๐บ๐ธ
TPI-Abuse
2026-08-26 01:44:27
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.243.158.138 (138.158.243.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.243.158.138 (138.158.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 21:44:22.642718 2026] [security2:error] [pid 22641:tid 22641] [client 35.243.158.138:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.globetechsecurities.com"] [uri "/.git/config"] [unique_id "ao5E9lfVmCxuoDCrxJf01wAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 00:03:17
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.243.158.138 (138.158.243.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.243.158.138 (138.158.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 20:03:09.954860 2026] [security2:error] [pid 9155:tid 9155] [client 35.243.158.138:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.ndanetworks.com"] [uri "/.git/config"] [unique_id "ao4tPRegTUTMKn9mg0jGgQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 22:14:12
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.243.158.138 (138.158.243.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.243.158.138 (138.158.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 18:14:08.146316 2026] [security2:error] [pid 30863:tid 30863] [client 35.243.158.138:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.poweribo.com"] [uri "/.git/config"] [unique_id "ao4TsD4uD1NdqTMDxS3dawAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-08-25 11:55:06
(16 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 10:48:56
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.243.158.138 (138.158.243.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.243.158.138 (138.158.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 06:48:52.078480 2026] [security2:error] [pid 12457:tid 12457] [client 35.243.158.138:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.livingawakenedbook.com"] [uri "/.openclaw/.env"] [unique_id "ao1zFCvXizMcN9hCIok4DwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
polycoda
2026-08-25 06:30:16
(21 hours ago)
AutoBlock: ๐ก Port Scan (Non Decay-Based)
Port Scan
๐ฉ๐ช
itsolon
2026-08-24 23:21:42
(1 day ago)
[25/Aug/2026:01:21:41 +0200] 178761370117.246413 35.243.158.138 42778 217.154.7.177 443
[25/Aug/2026 ...
show more
[25/Aug/2026:01:21:41 +0200] 178761370117.246413 35.243.158.138 42778 217.154.7.177 443
[25/Aug/2026:01:21:41 +0200] 178761370157.681437 35.243.158.138 42778 217.154.7.177 443
[25/Aug/2026:01:21:41 +0200] 178761370126.932272 35.243.158.138 42778 217.154.7.177 443
[25/Aug/2026:01:21:41 +0200] 178761370199.747385 35.243.158.138 42778 217.154.7.177 443
[25/Aug/2026:01:21:42 +0200] 178761370296.788238 35.243.158.138 42778 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
chronos
2026-08-24 21:12:14
(1 day ago)
[AUTORAVALT][[24/08/2026 - 18:12:14 -03:00 UTC]
Attack from [Google LLC]
[35.243.158.138][138.158.24 ...
show more
[AUTORAVALT][[24/08/2026 - 18:12:14 -03:00 UTC]
Attack from [Google LLC]
[35.243.158.138][138.158.243.35.bc.googleusercontent.com]
Action: BLocKed
Hacking... Unauthorized attempts to access the server.
Web App Attack -> Attempts to probe for or exploit installed web applications such as a CMS like WordPress/Drupal, e-commerce solutions, forum software, phpMyA]
...
show less
Hacking
Web App Attack
๐ฎ๐น
VHosting
2026-08-24 11:05:04
(1 day ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
factor1
2026-08-24 08:07:51
(1 day ago)
CrowdSec at sherman Reports Abuse
Web App Attack
๐บ๐ธ
snappic
2026-08-23 14:17:19
(2 days ago)
Scanning for config [GET /config.json.js] [meta-externalagent/1.1 (+https://developers.facebook.com/ ...
show more
Scanning for config [GET /config.json.js] [meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)]
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
updown.io
2026-08-23 10:57:48
(2 days ago)
{"level":"info","ts":1787482664.8692305,"logger":"http.log.access.log1","msg":"handled request","req ...
show more
{"level":"info","ts":1787482664.8692305,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"35.243.158.138","remote_port":"53376","client_ip":"35.243.158.138","proto":"HTTP/2.0","method":"GET","host":"status.markavo.com","uri":"/rclone.conf","headers":{"User-Agent":["Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; Claude-User/1.0; +mailto:[email protected] "],"Accept-Encoding":["gzip, deflate"],"Accept":["*/*"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"h2","server_name":"status.markavo.com","ech":false}},"bytes_read":0,"user_id":"","duration":0.000185093,"size":0,"status":429,"resp_headers":{"Server":["Caddy"],"Alt-Svc":["h3=\":443\"; ma=2592000"],"Retry-After":["1"]}}
{"level":"info","ts":1787482664.8694987,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"35.243.158.138","remote_port":"53376","client_ip":"35.243.158.138","proto":"HTTP/2.0","method":"GET","host":"status.markavo.com","
...
show less
DDoS Attack
Web App Attack
๐ฒ๐ฝ
octageeks.com
2026-08-23 04:06:30
(3 days ago)
Wordpress malicious attack:[octablocked]
Web App Attack
๐ซ๐ท
Baking333
2026-08-22 14:20:52
(3 days ago)
[redacted] 35.243.158.138 - - [22/Aug/2026:15:20:50 +0100] "GET /[redacted] HTTP/2.0" 307 64 "-" "CC ...
show more
[redacted] 35.243.158.138 - - [22/Aug/2026:15:20:50 +0100] "GET /[redacted] HTTP/2.0" 307 64 "-" "CCBot/2.0 (https://[redacted]/faq/)" [redacted] 35.243.158.138 - - [22/Aug/2026:15:20:50 +0100] "GET /.[redacted] HTTP/2.0" 307 41 "-" "CCBot/2.0 (https://[redacted]/faq/)"
show less
Bad Web Bot
Web App Attack
๐ฎ๐น
CoreTech srl
2026-08-22 11:08:56
(3 days ago)
cloudlinux2 fail2ban: 2026-08-22 13:05:18,914 fail2ban.filter [1480]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-08-22 13:05:18,914 fail2ban.filter [1480]: INFO [plesk-modsecurity] Found 104.207.53.7 - 2026-08-22 13:05:18cloudlinux2 fail2ban: 2026-08-22 13:05:37,262 fail2ban.filter [1480]: INFO [plesk-apache] Found 65.111.23.168 - 2026-08-22 13:05:36cloudlinux2 fail2ban: 2026-08-22 13:06:31,019 fail2ban.filter [1480]: INFO [plesk-modsecurity] Found 35.243.158.138 - 2026-08-22 13:06:30cloudlinux2 fail2ban: 2026-08-22 13:06:31,035 fail2ban.filter [1480]: INFO [plesk-modsecurity] Found 35.243.158.138 - 2026-08-22 13:06:30cloudlinux2 fail2ban: 2026-08-22 13:06:31,070 fail2ban.filter [1480]: INFO [plesk-modsecurity] Found 35.243.158.138 - 2026-08-22 13:06:31cloudlinux2 fail2ban: 2026-08-22 13:06:31,175 fail2ban.filter [1480]: INFO [plesk-modsecurity] Found 35.243.158.138 - 2026-08-22 13:06:31cloudlinux2 fail2ban: 2026-08-22 13:06:31,191 fail2ban.filter [1480]: INFO [plesk-modsecurity] Found 35.243.158.138 - 2026-08-22 13:0
show less
Brute-Force