๐บ๐ธ
TPI-Abuse
2026-09-16 07:58:47
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.236.189.32 (32.189.236.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.189.32 (32.189.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 03:58:39.455655 2026] [security2:error] [pid 2667:tid 2667] [client 35.236.189.32:53046] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.exhibitmanager.krmartindale.com"] [uri "/.git/config"] [unique_id "aqpML2W14g0XHl6PGtbD4wAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 06:41:50
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.236.189.32 (32.189.236.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.189.32 (32.189.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 02:41:42.751251 2026] [security2:error] [pid 9171:tid 9171] [client 35.236.189.32:50208] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.drbolen.com"] [uri "/.git/config"] [unique_id "aqo6JtRnmDGYweSjtdvccgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 04:31:56
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.236.189.32 (32.189.236.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.189.32 (32.189.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 00:31:50.066795 2026] [security2:error] [pid 2040666:tid 2040666] [client 35.236.189.32:51538] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.exchange.ic1.solutions.ic1.biz"] [uri "/.git/config"] [unique_id "aqobtlPbVNRTzLVbz2LfNwAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
akasolutions.de
2026-09-16 04:15:40
(14 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 35.236.189.32 (TW/Taiwan/32.189.236.35. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.236.189.32 (TW/Taiwan/32.189.236.35.bc.googleusercontent.com)
show less
SQL Injection
Anonymous
2026-09-16 03:29:50
(15 hours ago)
๐จ Repeated automated attempts to access prohibited paths and exploit known web application vulnerabi ...
show more
๐จ Repeated automated attempts to access prohibited paths and exploit known web application vulnerabilities.
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 21:52:27
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.236.189.32 (32.189.236.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.189.32 (32.189.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 17:52:21.937176 2026] [security2:error] [pid 27022:tid 27022] [client 35.236.189.32:44292] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.eweekmaine.arsenaultartistmanagement.com"] [uri "/.git/config"] [unique_id "aqm-FahS_37400hcRPjmqwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 20:26:46
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.236.189.32 (32.189.236.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.189.32 (32.189.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 16:26:42.523684 2026] [security2:error] [pid 22794:tid 22794] [client 35.236.189.32:47438] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.evtoy.danged.com"] [uri "/.git/config"] [unique_id "aqmqAmnEjCxCScq41l7LvgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-09-15 18:50:09
(23 hours ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ฉ๐ช
yitzhaq
2026-09-15 18:27:39
(1 day ago)
35.236.189.32 - - [15/Sep/2026:20:27:33 +0200] "POST / HTTP/1.1" 500 8060 "-" "Mozilla/5.0 (Macintos ...
show more
35.236.189.32 - - [15/Sep/2026:20:27:33 +0200] "POST / HTTP/1.1" 500 8060 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.236.189.32 - - [15/Sep/2026:20:27:34 +0200] "GET /.git/config HTTP/1.1" 403 4476 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.236.189.32 - - [15/Sep/2026:20:27:34 +0200] "POST / HTTP/1.1" 500 4075 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.236.189.32 - - [15/Sep/2026:20:27:34 +0200] "GET /.env HTTP/1.1" 404 4473 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.236.189.32 - - [15/Sep/2026:20:27:35 +0200] "GET /.env.local HTTP/1.1" 404 513 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safa
show less
Web App Attack
Hacking
๐ฉ๐ช
FD-IX
2026-09-15 17:57:40
(1 day ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
Anonymous
2026-09-15 12:40:00
(1 day ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐ฆ๐บ
paulshipley.com.au
2026-09-15 12:30:48
(1 day ago)
[Tue Sep 15 22:30:47.914973 2026] [security2:error] [pid 247615] [client 35.236.189.32:53096] [clien ...
show more
[Tue Sep 15 22:30:47.914973 2026] [security2:error] [pid 247615] [client 35.236.189.32:53096] [client 35.236.189.32] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "winesbydesign.com.au"] [uri "/"] [unique_id "aqk6d4wTYbu-m6XNopfzvQAAAA4"]
...
show less
Web App Attack
Anonymous
2026-09-15 12:23:26
(1 day ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
๐ฎ๐น
VHosting
2026-09-15 09:35:03
(1 day ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 06:42:22
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.236.189.32 (32.189.236.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.189.32 (32.189.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 02:42:13.308326 2026] [security2:error] [pid 21196:tid 21196] [client 35.236.189.32:34728] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "winbayfire.com"] [uri "/.git/config"] [unique_id "aqjoxW1ktCL6APDsxo38GgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack