๐บ๐ธ
TPI-Abuse
2026-10-02 15:44:13
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 35.243.88.127 (127.88.243.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.243.88.127 (127.88.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 11:44:06.906520 2026] [security2:error] [pid 7509:tid 7518] [client 35.243.88.127:54786] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.tnccivic.org"] [uri "/.env"] [unique_id "ar_RRk7cokDQjAL-PP-UeQAAAIc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Campus France
2026-10-02 15:35:54
(4 days ago)
[Fri Oct 02 17:35:45.363096 2026] [php:error] [pid 4004154] [client 35.243.88.127:53292] script '/va ...
show more
[Fri Oct 02 17:35:45.363096 2026] [php:error] [pid 4004154] [client 35.243.88.127:53292] script '/var/www/html/brume.org/document.php' not found or unable to stat
[Fri Oct 02 17:35:51.495993 2026] [php:error] [pid 4004123] [client 35.243.88.127:53384] script '/var/www/html/brume.org/pi.php' not found or unable to stat
[Fri Oct 02 17:35:52.255630 2026] [php:error] [pid 4004437] [client 35.243.88.127:53374] script '/var/www/html/brume.org/test.php' not found or unable to stat
[Fri Oct 02 17:35:52.856267 2026] [php:error] [pid 4004439] [client 35.243.88.127:53404] script '/var/www/html/brume.org/i.php' not found or unable to stat
[Fri Oct 02 17:35:53.588514 2026] [php:error] [pid 4004437] [client 35.243.88.127:53374] script '/var/www/html/brume.org/phpinfo.php' not found or unable to stat
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
factor1
2026-10-02 15:30:43
(4 days ago)
CrowdSec at saturn Reports Abuse
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 14:54:36
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 35.243.88.127 (127.88.243.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.243.88.127 (127.88.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 10:54:33.073295 2026] [security2:error] [pid 4874:tid 4874] [client 35.243.88.127:44912] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.americanacademyofteachersofsinging.org"] [uri "/.git/config"] [unique_id "ar_FqSN9uE8znEnjqN5vGQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
IndigoRidge
2026-10-02 14:01:04
(4 days ago)
35.243.88.127 - - [02/Oct/2026:10:00:59 -0400] "GET /api/console/api_server?sense_version=%40%40SENS ...
show more
35.243.88.127 - - [02/Oct/2026:10:00:59 -0400] "GET /api/console/api_server?sense_version=%40%40SENSE_VERSION&apis=../../../../../../.env HTTP/1.1" 403 21980 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)"
35.243.88.127 - - [02/Oct/2026:10:01:02 -0400] "GET /api/fs/read?allowOutsideWorkspace=true&path=/app/.env HTTP/1.1" 301 4898 "-" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)"
35.243.88.127 - - [02/Oct/2026:10:01:03 -0400] "GET /cache/original/%2e%2e/.env HTTP/1.1" 301 4851 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1)"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 13:51:57
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 35.243.88.127 (127.88.243.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.243.88.127 (127.88.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 09:51:50.606431 2026] [security2:error] [pid 6289:tid 6289] [client 35.243.88.127:43740] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.blackriverarc.org"] [uri "/.htpasswd"] [unique_id "ar-29oulSDaiAa8ar_coDgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-02 13:40:49
(4 days ago)
35.243.88.127 - - [02/Oct/2026:02:57:55 -0500] "GET /.env.test HTTP/1.1" 403 199 "-" "Mozilla/5.0 (c ...
