π·πΊ
DZBOT
2026-09-21 06:40:27
(1 day ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 06:21:52
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.237.228.8 (8.228.237.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.237.228.8 (8.228.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 02:21:48.474553 2026] [security2:error] [pid 7865:tid 7865] [client 35.237.228.8:36508] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.eagrant.com|F|2"] [data ".eagrant.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.eagrant.com"] [uri "/z9x8c7v6b5-debug-trigger-www.eagrant.com"] [unique_id "arDM_GXqJRJs-tCsLeWB9wAAADg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 06:05:59
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.237.228.8 (8.228.237.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.228.8 (8.228.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 02:05:51.373441 2026] [security2:error] [pid 1332:tid 1332] [client 35.237.228.8:51868] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.eileensharaga.com"] [uri "/%2e%2e/%2e%2e/%2e%2e/%2e%2e/.env"] [unique_id "arDJPy_Pyk7Hlk8luD2rpgAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
ecode hosting
2026-09-21 05:08:05
(1 day ago)
Domain : ecodehost.com
Rule : env
2026-09-21 05:06:01 10.100.1.20 GET /client/.env - 443 - 35.237.22 ...
show more
Domain : ecodehost.com
Rule : env
2026-09-21 05:06:01 10.100.1.20 GET /client/.env - 443 - 35.237.228.8 HTTP/2 Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; https://kimi.ai/) - www.ecodehost.com 401 4 5 1293 399 154 - -
show less
Hacking
SQL Injection
πΊπΈ
TPI-Abuse
2026-09-21 05:07:50
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.237.228.8 (8.228.237.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.228.8 (8.228.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 01:07:42.863309 2026] [security2:error] [pid 28626:tid 28626] [client 35.237.228.8:40816] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.ehrlichfamily.com"] [uri "/.git/config"] [unique_id "arC7nud5ChPdxEHyAiWwhAAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Site.eu
2026-09-21 04:57:00
(1 day ago)
Excessive multi-domain requests
Brute-Force
πΊπΈ
TPI-Abuse
2026-09-21 04:43:05
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.237.228.8 (8.228.237.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.228.8 (8.228.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 00:43:00.291092 2026] [security2:error] [pid 18665:tid 18665] [client 35.237.228.8:54052] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.dungeonsremastered.com"] [uri "/deploy/.env"] [unique_id "arC11J2gi1tY085h-FqZLQAAAC0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
mnsf
2026-09-21 04:06:23
(1 day ago)
Abuse Detected (1)
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 04:02:33
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.237.228.8 (8.228.237.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.228.8 (8.228.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 00:02:27.518537 2026] [security2:error] [pid 5627:tid 5627] [client 35.237.228.8:43208] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.efsews.com"] [uri "/shop/.env"] [unique_id "arCsU4qW55Bqpq6SglnRWQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
WeCloudit-Anti-Abuse
2026-09-21 03:13:43
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
πΊπΈ
TPI-Abuse
2026-09-21 03:05:30
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.237.228.8 (8.228.237.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.228.8 (8.228.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 23:05:25.482635 2026] [security2:error] [pid 27876:tid 27876] [client 35.237.228.8:56580] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.my-spec.com"] [uri "/.git/config"] [unique_id "arCe9SMkwMa7XyGWskO0FgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 01:27:12
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.237.228.8 (8.228.237.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.228.8 (8.228.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 21:27:08.848558 2026] [security2:error] [pid 10823:tid 10823] [client 35.237.228.8:56070] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.cajunfriedturkey.com"] [uri "/.git/HEAD"] [unique_id "arCH7CgOAqDdsboa-q5LXQAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
WeCloudit-Anti-Abuse
2026-09-21 01:20:28
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
πΊπΈ
TPI-Abuse
2026-09-21 01:10:41
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.237.228.8 (8.228.237.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.228.8 (8.228.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 21:10:35.075875 2026] [security2:error] [pid 19287:tid 19287] [client 35.237.228.8:45820] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.ebizplayers.com"] [uri "/.git/HEAD"] [unique_id "arCEC8rig2M1WyRcK57oswAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 00:54:10
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.237.228.8 (8.228.237.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.228.8 (8.228.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 20:54:05.006390 2026] [security2:error] [pid 2274:tid 2274] [client 35.237.228.8:58302] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.edgewatertaxidermy.com"] [uri "/api/.env"] [unique_id "arCALbEIa5POBWtGCbYsGAAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack