🇩🇪
rh24
2026-09-13 22:48:12
(4 hours ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 35.240.111.50 (BE/Be ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 35.240.111.50 (BE/Belgium/50.111.240.35.bc.googleusercontent.com)
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-13 20:56:30
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.240.111.50 (50.111.240.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.240.111.50 (50.111.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 16:56:25.770832 2026] [security2:error] [pid 7283:tid 7283] [client 35.240.111.50:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "haywardcarpentry.com"] [uri "/.env"] [unique_id "aqcN-YoUeLrnO7MGXfDUhAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
neckaralb-admin.de
2026-09-13 19:13:09
(8 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 17:49:51
(9 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.240.111.50 (50.111.240.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.240.111.50 (50.111.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 13:49:47.313388 2026] [security2:error] [pid 14383:tid 14383] [client 35.240.111.50:38166] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||handcraftedparquet.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "handcraftedparquet.com"] [uri "/z9x8c7v6b5-debug-trigger-handcraftedparquet.com"] [unique_id "aqbiO8hPUoUPdjrFmhKUOQAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
Epimetheus
2026-09-13 15:00:49
(12 hours ago)
Zombie network / Bot scanner detected:
[POST] /read-document
[GET] /graphql/console
[GET] /app_dev. ...
show more
Zombie network / Bot scanner detected:
[POST] /read-document
[GET] /graphql/console
[GET] /app_dev.php
[GET] /wp-json
[GET] /api/v1/settings
[GET] /@fs/app/.env
[GET] /.idea/WebServers.xml
[GET] /.env.old
[GET] /config/firebase-admin.json
[GET] /.env.development
[GET] /wp-config.php.swp
UA: Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)
show less
Bad Web Bot
Exploited Host
Web App Attack
🇺🇸
Epimetheus
2026-09-13 14:44:36
(12 hours ago)
Zombie network / Bot scanner detected:
[GET] /service-account.json
[GET] /firebase-service-account. ...
show more
Zombie network / Bot scanner detected:
[GET] /service-account.json
[GET] /firebase-service-account.json
[GET] /.git-credentials
[GET] /gcp-key.json
[GET] /config.php.bak
[GET] /config/application.properties
[GET] /@fs/app/.env.local
[GET] /.env.local
[GET] /account
[GET] /images../.env
[POST] /v1/graphql
UA: Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)
show less
Bad Web Bot
Exploited Host
Web App Attack
🇪🇸
masterguru
2026-09-13 14:15:16
(13 hours ago)
BAD BOT - Detected and Blocked.. Matched phrase "PerplexityBot" at REQUEST_HEADERS:user-agent. (1100 ...
show more
BAD BOT - Detected and Blocked.. Matched phrase "PerplexityBot" at REQUEST_HEADERS:user-agent. (1100000-122)
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-13 13:57:10
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.240.111.50 (50.111.240.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.240.111.50 (50.111.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 09:57:04.180865 2026] [security2:error] [pid 29194:tid 29194] [client 35.240.111.50:36974] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gunningphysio.com"] [uri "/@fs/proc/self/cwd/.env"] [unique_id "aqarsNcpjOh4XOvC5CH1CAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 13:33:40
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.240.111.50 (50.111.240.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.240.111.50 (50.111.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 09:33:34.892711 2026] [security2:error] [pid 14707:tid 14728] [client 35.240.111.50:44450] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "guitarmans.com"] [uri "/api/.env"] [unique_id "aqamLtcdyJ5P5mzQ5qsAFgAAAJI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-09-13 13:15:03
(14 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 13:11:53
(14 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.240.111.50 (50.111.240.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.240.111.50 (50.111.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 09:11:48.426780 2026] [security2:error] [pid 2151:tid 2151] [client 35.240.111.50:57912] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||guarinofurnituredesigns.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "guarinofurnituredesigns.com"] [uri "/z9x8c7v6b5-debug-trigger-guarinofurnituredesigns.com"] [unique_id "aqahFGqMGe9pLZ88yhTOzQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 12:46:04
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.240.111.50 (50.111.240.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.240.111.50 (50.111.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 08:45:57.901054 2026] [security2:error] [pid 18623:tid 18623] [client 35.240.111.50:47108] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gslministries.com"] [uri "/.env"] [unique_id "aqabBXpVVVCF_4I04oZ-5wAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-13 12:35:46
(15 hours ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
Anonymous
2026-09-13 12:30:01
(15 hours ago)
suspicious request in access.log
Web App Attack
Anonymous
2026-09-13 12:27:35
(15 hours ago)
Banned by Fail2Ban on server
Web App Attack