show more
35.243.88.127 - - [02/Oct/2026:02:57:55 -0500] "GET /.env.test HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)" 35.243.88.127
35.243.88.127 - - [02/Oct/2026:02:57:55 -0500] "GET /.env.development HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)" 35.243.88.127
35.243.88.127 - - [02/Oct/2026:02:57:55 -0500] "GET /.env.staging HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36" 35.243.88.127
35.243.88.127 - - [02/Oct/2026:02:57:55 -0500] "GET /.env.production.bak HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)" 35.243.88.127
35.243.88.127 - - [02/Oct/2026:02:57:55 -0500] "GET /.env.docker HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36" 35.243.88.127
35.243.88.127 - - [02/Oct/2026:02:57:55 -0500] "GET /.env.prod.bak HTTP/1.1" 403 199 "-" "Mozilla/5.0 AppleWeb
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 13:36:41
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 35.243.88.127 (127.88.243.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.243.88.127 (127.88.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 09:36:33.887239 2026] [security2:error] [pid 20144:tid 20144] [client 35.243.88.127:46468] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/Web.config" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.horneman.org"] [uri "/web.config"] [unique_id "ar-zYT9VoKJzAy8lRkXzXwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 13:19:07
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 35.243.88.127 (127.88.243.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.243.88.127 (127.88.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 09:19:03.534425 2026] [security2:error] [pid 22240:tid 22240] [client 35.243.88.127:56840] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.theseventhcongregationofladderdayvixens.org"] [uri "/.env.development"] [unique_id "ar-vR7pL7C1WLjNjcroV2wAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
IndigoRidge
2026-10-02 12:43:44
(4 days ago)
35.243.88.127 - - [02/Oct/2026:08:43:42 -0400] "GET /api/console/api_server?sense_version=%40%40SENS ...
show more
35.243.88.127 - - [02/Oct/2026:08:43:42 -0400] "GET /api/console/api_server?sense_version=%40%40SENSE_VERSION&apis=../../../../../../.env HTTP/1.1" 404 40188 "https://southlandproperties.org/api/console/api_server?sense_version=%40%40SENSE_VERSION&apis=../../../../../../.env" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] )"
35.243.88.127 - - [02/Oct/2026:08:43:43 -0400] "GET /api/fs/read?allowOutsideWorkspace=true&path=/app/.env HTTP/1.1" 404 40188 "https://southlandproperties.org/api/fs/read?allowOutsideWorkspace=true&path=/app/.env" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)"
35.243.88.127 - - [02/Oct/2026:08:43:43 -0400] "GET /cache/original/%2e%2e/.env HTTP/1.1" 404 40188 "https://southlandproperties.org/cache/original/%2e%2e/.env" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 12:33:00
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 35.243.88.127 (127.88.243.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.243.88.127 (127.88.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 08:32:57.039259 2026] [security2:error] [pid 12200:tid 12200] [client 35.243.88.127:44064] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.thepinman.org"] [uri "/wp-config.php.old"] [unique_id "ar-kednQV1REk48dofTgsQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
polycoda
2026-10-02 12:04:26
(4 days ago)
AutoBlock: ๐ก Port Scan (Non Decay-Based) - โ Excessive 40X Errors (Decay-Based)
Port Scan
Bad Web Bot
Anonymous
2026-10-02 12:03:48
(4 days ago)
Web Attack Next.js Authorization Bypass Vulnerability
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 11:49:19
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 35.243.88.127 (127.88.243.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.243.88.127 (127.88.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 07:49:13.486661 2026] [security2:error] [pid 23672:tid 23672] [client 35.243.88.127:58462] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.lunchtimers.org"] [uri "/%2e%2e/%2e%2e/%2e%2e/%2e%2e/.env"] [unique_id "ar-aObgDyjc4oQNolo9G7AAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
LoneRider
2026-10-02 10:50:51
(4 days ago)
[02/Oct/2026:12:50:51.450791 +0200] ar-Mi9dbZ5IZj8n-jdOPTwAAAAU 35.243.88.127 46510 127.0.0.1 7081
[ ...
show more
[02/Oct/2026:12:50:51.450791 +0200] ar-Mi9dbZ5IZj8n-jdOPTwAAAAU 35.243.88.127 46510 127.0.0.1 7081
[02/Oct/2026:12:50:51.455659 +0200] ar-MiwLsw14co-ST9JBqzgAAAAk 35.243.88.127 46516 127.0.0.1 7081
[02/Oct/2026:12:50:51.458793 +0200] ar-Mi_tJVn7Ja35Mjty1egAAAAE 35.243.88.127 46526 127.0.0.1 7081
...
show less
Hacking