πΊπΈ
TPI-Abuse
2026-09-29 20:27:57
(1 minute ago)
(mod_security) mod_security (id:210492) triggered by 35.245.160.46 (46.160.245.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.245.160.46 (46.160.245.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 16:27:52.648083 2026] [security2:error] [pid 17066:tid 17078] [client 35.245.160.46:47244] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.track.ahsdistance.org"] [uri "/.git/config"] [unique_id "arwfSMuCE5ObDl-HNqsGSQAAAMU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
Charlesiv
2026-09-29 08:01:01
(12 hours ago)
Triggered Cloudflare WAF (linkMaze) from US.
Action taken: LINK_MAZE_INJECTED
ASN: 396982 (Google LL ...
show more
Triggered Cloudflare WAF (linkMaze) from US.
Action taken: LINK_MAZE_INJECTED
ASN: 396982 (Google LLC)
Protocol: HTTP/1.1 (GET method)
Endpoint: /wp-json/gravitysmtp/v1/tests/mock-data
Query: ?page=gravitysmtp-settings
Timestamp: 2026-09-29T07:30:25Z
Ray ID: a429484ebc8ed6a8
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0 Safari/537.36
show less
Bad Web Bot
πΊπΈ
[email protected]
2026-09-29 07:09:16
(13 hours ago)
CrowdSec ban: crowdsecurity/appsec-vpatch on unknown-host (duration 4h)
Web App Attack
π©πͺ
lolyay
2026-09-29 06:26:56
(14 hours ago)
35.245.160.46 - - [29/Sep/2026:06:26:54 +0000] "GET /.git/config HTTP/1.1" 403 195 "-" "Mozilla/5.0 ...
show more
35.245.160.46 - - [29/Sep/2026:06:26:54 +0000] "GET /.git/config HTTP/1.1" 403 195 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.245.160.46 - - [29/Sep/2026:06:26:55 +0000] "GET /.env HTTP/1.1" 403 195 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Web App Attack
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-09-29 00:00:29
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.245.160.46 (46.160.245.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.245.160.46 (46.160.245.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 20:00:23.678416 2026] [security2:error] [pid 20543:tid 20543] [client 35.245.160.46:51410] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.mountararattrek.com"] [uri "/.git/config"] [unique_id "arr_l4o0V1NIAI5LpK18iAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-28 05:33:32
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.245.160.46 (46.160.245.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.245.160.46 (46.160.245.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 01:33:28.721340 2026] [security2:error] [pid 16504:tid 16504] [client 35.245.160.46:44956] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pinkrays.com"] [uri "/.git/config"] [unique_id "arn8KJonQSoOUg_S4YhQIgAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Alt255
2026-09-28 04:07:14
(1 day ago)
[ti-07al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-07al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 35.245.160.46 - - [28/Sep/2026:06:06:58 +0200] "GET /.git/config HTTP/1.1" 404 2105 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
π©πͺ
NihiliousMonk
2026-09-27 15:36:54
(2 days ago)
Fail2Ban report from jail npm-scanners
Bad Web Bot
Web App Attack
π©πͺ
outputblog.de
2026-09-27 06:08:39
(2 days ago)
apache-noscript
Hacking
Brute-Force
Web App Attack
Anonymous
2026-09-26 22:25:22
(2 days ago)
(NGINX) Security rule triggered from 35.245.160.46 (US/United States/46.160.245.35.bc.googleusercont ...
show more
(NGINX) Security rule triggered from 35.245.160.46 (US/United States/46.160.245.35.bc.googleusercontent.com): 5 in the last 3600 secs
show less
Web App Attack
Anonymous
2026-09-26 11:11:02
(3 days ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
Anonymous
2026-09-26 08:08:10
(3 days ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
π¦πΊ
paulshipley.com.au
2026-09-25 00:08:41
(4 days ago)
[Fri Sep 25 10:08:39.624431 2026] [security2:error] [pid 589079] [client 35.245.160.46:60724] [clien ...
show more
[Fri Sep 25 10:08:39.624431 2026] [security2:error] [pid 589079] [client 35.245.160.46:60724] [client 35.245.160.46] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "levellapromotions.com.au"] [uri "/.git/config"] [unique_id "arW7h32K8J9KVgndKzSqeAAAAAI"]
...
show less
Web App Attack
π³π±
Mangelot Hosting
2026-09-24 03:06:35
(5 days ago)
(modsecurity) srv104 ModSecurity 35.245.160.46 (US/United States/46.160.245.35.bc.googleusercontent. ...
show more
(modsecurity) srv104 ModSecurity 35.245.160.46 (US/United States/46.160.245.35.bc.googleusercontent.com): 30 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
π³π±
WeCloudit-Anti-Abuse
2026-09-24 01:27:12
(5 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking