๐บ๐ธ
TPI-Abuse
2026-09-22 00:54:38
(6 days ago)
(mod_security) mod_security (id:949110) triggered by 35.233.172.138 (138.172.233.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:949110) triggered by 35.233.172.138 (138.172.233.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 20:54:32.871566 2026] [security2:error] [pid 28049:tid 28049] [client 35.233.172.138:46384] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.cwbaz.com"] [uri "/.git/HEAD"] [unique_id "arHRyI_C0pgpEfBQ7W3OSwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 00:16:22
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 35.233.172.138 (138.172.233.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.233.172.138 (138.172.233.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 20:16:15.629799 2026] [security2:error] [pid 25973:tid 25973] [client 35.233.172.138:34298] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.aluthienproperties.com"] [uri "/.env"] [unique_id "arHIz6ldkmxozuIKcKWRXAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-22 00:12:40
(6 days ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-195)
Hacking
Web App Attack
๐บ๐ธ
mnsf
2026-09-21 22:05:32
(6 days ago)
Scanning/Probing (12)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 21:02:27
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 35.233.172.138 (138.172.233.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.233.172.138 (138.172.233.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 17:02:22.477774 2026] [security2:error] [pid 15804:tid 15804] [client 35.233.172.138:57606] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "curtmudgins.com"] [uri "/server/.env"] [unique_id "arGbXgBW9KTiZOiWCZM91QAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-21 19:37:51
(6 days ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 19:29:25
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 35.233.172.138 (138.172.233.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.233.172.138 (138.172.233.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 15:29:19.668927 2026] [security2:error] [pid 17031:tid 17031] [client 35.233.172.138:47002] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "5starfluffandfold.com"] [uri "/.env.bak"] [unique_id "arGFj-wE4OFs9ynp-Es9FAAAADQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-21 18:26:26
(6 days ago)
[ti-17al] Web exploit scanning: 3 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-17al] Web exploit scanning: 3 suspicious requests detected by fail2ban jail apache-scanner. Example: 35.233.172.138 - - [21/Sep/2026:20:26:25 +0200] "GET /.git/HEAD HTTP/2.0" 404 2004 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)"
35.233.172.138 - - [21/Sep/2026:20:26:25 +0200] "GET /admin/.env HTTP/2.0" 404 2004 "-" "Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)"
35.233.172.138 - - [21/Sep/2026:20:26:25 +0200] "GET /.git/config HTTP/2.0" 404 2004 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 17:34:16
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 35.233.172.138 (138.172.233.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.233.172.138 (138.172.233.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 13:34:09.217873 2026] [security2:error] [pid 26343:tid 26380] [client 35.233.172.138:33920] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.danandlila.com"] [uri "/client/.env"] [unique_id "arFqkWVNjguNkQuLWSpJoAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-09-21 17:00:06
(6 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 15:28:52
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 35.233.172.138 (138.172.233.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.233.172.138 (138.172.233.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 11:28:45.127230 2026] [security2:error] [pid 28674:tid 28674] [client 35.233.172.138:41254] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "monitor.kemela.com"] [uri "/.env.backup"] [unique_id "arFNLV8RJnKkeQkyMCkvIgAAACw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-21 15:08:57
(6 days ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-09-21 15:04:06
(6 days ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐ฉ๐ช
Hazzard
2026-09-21 14:56:05
(6 days ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-09-21 14:54:05
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 35.233.172.138 (138.172.233.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.233.172.138 (138.172.233.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 10:54:00.782512 2026] [security2:error] [pid 15680:tid 15680] [client 35.233.172.138:51398] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.internetnameregistration.com"] [uri "/.git/HEAD"] [unique_id "arFFCAwKeWwo-Ur0RIeIxgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack