๐บ๐ธ
TPI-Abuse
2026-08-31 15:00:38
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.247.186.140 (140.186.247.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.247.186.140 (140.186.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 11:00:33.155154 2026] [security2:error] [pid 19781:tid 19781] [client 35.247.186.140:43754] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.trade.dodojuice.com"] [uri "/.git/config"] [unique_id "apWXEQHrYgwEuGiySMyttQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-31 14:15:21
(7 hours ago)
IP banned by Fail2Ban in jail nginx-abusive-ips
Web App Attack
Brute-Force
Bad Web Bot
๐ฎ๐น
CoreTech srl
2026-08-31 13:38:56
(7 hours ago)
cloudlinux2 fail2ban: 2026-08-31 15:34:04,097 fail2ban.actions [1605]: NOTICE [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-08-31 15:34:04,097 fail2ban.actions [1605]: NOTICE [plesk-modsecurity] Unban 35.200.11.248cloudlinux2 fail2ban: 2026-08-31 15:35:11,765 fail2ban.filter [1605]: INFO [plesk-modsecurity] Found 34.29.150.20 - 2026-08-31 15:35:11cloudlinux2 fail2ban: 2026-08-31 15:35:55,453 fail2ban.actions [1605]: NOTICE [plesk-modsecurity] Unban 59.184.150.215cloudlinux2 fail2ban: 2026-08-31 15:36:00,080 fail2ban.filter [1605]: INFO [recidive] Found 35.247.186.140 - 2026-08-31 15:36:00cloudlinux2 fail2ban: 2026-08-31 15:35:59,783 fail2ban.filter [1605]: INFO [plesk-modsecurity] Found 35.247.186.140 - 2026-08-31 15:35:59cloudlinux2 fail2ban: 2026-08-31 15:35:59,618 fail2ban.filter [1605]: INFO [plesk-modsecurity] Found 35.247.186.140 - 2026-08-31 15:35:59cloudlinux2 fail2ban: 2026-08-31 15:35:59,950 fail2ban.filter [1605]: INFO [plesk-modsecurity] Found 35.247.186.140 - 2026-08-31 15:35:59cloudlinux2 fail2ban: 2026-08-31 15:35:59,33
show less
Brute-Force
Anonymous
2026-08-31 11:27:31
(10 hours ago)
35.247.186.140 - - [31/Aug/2026:13:27:26 +0200] "GET /phpinfo.php HTTP/1.1" 404 196 "-" "Mozilla/5.0 ...
show more
35.247.186.140 - - [31/Aug/2026:13:27:26 +0200] "GET /phpinfo.php HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.247.186.140 - - [31/Aug/2026:13:27:26 +0200] "GET /info.php HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.247.186.140 - - [31/Aug/2026:13:27:26 +0200] "GET /php.php HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.247.186.140 - - [31/Aug/2026:13:27:26 +0200] "GET /i.php HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.247.186.140 - - [31/Aug/2026:13:27:26 +0200] "GET /pi.php HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.247.1
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 11:24:18
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.247.186.140 (140.186.247.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.247.186.140 (140.186.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 07:24:10.660105 2026] [security2:error] [pid 18656:tid 18656] [client 35.247.186.140:46338] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.toyboxmotorsports.thelowensteinfamily.com"] [uri "/.git/config"] [unique_id "apVkWthlfG08KYEmU-5evwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-31 11:05:37
(10 hours ago)
GET /.git/config HTTP/1.1
...
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-08-31 09:12:59
(12 hours ago)
Try to access /.git/config
Web App Attack
๐ณ๐ฑ
Site.eu
2026-08-31 09:05:22
(12 hours ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-31 08:39:04
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.247.186.140 (140.186.247.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.247.186.140 (140.186.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 04:38:56.104697 2026] [security2:error] [pid 6571:tid 6571] [client 35.247.186.140:59104] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.touchmypython.bwill.dev"] [uri "/.git/config"] [unique_id "apU9oJOX_39DtdoluAgkHAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐ด
clauss
2026-08-31 08:18:49
(13 hours ago)
35.247.186.140 - - [31/Aug/2026:11:18:49 +0300] "GET /phpinfo.php HTTP/2.0" 404 20 "-" "Mozilla/5.0 ...
show more
35.247.186.140 - - [31/Aug/2026:11:18:49 +0300] "GET /phpinfo.php HTTP/2.0" 404 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.247.186.140 - - [31/Aug/2026:11:18:49 +0300] "GET /info.php HTTP/2.0" 404 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 06:50:43
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.247.186.140 (140.186.247.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.247.186.140 (140.186.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 02:50:34.466130 2026] [security2:error] [pid 6716:tid 6725] [client 35.247.186.140:34016] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.totalbodycare753.kylight.com"] [uri "/.git/config"] [unique_id "apUkOh806Fll7K-ZZEQqBgAAAMc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-08-31 06:47:08
(14 hours ago)
[MonAug3108:47:01.5621352026][security2:error][pid1673334:tid1673813][client35.247.186.140:0]ModSecu ...
show more
[MonAug3108:47:01.5621352026][security2:error][pid1673334:tid1673813][client35.247.186.140:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".git\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"610\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"www.total360.ch.81-17-25-250.cpanel.site\"][uri\"/.git/config\"][unique_id\"apUjZR5dZFv7pVdc1_BQOQAAAM4\"]
show less
Hacking
Web App Attack
Anonymous
2026-08-31 06:42:04
(14 hours ago)
Bot / scanning and/or hacking attempts: GET /.env.backup HTTP/1.1, GET / HTTP/1.1, GET /.env.docker ...
show more
Bot / scanning and/or hacking attempts: GET /.env.backup HTTP/1.1, GET / HTTP/1.1, GET /.env.docker HTTP/1.1, GET /.env.preprod HTTP/1.1, GET /.git/config HTTP/1.1, GET /.env~ HTTP/1.1, GET /.env.swp HTTP/1.1, GET /.env2 HTTP/1.1, GET /.env.old HTTP/1.1, GET /.env.stage HTTP/1.1, GET /.env.ci HTTP/1.1, GET /.env1 HTTP/1.1, GET /.env.uat HTTP/1.1, GET /.env.live HTTP/1.1, GET /.env.dist HTTP/1.1
show less
Hacking
Web App Attack
๐ฉ๐ช
4server
2026-08-31 05:53:14
(15 hours ago)
[MonAug3107:53:08.5337912026][security2:error][pid2270389:tid2270479][client35.247.186.140:0]ModSecu ...
show more
[MonAug3107:53:08.5337912026][security2:error][pid2270389:tid2270479][client35.247.186.140:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"www.torrimonda.ch.136-243-54-122.cpanel.site\"][uri\"/.env.bak\"][unique_id\"apUWxLauPeG97sSeX_S3QQAAAQ0\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 05:50:30
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.247.186.140 (140.186.247.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.247.186.140 (140.186.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 01:50:23.659948 2026] [security2:error] [pid 20303:tid 20303] [client 35.247.186.140:51708] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.torresyrellenos.com.disenowebprofesional.com"] [uri "/.git/config"] [unique_id "apUWH8bvq73PVKN48zQ4jQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack