๐บ๐ธ
TPI-Abuse
2026-09-01 14:05:43
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.237.48.6 (6.48.237.35.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.48.6 (6.48.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 10:05:36.430766 2026] [security2:error] [pid 31824:tid 31824] [client 35.237.48.6:39878] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.rendermatrix.com"] [uri "/.env.backup"] [unique_id "apbbsHGHhlFQvUqAxzbh3AAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 12:47:11
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.237.48.6 (6.48.237.35.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.48.6 (6.48.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 08:47:06.958802 2026] [security2:error] [pid 11806:tid 11806] [client 35.237.48.6:55940] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cfcameron.cygnetsilks.com"] [uri "/.env.production"] [unique_id "apbJSnGX-ATuAgaaCK-UdgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-01 12:39:58
(2 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐ซ๐ท
Baking333
2026-09-01 12:39:55
(2 hours ago)
[redacted] 35.237.48.6 - - [01/Sep/2026:13:39:54 +0100] "GET /.[redacted] HTTP/1.1" 302 1528 0/43063 ...
show more
[redacted] 35.237.48.6 - - [01/Sep/2026:13:39:54 +0100] "GET /.[redacted] HTTP/1.1" 302 1528 0/43063 "-" "crusader-worker/1.0" [redacted] 35.237.48.6 - - [01/Sep/2026:13:39:54 +0100] "GET /.[redacted] HTTP/1.1" 302 1528 0/55438 "-" "crusader-worker/1.0" [redacted] 35.237.48.6 - - [01/Sep/2026:13:39:54 +0100] "GET /.[redacted] HTTP/1.1" 302 1528 0/49537 "-" "crusader-worker/1.0"
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-01 12:19:49
(2 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
๐ซ๐ท
mail.avx.gr
2026-09-01 11:25:02
(3 hours ago)
(nginxCONFIGSCAN) nginx configuration-file scanner detected from 35.237.48.6 (US/United States/South ...
show more
(nginxCONFIGSCAN) nginx configuration-file scanner detected from 35.237.48.6 (US/United States/South Carolina/North Charleston/6.48.237.35.bc.googleusercontent.com)
show less
Hacking
๐ฉ๐ช
raph
2026-09-01 11:19:36
(3 hours ago)
[Wordpress] crawler /wp-admin/*, /wp-content/*, etc.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 10:59:03
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.237.48.6 (6.48.237.35.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.48.6 (6.48.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 06:58:55.094723 2026] [security2:error] [pid 12294:tid 12294] [client 35.237.48.6:39286] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.doctorspainmanagement.com"] [uri "/.env.backup"] [unique_id "apav78uWmKjE-QPqX07f1wAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-09-01 10:55:38
(4 hours ago)
[TueSep0112:55:32.2731312026][security2:error][pid4075409:tid4075465][client35.237.48.6:0]ModSecurit ...
show more
[TueSep0112:55:32.2731312026][security2:error][pid4075409:tid4075465][client35.237.48.6:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"webdisk.gmint.ch\"][uri\"/.env.bak\"][unique_id\"apavJAOMxCQ8V14NNBayRgAAAFQ\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ธ๐ช
SkyDancer
2026-09-01 09:56:28
(5 hours ago)
Multiple unauthorized attempts to access using wrong credentials. Attack automatically blocked by Sk ...
show more
Multiple unauthorized attempts to access using wrong credentials. Attack automatically blocked by SkyDancer Ai. EXT-SYS-Vx
show less
Hacking
Brute-Force
SSH
๐ฉ๐ช
maxpower
2026-09-01 09:45:38
(5 hours ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 35.237.48.6 (US/United States/6.48.237.3 ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 35.237.48.6 (US/United States/6.48.237.35.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 35.237.48.6 - - [01/Sep/2026:11:45:35 +0200] "GET /wp-config.php.bak HTTP/1.1" 403 146 "-" "crusader-worker/1.0" "-" host=spazioitaliaarteinmovimento.it
show less
Port Scan
๐ซ๐ท
masterguru
2026-09-01 09:34:41
(5 hours ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 35.237.48.6 (US/United States/6.48.23 ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 35.237.48.6 (US/United States/6.48.237.35.bc.googleusercontent.com): 2 in the last 3600 secs (0-196)
show less
Hacking
๐ฉ๐ช
wpadm4
2026-09-01 09:31:35
(5 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐บ๐ธ
Lee Daniel
2026-09-01 09:20:01
(5 hours ago)
35.237.48.6 - - [01/Sep/2026:05:20:00 -0400] "GET /.env HTTP/1.1" 403 6271 "-" "crusader-worker/1.0" ...
show more
35.237.48.6 - - [01/Sep/2026:05:20:00 -0400] "GET /.env HTTP/1.1" 403 6271 "-" "crusader-worker/1.0"
...
show less
DDoS Attack
Web Spam
Email Spam
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 08:47:02
(6 hours ago)
(mod_security) mod_security (id:949110) triggered by 35.237.48.6 (6.48.237.35.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:949110) triggered by 35.237.48.6 (6.48.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 04:46:56.513816 2026] [security2:error] [pid 15901:tid 15901] [client 35.237.48.6:38798] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "servicesafes.com"] [uri "/.env.example"] [unique_id "apaRAONKJdulNleHnpfu4gAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack