๐บ๐ธ
TPI-Abuse
2026-09-16 11:41:04
(18 minutes ago)
(mod_security) mod_security (id:210492) triggered by 35.243.232.124 (124.232.243.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.243.232.124 (124.232.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 07:40:59.208032 2026] [security2:error] [pid 2577837:tid 2577837] [client 35.243.232.124:54638] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.sf2g.com.mrcd.org"] [uri "/.git/config"] [unique_id "aqqAS33rxhh4YEdpA0086gAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฟ
UltimWeb
2026-09-16 11:23:35
(36 minutes ago)
Fail2ban_apache-auth
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2026-09-16 11:05:04
(54 minutes ago)
Scanning/Probing (11)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 10:50:06
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.243.232.124 (124.232.243.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.243.232.124 (124.232.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 06:50:00.175924 2026] [security2:error] [pid 28020:tid 28020] [client 35.243.232.124:37470] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.seychelles-boat-registration.com.boatregistrationdelaware.com"] [uri "/.git/config"] [unique_id "aqp0WL9eVYpT7yssyGUUlQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-09-16 10:20:09
(1 hour ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ฉ๐ช
yitzhaq
2026-09-16 10:17:51
(1 hour ago)
35.243.232.124 - - [16/Sep/2026:12:17:46 +0200] "GET /.env.test HTTP/1.1" 307 627 "-" "Mozilla/5.0 ( ...
show more
35.243.232.124 - - [16/Sep/2026:12:17:46 +0200] "GET /.env.test HTTP/1.1" 307 627 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.243.232.124 - - [16/Sep/2026:12:17:47 +0200] "GET /.env.remote HTTP/1.1" 307 631 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.243.232.124 - - [16/Sep/2026:12:17:47 +0200] "GET /.env.bak HTTP/1.1" 307 625 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.243.232.124 - - [16/Sep/2026:12:17:47 +0200] "GET /.env.backup HTTP/1.1" 307 631 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.243.232.124 - - [16/Sep/2026:12:17:47 +0200] "GET /.env.save HTTP/1.1" 307 627 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.243.232.124 - - [16/Sep/2026:12:17:47 +0200]
show less
Web App Attack
Hacking
๐ซ๐ท
Octopuce
2026-09-16 09:40:17
(2 hours ago)
Aggressive web search of vulnerable pages: /.env /.env.local /app/.env /apps/.env /api/.env ...
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2026-09-16 07:39:34
(4 hours ago)
(modsecurity) srv101 ModSecurity 35.243.232.124 (US/United States/124.232.243.35.bc.googleuserconten ...
show more
(modsecurity) srv101 ModSecurity 35.243.232.124 (US/United States/124.232.243.35.bc.googleusercontent.com): 30 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐ซ๐ท
masterguru
2026-09-16 05:55:28
(6 hours ago)
Remote Command Execution: Unix Command Injection (command without evasion). Pattern match "(?i)(?:b ...
show more
Remote Command Execution: Unix Command Injection (command without evasion). Pattern match "(?i)(?:b (932235-195)
show less
Hacking
๐ณ๐ฑ
Site.eu
2026-09-16 04:33:03
(7 hours ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-16 02:02:22
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.243.232.124 (124.232.243.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.243.232.124 (124.232.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 22:02:19.004906 2026] [security2:error] [pid 22551:tid 22551] [client 35.243.232.124:34048] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.settummanque.net.scoutinsignia.com"] [uri "/.git/config"] [unique_id "aqn4q5caDbs0pmvARJXsygAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 23:25:14
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.243.232.124 (124.232.243.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.243.232.124 (124.232.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 19:25:06.904513 2026] [security2:error] [pid 21002:tid 21002] [client 35.243.232.124:40862] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.sessionsdispensary.com.modeltdr.com"] [uri "/.git/config"] [unique_id "aqnT0pBwnNaE-7gPKZ29mwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ณ
nadnitin
2026-09-15 23:22:22
(12 hours ago)
Automated trigger via Nginx Police. Reason: PATH-PROBER. Trigger Log: 35.243.232.124 - - [16/Sep/202 ...
show more
Automated trigger via Nginx Police. Reason: PATH-PROBER. Trigger Log: 35.243.232.124 - - [16/Sep/2026:04:52:22 +0530] "GET /.env.production HTTP/1.1" 200 2297 Host:"www.sessionmanager.linkpc.net" Backend:"-" RespTime:-s "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 23:04:12
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.243.232.124 (124.232.243.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.243.232.124 (124.232.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 19:04:04.197712 2026] [security2:error] [pid 13858:tid 13858] [client 35.243.232.124:39602] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.seskalee.com.sfsdesignsproductions.com"] [uri "/.git/config"] [unique_id "aqnO5Pbu1tA8UmNoQxSZ5QAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-09-15 22:16:27
(13 hours ago)
[WedSep1600:16:24.0436482026][security2:error][pid2032281:tid2032312][client35.243.232.124:0]ModSecu ...
show more
[WedSep1600:16:24.0436482026][security2:error][pid2032281:tid2032312][client35.243.232.124:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".git\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"610\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"www.sesael.ch.81-17-25-250.cpanel.site\"][uri\"/.git/config\"][unique_id\"aqnDuMdERnc8u7g-2az6QgAAABY\"]
show less
Hacking
Web App Attack