๐บ๐ธ
TPI-Abuse
2026-09-20 15:36:12
(36 minutes ago)
(mod_security) mod_security (id:210492) triggered by 35.243.150.27 (27.150.243.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.243.150.27 (27.150.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 11:36:07.608291 2026] [security2:error] [pid 10489:tid 10552] [client 35.243.150.27:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "raytbrown.com"] [uri "/tmp/.env"] [unique_id "aq_9Z2MtvIykVLFTU32y-wAAAUQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Stara
2026-09-20 15:29:39
(43 minutes ago)
ModSecurity detected web attack - .env/config probing or SQLi/Code injection (Rule 949110)
Brute-Force
Hacking
Web App Attack
๐ฉ๐ช
IVski.com
2026-09-20 14:38:33
(1 hour ago)
IVski WAF | Vite /@fs/ CVE-2025-30208 file-read scan
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
robotstxt
2026-09-20 14:37:41
(1 hour ago)
35.243.150.27 - - [20/Sep/2026:14:36:37 +0000] "GET /.bash_profile HTTP/2.0" 403 17813 "-" "Mozilla/ ...
show more
35.243.150.27 - - [20/Sep/2026:14:36:37 +0000] "GET /.bash_profile HTTP/2.0" 403 17813 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36" "-" edge="35.243.150.27"
35.243.150.27 - - [20/Sep/2026:14:36:37 +0000] "GET /.profile HTTP/2.0" 403 17813 "-" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)" "-" edge="35.243.150.27"
35.243.150.27 - - [20/Sep/2026:14:36:38 +0000] "GET /@fs/../.env?raw?? HTTP/2.0" 403 17813 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)" "-" edge="35.243.150.27"
35.243.150.27 - - [20/Sep/2026:14:36:38 +0000] "GET /@fs/src/.env?raw?? HTTP/2.0" 403 17813 "-" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)" "-" edge="35.243.150.27"
35.243.150.27 - - [20/Sep/2026:14:36:38 +0000] "GET /_nuxt/../.env HTTP/2.0" 403 17813 "-" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" "-" edge="35.243.150.27"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 14:35:07
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.243.150.27 (27.150.243.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.243.150.27 (27.150.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 10:34:58.224026 2026] [security2:error] [pid 11409:tid 11409] [client 35.243.150.27:41882] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "indie100.com"] [uri "/model/.env"] [unique_id "aq_vEr__BjSId1FPnZ3rVgAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 14:16:35
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.243.150.27 (27.150.243.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.243.150.27 (27.150.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 10:16:29.653850 2026] [security2:error] [pid 27844:tid 27844] [client 35.243.150.27:50574] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "getitenglish.com"] [uri "/src/.env"] [unique_id "aq_qvbSHDNkONs6cThI7eQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-09-20 13:57:07
(2 hours ago)
csagent: score 20.4: secrets grab x2, 404 noise floor x2; 1 domain(s) in 5s
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 13:46:23
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.243.150.27 (27.150.243.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.243.150.27 (27.150.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 09:46:17.506801 2026] [security2:error] [pid 10095:tid 10099] [client 35.243.150.27:39348] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "danfriel.com"] [uri "/build/.env"] [unique_id "aq_jqXFmCuI-OtmwC46KaQAAAEE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 13:23:02
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.243.150.27 (27.150.243.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.243.150.27 (27.150.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 09:22:56.356806 2026] [security2:error] [pid 10687:tid 10687] [client 35.243.150.27:38980] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||blackjobsnetwork.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "blackjobsnetwork.com"] [uri "/z9x8c7v6b5-debug-trigger-blackjobsnetwork.com"] [unique_id "aq_eMIgDal47bjE6zS5ZAgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 12:56:40
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.243.150.27 (27.150.243.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.243.150.27 (27.150.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 08:56:36.796906 2026] [security2:error] [pid 18922:tid 18922] [client 35.243.150.27:43768] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||altermondo.com|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "altermondo.com"] [uri "/server.key"] [unique_id "aq_YBEsvVsw7rThPuTR1UQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-09-20 12:55:04
(3 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ฌ๐ง
abivia
2026-09-20 12:54:08
(3 hours ago)
Abivia WAF trigger: Rule scriptKiddies: Credential probing uri: /__/firebase/init.json
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-20 12:41:21
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.243.150.27 (27.150.243.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.243.150.27 (27.150.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 08:41:13.380094 2026] [security2:error] [pid 25637:tid 25637] [client 35.243.150.27:59682] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "15cherryavenue.com"] [uri "/ai/.env"] [unique_id "aq_UaVohFoUP4z0WIoZpoQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
xmission.com
2026-09-20 12:30:45
(3 hours ago)
Blocked by UFW (TCP on 8443)
Source port: 43332
TTL: 60
Packet length: 60
TOS: 0x00
This report (fo ...
show more
Blocked by UFW (TCP on 8443)
Source port: 43332
TTL: 60
Packet length: 60
TOS: 0x00
This report (for 35.243.150.27) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan