🇺🇸
TPI-Abuse
2026-09-08 20:03:43
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.239.11.51 (51.11.239.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.239.11.51 (51.11.239.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 16:03:35.106482 2026] [security2:error] [pid 21835:tid 21835] [client 35.239.11.51:15192] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.csmedicalbilling.com"] [uri "/@fs/.env"] [unique_id "aqBqF9jHdnhuJd6T4SzlBgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 19:42:12
(3 hours ago)
Bot / seems abusive / Apache connections: 34
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 19:22:18
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.239.11.51 (51.11.239.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.239.11.51 (51.11.239.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 15:22:15.036189 2026] [security2:error] [pid 15019:tid 15019] [client 35.239.11.51:18908] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.title39.com"] [uri "/@fs/app/.env"] [unique_id "aqBgZwUoRGN9jRGpJ3f_2wAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 18:40:08
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.239.11.51 (51.11.239.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.239.11.51 (51.11.239.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 14:40:00.234363 2026] [security2:error] [pid 1077:tid 1088] [client 35.239.11.51:46294] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.jsbarber.com"] [uri "/@fs/src/.env"] [unique_id "aqBWgNMm2WgHaPfHufJ1xwAAAMU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 18:22:27
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.239.11.51 (51.11.239.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.239.11.51 (51.11.239.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 14:22:22.745273 2026] [security2:error] [pid 4382:tid 4382] [client 35.239.11.51:10448] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.ferareta.com.ar"] [uri "/@fs/src/.env"] [unique_id "aqBSXn-7YHglIaYYzmDkuQAAACo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-09-08 18:05:50
(5 hours ago)
Scanning/Probing (27)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 17:58:58
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.239.11.51 (51.11.239.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.239.11.51 (51.11.239.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 13:58:52.839395 2026] [security2:error] [pid 16296:tid 16296] [client 35.239.11.51:21774] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.performingartsguild.com"] [uri "/@fs/root/.env"] [unique_id "aqBM3BtCq0WtG2wUKOrm_AAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
cmbplf
2026-09-08 17:38:33
(5 hours ago)
591 requests with url.path *.azure/*
149 requests with url.path */auth.json
Brute-Force
Bad Web Bot
Anonymous
2026-09-08 17:19:49
(6 hours ago)
Aggressive web scan
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 17:12:32
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.239.11.51 (51.11.239.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.239.11.51 (51.11.239.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 13:12:25.297714 2026] [security2:error] [pid 24048:tid 24048] [client 35.239.11.51:27022] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.houseofbates.net"] [uri "/@fs/root/.env"] [unique_id "aqBB-fEcISRqt-to_WR97QAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-08 16:57:23
(6 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 16:33:51
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.239.11.51 (51.11.239.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.239.11.51 (51.11.239.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 12:33:45.841244 2026] [security2:error] [pid 1339:tid 1379] [client 35.239.11.51:44846] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.volcano-sa.com"] [uri "/@fs/app/.env"] [unique_id "aqA46QrP3EOguvVEFYqxqgAAAYs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
agenciahypelab.com.br
2026-09-08 16:33:16
(7 hours ago)
WordPress login brute-force detectado e bloqueado pelo CSF/LFD. Trigger: LF_TRIGGER
Brute-Force
SSH
🇺🇸
IndigoRidge
2026-09-08 16:14:58
(7 hours ago)
[08/Sep/2026:12:14:57.628279 --0400] aqA0gTuZA-9ZsEGSkBMxzwAAAUY 35.239.11.51 57760 205.233.18.17 70 ...
show more
[08/Sep/2026:12:14:57.628279 --0400] aqA0gTuZA-9ZsEGSkBMxzwAAAUY 35.239.11.51 57760 205.233.18.17 7081
[08/Sep/2026:12:14:57.629345 --0400] aqA0gbsx3xrnKUq-3xTKLQAAAEk 35.239.11.51 57790 205.233.18.17 7081
[08/Sep/2026:12:14:57.629761 --0400] aqA0gTuZA-9ZsEGSkBMx0AAAAVc 35.239.11.51 57800 205.233.18.17 7081
[08/Sep/2026:12:14:57.636648 --0400] aqA0gYgBOgIwJ-r2O@IbpAAAAJQ 35.239.11.51 57870 205.233.18.17 7081
[08/Sep/2026:12:14:57.640020 --0400] aqA0gS9C42XMggPeJdxzfgAAAAE 35.239.11.51 57844 205.233.18.17 7081
...
show less
Hacking
🇫🇷
dynamix
2026-09-08 16:12:59
(7 hours ago)
Multiple WAF Violations
Web App Attack