🇺🇸
TPI-Abuse
2026-09-13 01:23:54
(10 minutes ago)
(mod_security) mod_security (id:210730) triggered by 35.241.170.248 (248.170.241.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.241.170.248 (248.170.241.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 21:23:49.223670 2026] [security2:error] [pid 22448:tid 22448] [client 35.241.170.248:48250] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||thetribehouse.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "thetribehouse.com"] [uri "/z9x8c7v6b5-debug-trigger-thetribehouse.com"] [unique_id "aqX7Jf6SuvFL-6nSDS5sFwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
[email protected]
2026-09-13 01:15:53
(18 minutes ago)
Fail2Ban jail apache-json-scanners detected activity on 2026-09-13T01:15:53Z
Brute-Force
🇫🇷
✨
2026-09-13 01:07:12
(27 minutes ago)
Domain : ampersand-it.uk
Rule : admin
2026-09-13 01:04:02 217.194.212.5 GET /admin/login - 443 - 35. ...
show more
Domain : ampersand-it.uk
Rule : admin
2026-09-13 01:04:02 217.194.212.5 GET /admin/login - 443 - 35.241.170.248 HTTP/2.0 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36 - ampersand-it.uk 404 0 2 9069 823 62 - -
show less
Hacking
SQL Injection
Brute-Force
🇺🇸
TPI-Abuse
2026-09-13 01:06:10
(28 minutes ago)
(mod_security) mod_security (id:210492) triggered by 35.241.170.248 (248.170.241.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.241.170.248 (248.170.241.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 21:06:03.798736 2026] [security2:error] [pid 2352406:tid 2352492] [client 35.241.170.248:43752] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "amphoracollectors.org"] [uri "/api/.env/public/.env"] [unique_id "aqX2-9w7ItTN8CoJIPmSnwAAAJI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇬
Cloudkul Cloudkul
2026-09-13 01:05:36
(28 minutes ago)
Attempted Brute Force on our application
Brute-Force
Web App Attack
🇩🇪
XICTRON
2026-09-13 01:05:15
(29 minutes ago)
ModSecurity rule violation detected by Fail2Ban
Web App Attack
🇬🇧
andypiper
2026-09-13 01:02:15
(32 minutes ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
Anonymous
2026-09-13 00:37:19
(57 minutes ago)
apache vulnerability scan
Web App Attack
🇪🇸
elcruzado.es
2026-09-13 00:12:52
(1 hour ago)
(mod_security) mod_security triggered on hostname [redacted] 35.241.170.248 (BE/Belgium/248.170.241. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.241.170.248 (BE/Belgium/248.170.241.35.bc.googleusercontent.com)
show less
SQL Injection
🇫🇷
✨
2026-09-13 00:12:10
(1 hour ago)
Domain : redirect.netenergy.uk
Rule : env
2026-09-13 00:10:26 217.194.210.152 GET /config/.env - 443 ...
show more
Domain : redirect.netenergy.uk
Rule : env
2026-09-13 00:10:26 217.194.210.152 GET /config/.env - 443 - 35.241.170.248 HTTP/2 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1) - amies.org 404 0 2 1517 506 8 - -
show less
Hacking
SQL Injection
🇺🇸
TPI-Abuse
2026-09-13 00:03:50
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.241.170.248 (248.170.241.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.241.170.248 (248.170.241.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 20:03:42.114952 2026] [security2:error] [pid 30215:tid 30215] [client 35.241.170.248:46414] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "amgtr.com"] [uri "/@fs/var/task/.env"] [unique_id "aqXoXofd7nGUMKDxxzhligAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
[email protected]
2026-09-12 23:58:13
(1 hour ago)
Fail2Ban jail apache-json-scanners detected activity on 2026-09-12T23:58:13Z
Brute-Force
Anonymous
2026-09-12 23:53:08
(1 hour ago)
35.241.170.248 - - [12/Sep/2026:18:53:07 -0500] "GET /.env?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 Ap ...
show more
35.241.170.248 - - [12/Sep/2026:18:53:07 -0500] "GET /.env?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )" 35.241.170.248
35.241.170.248 - - [12/Sep/2026:18:53:07 -0500] "GET /.env?import&raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/)" 35.241.170.248
35.241.170.248 - - [12/Sep/2026:18:53:07 -0500] "GET /.env.local?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)" 35.241.170.248
35.241.170.248 - - [12/Sep/2026:18:53:07 -0500] "GET /.env?import&url&inline HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)" 35.241.170.248
35.241.170.248 - - [12/Sep/2026:18:53:07 -0500] "GET /.env.production?import&raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)" 35.241.170.248
35.241.170.248 - - [12/Sep/2026:18:53:07 -0500] "GET /.env.development?im
...
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
BlueWire Hosting
2026-09-12 23:50:14
(1 hour ago)
Bad bot ignoring robot.txt
Bad Web Bot
🇦🇺
rubixstudios
2026-09-12 23:43:02
(1 hour ago)
Excessive HTTP requests consistent with automated attack behaviour detected by Imunify360
DDoS Attack
Brute-Force
Web App Attack