๐ฌ๐ง
sc user
2026-08-31 22:48:35
(1 day ago)
Fail2Ban nginx: repeated suspicious HTTP requests consistent with automated probing, scanning or bad ...
show more
Fail2Ban nginx: repeated suspicious HTTP requests consistent with automated probing, scanning or bad bot behaviour. Technical log details and local server identifiers intentionally omitted for privacy.
show less
Bad Web Bot
Web App Attack
Port Scan
๐ฌ๐ง
sc user
2026-08-30 22:18:45
(2 days ago)
Fail2Ban nginx: repeated suspicious HTTP requests consistent with automated probing, scanning or bad ...
show more
Fail2Ban nginx: repeated suspicious HTTP requests consistent with automated probing, scanning or bad bot behaviour. Technical log details and local server identifiers intentionally omitted for privacy.
show less
Bad Web Bot
Web App Attack
Port Scan
๐ฌ๐ง
sc user
2026-08-28 21:45:54
(4 days ago)
Fail2Ban nginx: repeated suspicious HTTP requests consistent with automated probing, scanning or bad ...
show more
Fail2Ban nginx: repeated suspicious HTTP requests consistent with automated probing, scanning or bad bot behaviour. Technical log details and local server identifiers intentionally omitted for privacy.
show less
Bad Web Bot
Web App Attack
Port Scan
๐ฌ๐ง
sc user
2026-08-26 23:19:25
(6 days ago)
Fail2Ban nginx: repeated suspicious HTTP requests consistent with automated probing, scanning or bad ...
show more
Fail2Ban nginx: repeated suspicious HTTP requests consistent with automated probing, scanning or bad bot behaviour. Technical log details and local server identifiers intentionally omitted for privacy.
show less
Bad Web Bot
Web App Attack
Port Scan
๐บ๐ธ
TPI-Abuse
2026-08-26 05:43:56
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.232.179.28 (28.179.232.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.232.179.28 (28.179.232.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 01:43:49.145403 2026] [security2:error] [pid 999:tid 999] [client 35.232.179.28:6368] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thehunterstomb.com"] [uri "/.env"] [unique_id "ao59FZvCkSXakO58BNIlrwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 04:31:17
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.232.179.28 (28.179.232.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.232.179.28 (28.179.232.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 00:31:10.031433 2026] [security2:error] [pid 1479:tid 1479] [client 35.232.179.28:50564] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thehiddengemmalta.com"] [uri "/.env"] [unique_id "ao5sDonWuEfyAddi9458RQAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐ฝ
octageeks.com
2026-08-26 04:17:27
(1 week ago)
Wordpress malicious attack:[octablocked]
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-08-26 04:15:04
(1 week ago)
csagent: score 20.4: secrets grab x2, 404 noise floor x2; 1 domain(s) in 1s
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 02:24:16
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.232.179.28 (28.179.232.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.232.179.28 (28.179.232.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 22:24:08.419698 2026] [security2:error] [pid 14506:tid 14506] [client 35.232.179.28:2506] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thegrabbagshow.com"] [uri "/.env"] [unique_id "ao5OSMny2HA2XS8elbJ7GAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 02:03:43
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.232.179.28 (28.179.232.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.232.179.28 (28.179.232.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 22:03:35.861546 2026] [security2:error] [pid 11262:tid 11262] [client 35.232.179.28:7270] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thegoldreserve.com"] [uri "/.env"] [unique_id "ao5Jd32AE4ODWdIrhT1kYwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 00:51:33
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.232.179.28 (28.179.232.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.232.179.28 (28.179.232.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 20:51:26.166250 2026] [security2:error] [pid 29539:tid 29539] [client 35.232.179.28:21030] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thegamblefamily.com"] [uri "/.env"] [unique_id "ao44jmvkdxi3n277h28NqQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
thedreamer.nl
2026-08-25 20:55:18
(1 week ago)
35.232.179.28 - - [25/Aug/2026:22:53:53 +0200] "GET /.env HTTP/1.1" 200 1007 "-" "Mozilla/5.0 (Windo ...
show more
35.232.179.28 - - [25/Aug/2026:22:53:53 +0200] "GET /.env HTTP/1.1" 200 1007 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64)" "US" "Council Bluffs" "41.25910" "-95.85170"
35.232.179.28 - - [25/Aug/2026:22:53:54 +0200] "GET /.git/config HTTP/1.1" 200 1007 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64)" "US" "Council Bluffs" "41.25910" "-95.85170"
35.232.179.28 - - [25/Aug/2026:22:53:54 +0200] "GET /.env.bak HTTP/1.1" 200 1007 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64)" "US" "Council Bluffs" "41.25910" "-95.85170"
35.232.179.28 - - [25/Aug/2026:22:53:55 +0200] "GET /wp-config.php-backup HTTP/1.1" 200 1007 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64)" "US" "Council Bluffs" "41.25910" "-95.85170"
...
show less
Hacking
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 20:44:06
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.232.179.28 (28.179.232.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.232.179.28 (28.179.232.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 16:44:02.257887 2026] [security2:error] [pid 4583:tid 4583] [client 35.232.179.28:49622] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thedoodlists.com"] [uri "/.env"] [unique_id "ao3-kp9Jnt4B_Zi491t7iwAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 19:49:01
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.232.179.28 (28.179.232.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.232.179.28 (28.179.232.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 15:48:54.583322 2026] [security2:error] [pid 28782:tid 28782] [client 35.232.179.28:16344] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thedenzers.com"] [uri "/.env"] [unique_id "ao3xpqzDcFPooS_If3RzbwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
thesimonmanuel
2026-08-25 19:05:47
(1 week ago)
35.232.179.28 - - [26/Aug/2026:00:35:46 +0530] "GET /.env HTTP/1.1" 404 12801 "-" "Mozilla/5.0 (Wind ...
show more
35.232.179.28 - - [26/Aug/2026:00:35:46 +0530] "GET /.env HTTP/1.1" 404 12801 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64)"
show less
Web App Attack