๐ซ๐ท
SpaceHost-Server
2026-09-16 22:21:37
(1 day ago)
Brute-Force
Web App Attack
Anonymous
2026-09-16 05:44:58
(1 day ago)
Aggressive web scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 03:48:00
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.237.20.192 (192.20.237.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.20.192 (192.20.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 23:47:52.747277 2026] [security2:error] [pid 14419:tid 14419] [client 35.237.20.192:37056] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "starrmail.net"] [uri "/%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env"] [unique_id "aqoRaMqIeE33kQFeyCbSZgAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
jormaster3k
2026-09-16 03:35:39
(1 day ago)
Attack against Apache (too many 404s)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 03:28:56
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.237.20.192 (192.20.237.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.237.20.192 (192.20.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 23:28:49.467100 2026] [security2:error] [pid 8769:tid 8769] [client 35.237.20.192:56402] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||progressivefileshare.org|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "progressivefileshare.org"] [uri "/rclone.conf"] [unique_id "aqoM8dnEw_pM-Pd6wBL1UgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 03:12:06
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.237.20.192 (192.20.237.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.20.192 (192.20.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 23:12:01.031982 2026] [security2:error] [pid 22097:tid 22097] [client 35.237.20.192:50004] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mroxygen.org"] [uri "/%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env"] [unique_id "aqoJAUvQ7FkzXgHup60SAAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-16 03:04:18
(1 day ago)
URL file extension is restricted by policy. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ ...
show more
URL file extension is restricted by policy. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. (920440-131)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-16 02:09:05
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.237.20.192 (192.20.237.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.20.192 (192.20.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 22:08:59.079073 2026] [security2:error] [pid 24187:tid 24275] [client 35.237.20.192:47448] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "exede-sales.com"] [uri "/.git/HEAD"] [unique_id "aqn6OwwHPcdkUn4WKJbjtAAAAJQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐พ
lns.bz
2026-09-16 01:54:28
(1 day ago)
Too many 404 requests [BY]
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 01:42:19
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.237.20.192 (192.20.237.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.20.192 (192.20.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 21:42:11.436744 2026] [security2:error] [pid 16505:tid 16505] [client 35.237.20.192:52548] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "crazycoin.net"] [uri "/.env.js"] [unique_id "aqnz80l4zN4e4EEcHylWxwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 01:17:37
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.237.20.192 (192.20.237.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.20.192 (192.20.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 21:17:31.629903 2026] [security2:error] [pid 18353:tid 18353] [client 35.237.20.192:47070] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cgsaviation.com"] [uri "/%2e%2e/%2e%2e/%2e%2e/%2e%2e/.env"] [unique_id "aqnuKzUqr3keKSdXQGT1QwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
maxpower
2026-09-16 01:12:56
(1 day ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 35.237.20.192 (US/United States/192.20.2 ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 35.237.20.192 (US/United States/192.20.237.35.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 35.237.20.192 - - [16/Sep/2026:03:12:54 +0200] "GET /.aws/credentials HTTP/2.0" 403 146 "-" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" "35.237.20.192" host=cgilchieti.it
show less
Port Scan
๐ฌ๐ง
Marten Mark
2026-09-16 00:50:15
(1 day ago)
35.237.20.192 - - [16/Sep/2026:00:50:14 +0000] "GET /.aws/credentials HTTP/2.0" 404 22988 "-" "Mozil ...
show more
35.237.20.192 - - [16/Sep/2026:00:50:14 +0000] "GET /.aws/credentials HTTP/2.0" 404 22988 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)"
...
show less
Web App Attack
Bad Web Bot
๐ณ๐ฑ
Site.eu
2026-09-16 00:27:37
(1 day ago)
Excessive multi-domain requests
Brute-Force
๐ซ๐ท
regishoussin
2026-09-16 00:23:45
(1 day ago)
Automated web scanning detected by Wazuh (rule 100241): repeated 400/404 errors from mass probing of ...
show more
Automated web scanning detected by Wazuh (rule 100241): repeated 400/404 errors from mass probing of admin/backdoor paths (e.g. wp-login.php, known CMS shell filenames) on an Apache web server, on 2026-09-16 00:23 UTC.
show less
Bad Web Bot
Web App Attack