๐บ๐ธ
inderiva6
2026-09-29 13:25:21
(1 day ago)
Automated HTTP(S) attack blocked by first-party WAF. FirstSeen=2026-09-29T13:24:33Z; LastSeen=2026-0 ...
show more
Automated HTTP(S) attack blocked by first-party WAF. FirstSeen=2026-09-29T13:24:33Z; LastSeen=2026-09-29T13:25:21Z; Requests=209; EvidenceHits=209; DistinctPaths=209; Methods=GET; Rules=scanner:209; SamplePaths=/.env|/.env.backup|/.env.backup1|/.env.backup2|/.env.bak; LogDigest=c1fa8ce4e99fd78e9420178ff6df5d47bf401c3ff0eb7b70255557754ba08cb8.
show less
Hacking
Web App Attack
Anonymous
2026-09-29 12:03:31
(1 day ago)
35.240.212.135 - - [29/Sep/2026:12:03:30 +0000] "GET /mailer/.env HTTP/1.1" 404 181 "-" "Mozilla/5.0 ...
show more
35.240.212.135 - - [29/Sep/2026:12:03:30 +0000] "GET /mailer/.env HTTP/1.1" 404 181 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.240.212.135 - - [29/Sep/2026:12:03:30 +0000] "GET /mail/.env HTTP/1.1" 404 181 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
dbmwebdesign
2026-09-29 08:55:13
(1 day ago)
Repeated probing for non-existent PHP exploit paths blocked by Fail2Ban
Web App Attack
๐ฉ๐ช
dbmwebdesign
2026-09-29 08:35:14
(1 day ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 07:07:56
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.240.212.135 (135.212.240.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.240.212.135 (135.212.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 03:07:50.948765 2026] [security2:error] [pid 4611:tid 4638] [client 35.240.212.135:41876] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "allstartaxidermy.com"] [uri "/.git/config"] [unique_id "artjxt-xYQtcVfb7C8ESBgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 04:20:21
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.240.212.135 (135.212.240.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.240.212.135 (135.212.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 00:20:16.389246 2026] [security2:error] [pid 3492:tid 3492] [client 35.240.212.135:48526] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "allseniorsolutions.com"] [uri "/.git/config"] [unique_id "ars8gGY85jtZa65ualgJyQAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Secure Gatewayยฎ๏ธ
2026-09-28 22:00:30
(1 day ago)
Report By Secure Gateway Security Team: XSS Injection Attempt Detected
SQL Injection
๐บ๐ธ
ALSCOยฎ๏ธ
2026-09-28 22:00:30
(1 day ago)
Report By ALSCO Security Team: Unauthorized Connection Attempt
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-09-26 15:15:23
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.240.212.135 (135.212.240.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.240.212.135 (135.212.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 11:15:19.488068 2026] [security2:error] [pid 21868:tid 21868] [client 35.240.212.135:51526] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.numbulary.com"] [uri "/.git/config"] [unique_id "arfhhxi-PSUX5PhJj5yoJwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-23 20:38:07
(6 days ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-09-22 06:57:22
(1 week ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-21 21:29:31
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.240.212.135 (135.212.240.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.240.212.135 (135.212.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 17:29:27.384237 2026] [security2:error] [pid 8874:tid 8874] [client 35.240.212.135:50080] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aluthienproperties.com"] [uri "/.git/config"] [unique_id "arGht6hUN06SI_Q1jKamUAAAAC8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-21 06:14:17
(1 week ago)
Fail2Ban: 2026/09/21 06:14:16 [info] 6598#6598: *12782 client sent no required SSL certificate while ...
show more
Fail2Ban: 2026/09/21 06:14:16 [info] 6598#6598: *12782 client sent no required SSL certificate while reading client request headers, client: 35.240.212.135, server: dash.ddns.schauwecker.eu, request: "GET / HTTP/1.1", host: "dash.ddns.schauwecker.eu"
2026/09/21 06:14:16 [info] 6598#6598: *12783 client sent no required SSL certificate while reading client request headers, client: 35.240.212.135, server: dash.ddns.schauwecker.eu, request: "POST / HTTP/1.1", host: "dash.ddns.schauwecker.eu"
2026/09/21 06:14:17 [info] 6598#6598: *12784 client sent no required SSL certificate while reading client request headers, client: 35.240.212.135, server: dash.ddns.schauwecker.eu, request: "POST / HTTP/1.1", host: "dash.ddns.schauwecker.eu"
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-21 05:38:37
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.240.212.135 (135.212.240.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.240.212.135 (135.212.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 01:38:31.808280 2026] [security2:error] [pid 14205:tid 14285] [client 35.240.212.135:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.humanet.io"] [uri "/.git/config"] [unique_id "arDC18rOIQOG4IaldDQUvAAAAZE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-09-20 16:35:04
(1 week ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack