๐ฉ๐ช
FeG Deutschland
2026-09-21 06:15:15
(9 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 247
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 06:10:05
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.243.239.9 (9.239.243.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.243.239.9 (9.239.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 02:09:55.697318 2026] [security2:error] [pid 11483:tid 11483] [client 35.243.239.9:33364] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.bridgital.com"] [uri "/userfiles"] [unique_id "arDKMxd4SNmlsXEMJLtLnAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Petros Stefanakis
2026-09-21 05:26:18
(10 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 35.243.239.9 (US/United States/9.239.24 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.243.239.9 (US/United States/9.239.243.35.bc.googleusercontent.com)
show less
SQL Injection
๐บ๐ธ
IndigoRidge
2026-09-21 05:15:20
(10 hours ago)
35.243.239.9 - - [21/Sep/2026:01:15:20 -0400] "GET /@fs/app/.env?raw?? HTTP/1.1" 403 5741 "-" "Mozil ...
show more
35.243.239.9 - - [21/Sep/2026:01:15:20 -0400] "GET /@fs/app/.env?raw?? HTTP/1.1" 403 5741 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36"
35.243.239.9 - - [21/Sep/2026:01:15:20 -0400] "GET /@fs/src/.env?raw?? HTTP/1.1" 403 5741 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)"
35.243.239.9 - - [21/Sep/2026:01:15:20 -0400] "GET /@fs/../.env?raw?? HTTP/1.1" 403 5741 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 05:14:22
(10 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.243.239.9 (9.239.243.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.243.239.9 (9.239.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 01:14:15.996759 2026] [security2:error] [pid 20852:tid 20852] [client 35.243.239.9:55428] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||rahmanou.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "rahmanou.com"] [uri "/z9x8c7v6b5-debug-trigger-rahmanou.com"] [unique_id "arC9J-ThCmS5Pbe7QW0AQQAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ramazan
2026-09-21 04:34:02
(11 hours ago)
Fail2Ban: nginx-4xx | Failures: 10 | Log: /.vite/manifest.json /build/manifest.json /dist/.vite/mani ...
show more
Fail2Ban: nginx-4xx | Failures: 10 | Log: /.vite/manifest.json /build/manifest.json /dist/.vite/manifest.json /dist/manifest.json /key.pem
show less
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-21 03:08:09
(12 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.243.239.9 (9.239.243.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.243.239.9 (9.239.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 23:08:02.436972 2026] [security2:error] [pid 6864:tid 6864] [client 35.243.239.9:48070] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.rannals.com|F|2"] [data ".rannals.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.rannals.com"] [uri "/z9x8c7v6b5-debug-trigger-www.rannals.com"] [unique_id "arCfkjVgAzSCodnWaVD_bAAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 02:26:17
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.243.239.9 (9.239.243.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.243.239.9 (9.239.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 22:26:13.650092 2026] [security2:error] [pid 4345:tid 4345] [client 35.243.239.9:38022] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.rachel-heiko.com.owenmail.com"] [uri "/.env.example"] [unique_id "arCVxdC5FEYcpFECcr2RuQAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-09-21 01:45:04
(14 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 01:35:45
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.243.239.9 (9.239.243.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.243.239.9 (9.239.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 21:35:38.225608 2026] [security2:error] [pid 1472:tid 1472] [client 35.243.239.9:33656] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.quangxpham.com"] [uri "/@fs/src/.env"] [unique_id "arCJ6vzMe-Mh2Z6wMWus9QAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 01:18:55
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.243.239.9 (9.239.243.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.243.239.9 (9.239.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 21:18:46.925952 2026] [security2:error] [pid 7622:tid 7622] [client 35.243.239.9:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.ralphrichardson.com"] [uri "/shop/.env"] [unique_id "arCF9raHJ5xQQJAISfc0cgAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 00:54:04
(15 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.243.239.9 (9.239.243.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.243.239.9 (9.239.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 20:53:59.508644 2026] [security2:error] [pid 13669:tid 13669] [client 35.243.239.9:60958] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.rallentarecg.com|F|2"] [data ".rallentarecg.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.rallentarecg.com"] [uri "/z9x8c7v6b5-debug-trigger-www.rallentarecg.com"] [unique_id "arCAJ56PLvuhVTu3JSV0iwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-21 00:09:07
(15 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 23:59:42
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.243.239.9 (9.239.243.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.243.239.9 (9.239.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 19:59:35.002533 2026] [security2:error] [pid 2052:tid 2052] [client 35.243.239.9:51806] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.psikeep.com"] [uri "/.git/config"] [unique_id "arBzZzbbo8HaKgyAyGPBdAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-20 23:43:16
(16 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking