๐ฉ๐ช
usc-IPDB
2026-09-17 16:24:51
(4 hours ago)
35.252.29.158 - - [17/Sep/2026:18:24:50 +0200] "GET /phpinfo.php HTTP/1.1" 404 181 "-" "Mozilla/5.0 ...
show more
35.252.29.158 - - [17/Sep/2026:18:24:50 +0200] "GET /phpinfo.php HTTP/1.1" 404 181 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.252.29.158 - - [17/Sep/2026:18:24:50 +0200] "GET /info.php HTTP/1.1" 404 181 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.252.29.158 - - [17/Sep/2026:18:24:50 +0200] "GET /php.php HTTP/1.1" 404 181 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-09-17 15:16:01
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.252.29.158 (158.29.252.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.252.29.158 (158.29.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 11:15:57.462124 2026] [security2:error] [pid 27072:tid 27072] [client 35.252.29.158:41574] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.usashooters.gemexpressions.com"] [uri "/.git/config"] [unique_id "aqwELfcxX05mKLd2AaiWRQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 13:54:58
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.252.29.158 (158.29.252.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.252.29.158 (158.29.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 09:54:55.043701 2026] [security2:error] [pid 27496:tid 27496] [client 35.252.29.158:32824] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.usaenquirer.com.bamedica.com"] [uri "/.git/config"] [unique_id "aqvxL3hsmwye3Xnd497ydQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-17 13:50:40
(7 hours ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
Anonymous
2026-09-17 11:02:03
(10 hours ago)
suspicious behavior
Blog Spam
Brute-Force
Web App Attack
๐ฉ๐ช
todix
2026-09-17 08:56:21
(12 hours ago)
WebAttack or semilar from 35.252.29.158
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 08:39:26
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.252.29.158 (158.29.252.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.252.29.158 (158.29.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 04:39:20.065461 2026] [security2:error] [pid 29970:tid 29970] [client 35.252.29.158:37714] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.url.kircali.net"] [uri "/.git/config"] [unique_id "aqunOLDpTv0n1lW9jT8UHQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 08:00:40
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.252.29.158 (158.29.252.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.252.29.158 (158.29.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 04:00:35.958449 2026] [security2:error] [pid 19201:tid 19201] [client 35.252.29.158:39020] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.urie.to.daveewalker.bz"] [uri "/.git/config"] [unique_id "aqueI568Um72TnSmZNmmUgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
๐จ๐ญ Hosting
2026-09-17 05:10:38
(16 hours ago)
Automated WAF report: 200-300 blocked requests from this IP detected by our WAF.
Bad Web Bot
Web App Attack
๐ณ๐ฑ
sernate
2026-09-17 04:54:34
(16 hours ago)
(403blocker) 403 trigger 35.252.29.158 (IL/Israel/158.29.252.35.bc.googleusercontent.com): 80 in the ...
show more
(403blocker) 403 trigger 35.252.29.158 (IL/Israel/158.29.252.35.bc.googleusercontent.com): 80 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER
show less
Brute-Force
๐ณ๐ฑ
ConsulHosting
2026-09-17 04:13:22
(17 hours ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-09-17 04:12:34
(17 hours ago)
csagent: score 19.9: secrets grab x2; 1 domain(s) in 4s
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 04:05:55
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.252.29.158 (158.29.252.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.252.29.158 (158.29.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 00:05:49.314192 2026] [security2:error] [pid 12384:tid 12405] [client 35.252.29.158:38092] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.workingwithseniors.richardleeweatherman.com"] [uri "/.git/config"] [unique_id "aqtnHaV2hC7z1UTUQTqbaQAAAJA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 03:50:09
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.252.29.158 (158.29.252.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.252.29.158 (158.29.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 23:50:02.057066 2026] [security2:error] [pid 31066:tid 31096] [client 35.252.29.158:45370] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.workbykathryn.workconfident.com"] [uri "/.git/config"] [unique_id "aqtjahUa1-CX3gKNQ_jE5gAAAUk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
venus.launch.bz
2026-09-17 03:44:54
(17 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 35.252.29.158 (IL/Israel/158.29.252.35. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.252.29.158 (IL/Israel/158.29.252.35.bc.googleusercontent.com)
show less
SQL Injection