๐บ๐ธ
TPI-Abuse
2026-09-01 13:49:28
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.241.228.138 (138.228.241.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.241.228.138 (138.228.241.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 09:49:22.712523 2026] [security2:error] [pid 10721:tid 10721] [client 35.241.228.138:35836] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.serranoscoffee.com"] [uri "/wp-config.php.swp"] [unique_id "apbX4klGm4kWsvz_jBkvcAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
CoreTech srl
2026-09-01 13:08:57
(2 hours ago)
cloudlinux2 fail2ban: 2026-09-01 15:06:24,175 fail2ban.actions [1605]: NOTICE [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-01 15:06:24,175 fail2ban.actions [1605]: NOTICE [plesk-modsecurity] Unban 97.97.236.74cloudlinux2 fail2ban: 2026-09-01 15:07:48,513 fail2ban.filter [1605]: INFO [plesk-modsecurity] Found 35.241.228.138 - 2026-09-01 15:07:48cloudlinux2 fail2ban: 2026-09-01 15:07:48,596 fail2ban.filter [1605]: INFO [plesk-modsecurity] Found 35.241.228.138 - 2026-09-01 15:07:48cloudlinux2 fail2ban: 2026-09-01 15:07:49,316 fail2ban.filter [1605]: INFO [plesk-modsecurity] Found 35.241.228.138 - 2026-09-01 15:07:49cloudlinux2 fail2ban: 2026-09-01 15:07:48,586 fail2ban.filter [1605]: INFO [plesk-modsecurity] Found 35.241.228.138 - 2026-09-01 15:07:48cloudlinux2 fail2ban: 2026-09-01 15:07:48,534 fail2ban.filter [1605]: INFO [plesk-modsecurity] Found 35.241.228.138 - 2026-09-01 15:07:48cloudlinux2 fail2ban: 2026-09-01 15:07:48,546 fail2ban.filter [1605]: INFO [plesk-modsecurity] Found 35.241.228.138 - 2026-09-01 15:07:48cloudlinux2
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-01 11:16:44
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.241.228.138 (138.228.241.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.241.228.138 (138.228.241.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 07:16:39.310529 2026] [security2:error] [pid 11402:tid 11402] [client 35.241.228.138:59532] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.vigants.com"] [uri "/.env"] [unique_id "apa0F6_pq2RlycYr1UdiGAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-09-01 10:53:19
(4 hours ago)
[01/Sep/2026:13:53:18 +0300] -- 35.241.228.138 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET ...
show more
[01/Sep/2026:13:53:18 +0300] -- 35.241.228.138 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /.env HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 10:49:27
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.241.228.138 (138.228.241.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.241.228.138 (138.228.241.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 06:49:23.641949 2026] [security2:error] [pid 226456:tid 226577] [client 35.241.228.138:57136] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ozworkshop.aussiepens.com"] [uri "/.env.production"] [unique_id "apatsyrdEraH6Tx-Bu-hTwAAAQY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
pscriptos
2026-09-01 09:26:07
(6 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ณ๐ฑ
e.fierstra
2026-09-01 08:23:26
(7 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ช๐ธ
masterguru
2026-09-01 07:56:54
(7 hours ago)
Inbound Anomaly Score Exceeded (Total Score: 10). Operator GE matched 5 at TX:anomaly_score. (949110 ...
show more
Inbound Anomaly Score Exceeded (Total Score: 10). Operator GE matched 5 at TX:anomaly_score. (949110-122)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-01 07:47:05
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.241.228.138 (138.228.241.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.241.228.138 (138.228.241.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 03:46:58.541703 2026] [security2:error] [pid 22150:tid 22150] [client 35.241.228.138:54130] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "glitchrpg.abraxasstudio.com"] [uri "/.env.old"] [unique_id "apaC8sycy6XxGXgDiaNiwQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 07:12:23
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.241.228.138 (138.228.241.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.241.228.138 (138.228.241.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 03:12:14.741144 2026] [security2:error] [pid 5504:tid 5504] [client 35.241.228.138:60524] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mlbechler.com"] [uri "/.env.prod"] [unique_id "apZ6zn4VSNMEbrXzvk2TDAAAACo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Hazzard
2026-09-01 07:10:30
(8 hours ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-09-01 06:41:11
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.241.228.138 (138.228.241.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.241.228.138 (138.228.241.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 02:41:06.773898 2026] [security2:error] [pid 26940:tid 26940] [client 35.241.228.138:51856] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "taschstudios.com.saadeh.ws"] [uri "/.env.prod"] [unique_id "apZzggP7k36TyDEc3GXViAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
todix
2026-09-01 06:26:24
(9 hours ago)
Web App Attack Exploid from 35.241.228.138
Web App Attack
๐ฉ๐ช
raph
2026-09-01 06:25:57
(9 hours ago)
[Wordpress] crawler /wp-admin/*, /wp-content/*, etc.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 06:08:06
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.241.228.138 (138.228.241.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.241.228.138 (138.228.241.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 02:07:58.304564 2026] [security2:error] [pid 30441:tid 30441] [client 35.241.228.138:55520] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.aacoustics.com"] [uri "/.env.save"] [unique_id "apZrvmx9e0FR-0IFHqQAjwAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack