173:tid 28173] [client 35.231.75.213:49590] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "closedfortheseason.com"] [uri "/.env.backup"] [unique_id "arHG0t01VKCxVd5RffO94AAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
poundawebsiteltd
2026-09-21 23:09:53
(1 day ago)
Malicious activity in general-malicious. Evidence: (apache_probe) Failed Access (403/404) 35.231.75. ...
show more
Malicious activity in general-malicious. Evidence: (apache_probe) Failed Access (403/404) 35.231.75.213 (US/United States/[REDACTED_DOMAIN]): 20 in the last 3600 secs | UA: (apache_probe) Failed Access (403/404) 35.231.75.213 (US/United States/213.75.231.35.bc.googleusercontent.com): 20 in the last 3600 secs
show less
Brute-Force
Web App Attack
๐ฉ๐ช
TheDjRider
2026-09-21 21:32:40
(1 day ago)
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban tri ...
show more
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban triggered. Detection time (UTC): 2026-09-21T21:32:36.469999428Z. Context: http_status=200
show less
Web App Attack
๐ฉ๐ช
IVski.com
2026-09-21 21:18:26
(1 day ago)
IVski WAF | Sensitive file probe - looking for exposed .env
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 20:52:46
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.231.75.213 (213.75.231.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.231.75.213 (213.75.231.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 16:52:40.713922 2026] [security2:error] [pid 10569:tid 10639] [client 35.231.75.213:35830] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.venezuelaguia.com"] [uri "/docker/.env"] [unique_id "arGZGDVmMLw7XBF23jcJUQAAAMs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 19:33:17
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.231.75.213 (213.75.231.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.231.75.213 (213.75.231.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 15:33:09.659831 2026] [security2:error] [pid 10745:tid 10745] [client 35.231.75.213:57160] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.constructionloansfunding.internetnameregistration.com|F|2"] [data ".constructionloansfunding.internetnameregistration.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.constructionloansfunding.internetnameregistration.com"] [uri "/z9x8c7v6b5-debug-trigger-www.constructionloansfunding.internetnameregistration.com"] [unique_id "arGGdbTypJWY9r84TFXssgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 18:08:39
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.231.75.213 (213.75.231.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.231.75.213 (213.75.231.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 14:08:31.414492 2026] [security2:error] [pid 19812:tid 19812] [client 35.231.75.213:40490] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.computerservicesofflorida.com"] [uri "/project/.env"] [unique_id "arFyn38SzGw53AOPrzl5ywAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-21 17:46:54
(1 day ago)
[ti-01ov] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 35. ...
show more
[ti-01ov] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 35.231.75.213 - - \[21/Sep/2026:19:46:46 +0200\] "GET /.aws/credentials HTTP/1.1" 301 611 "-" "Mozilla/5.0 AppleWebKit/537.36 \(KHTML, like Gecko\; compatible\; Claude-SearchBot/1.0\; [email protected] \)"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
IndigoRidge
2026-09-21 17:18:46
(1 day ago)
[21/Sep/2026:13:18:46.435352 --0400] arFm9llddWSQ@-qzWC2cjgAAAUY 35.231.75.213 46932 205.233.18.17 7 ...
show more
[21/Sep/2026:13:18:46.435352 --0400] arFm9llddWSQ@-qzWC2cjgAAAUY 35.231.75.213 46932 205.233.18.17 7081
[21/Sep/2026:13:18:46.438060 --0400] arFm9p7DswgBvZgVgbSxgAAAAlg 35.231.75.213 46926 205.233.18.17 7081
[21/Sep/2026:13:18:46.439585 --0400] arFm9llddWSQ@-qzWC2cjwAAAUY 35.231.75.213 46942 205.233.18.17 7081
[21/Sep/2026:13:18:46.459375 --0400] arFm9meLpu33oqBfA8qqPQAAAQE 35.231.75.213 46964 205.233.18.17 7081
[21/Sep/2026:13:18:46.465126 --0400] arFm9meLpu33oqBfA8qqPgAAARE 35.231.75.213 46974 205.233.18.17 7081
...
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-21 17:09:08
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.231.75.213 (213.75.231.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.231.75.213 (213.75.231.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 13:09:02.199411 2026] [security2:error] [pid 18281:tid 18281] [client 35.231.75.213:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.cloudbursttechnologies.com"] [uri "/app/.env"] [unique_id "arFkrmcKd9pLzdMdIjLdxwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 16:49:31
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.231.75.213 (213.75.231.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.231.75.213 (213.75.231.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 12:49:23.328332 2026] [security2:error] [pid 13441:tid 13441] [client 35.231.75.213:45370] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.bridgital.com"] [uri "/packages/.env"] [unique_id "arFgEy8HBuBvownbistImAAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
COMAITE
2026-09-21 16:49:15
(1 day ago)
Suspicious URL access.
Web App Attack
๐ช๐ธ
pepitogrillo
2026-09-21 16:40:55
(1 day ago)
35.231.75.213 - - [21/Sep/2026:16:40:54 +0000] "GET /api/settings HTTP/1.1" 301 368 "-" "Mozilla/5.0 ...
show more
35.231.75.213 - - [21/Sep/2026:16:40:54 +0000] "GET /api/settings HTTP/1.1" 301 368 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
...
show less
DNS Compromise
DNS Poisoning
Fraud Orders
DDoS Attack
Ping of Death
Phishing
Fraud VoIP
Open Proxy
Web Spam
Email Spam
Port Scan
Hacking
SQL Injection
Bad Web Bot
Exploited Host
Web App Attack
IoT Targeted