๐ฉ๐ช
Bedios GmbH
2026-09-21 06:21:25
(1 day ago)
Wordpress hacking attempt
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 05:14:05
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.240.235.87 (87.235.240.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.240.235.87 (87.235.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 01:13:57.972543 2026] [security2:error] [pid 22498:tid 22498] [client 35.240.235.87:42796] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.msbasile.com"] [uri "/.git/HEAD"] [unique_id "arC9FXQhAk0nX6bfkaooWgAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-21 05:13:27
(1 day ago)
35.240.235.87 - - [21/Sep/2026:07:13:26 +0200] "GET /.git/config HTTP/2.0" 301 169 "-" "CCBot/2.0 (h ...
show more
35.240.235.87 - - [21/Sep/2026:07:13:26 +0200] "GET /.git/config HTTP/2.0" 301 169 "-" "CCBot/2.0 (https:///faq/)"
show less
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-21 04:38:45
(1 day ago)
Excessive 404/403 errors
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-21 04:34:54
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.240.235.87 (87.235.240.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.240.235.87 (87.235.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 00:34:48.770395 2026] [security2:error] [pid 22980:tid 22980] [client 35.240.235.87:36186] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.yeswecanhandyservices.com"] [uri "/.git/config"] [unique_id "arCz6JJ0vElzOTfl2vp8kgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 04:19:11
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.240.235.87 (87.235.240.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.240.235.87 (87.235.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 00:19:07.496377 2026] [security2:error] [pid 30470:tid 30470] [client 35.240.235.87:36848] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.my-spec.com"] [uri "/@fs/../.env"] [unique_id "arCwO7TPfU8jMdFOIly4wgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 03:57:19
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.240.235.87 (87.235.240.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.240.235.87 (87.235.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 23:57:12.147256 2026] [security2:error] [pid 19486:tid 19486] [client 35.240.235.87:42718] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.musicfreakcentral.com"] [uri "/js../.env"] [unique_id "arCrGNK9lb1O80Ew85iBjgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-21 03:39:14
(1 day ago)
[ns1.skdns.gr] httpd-suspicious-path: iis-w3c
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 03:27:16
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.240.235.87 (87.235.240.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.240.235.87 (87.235.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 23:27:10.605708 2026] [security2:error] [pid 22497:tid 22497] [client 35.240.235.87:58094] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.bridgital.com"] [uri "/laravel/.env"] [unique_id "arCkDnnWOpuW662J4hvt4gAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 02:53:23
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.240.235.87 (87.235.240.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.240.235.87 (87.235.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 22:53:16.698453 2026] [security2:error] [pid 8897:tid 8897] [client 35.240.235.87:32834] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.myrtlebeachpartybuses.com"] [uri "/images../.env"] [unique_id "arCcHJfyMQqqBIEwhGe1dAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-21 02:47:13
(2 days ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
Anonymous
2026-09-21 02:23:59
(2 days ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 02:06:16
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.240.235.87 (87.235.240.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.240.235.87 (87.235.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 22:06:09.333906 2026] [security2:error] [pid 22718:tid 22742] [client 35.240.235.87:56370] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.destination-kitchen.com"] [uri "/css../.env"] [unique_id "arCREfvsD4R7ArMTCrnWCAAAARY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
palzer.IT
2026-09-21 00:49:20
(2 days ago)
Fail2ban automatic report for plesk-apache-badbot: 35.240.235.87 - - [21/Sep/2026:02:48:58 +0200] GE ...
show more
Fail2ban automatic report for plesk-apache-badbot: 35.240.235.87 - - [21/Sep/2026:02:48:58 +0200] GET /admin/.env [DOMAIN_REMOVED] 404 34570 - Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; +claudebot@[DOMAIN_REMOVED])
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-20 23:23:51
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 35.240.235.87 (87.235.240.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.240.235.87 (87.235.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 19:23:46.548922 2026] [security2:error] [pid 20535:tid 20535] [client 35.240.235.87:56674] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.effectivefirearms.com|F|2"] [data ".effectivefirearms.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.effectivefirearms.com"] [uri "/z9x8c7v6b5-debug-trigger-www.effectivefirearms.com"] [unique_id "arBrAjTtP_5iwWd6pL4gmwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack