๐บ๐ธ
TPI-Abuse
2026-09-02 18:15:08
(11 minutes ago)
(mod_security) mod_security (id:210730) triggered by 35.253.138.190 (190.138.253.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.253.138.190 (190.138.253.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 14:14:56.660860 2026] [security2:error] [pid 22139:tid 22139] [client 35.253.138.190:44544] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.usaangelinvestors.com|F|2"] [data ".env.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.usaangelinvestors.com"] [uri "/.env.bak"] [unique_id "aphnoBipbhdYzNFh0E4iHQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Octopuce
2026-09-02 17:55:01
(32 minutes ago)
Aggressive web search of vulnerable pages: /.env /.env.local /app/.env /apps/.env /api/.env ...
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 17:29:23
(57 minutes ago)
(mod_security) mod_security (id:210492) triggered by 35.253.138.190 (190.138.253.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.253.138.190 (190.138.253.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 13:29:16.148874 2026] [security2:error] [pid 9081:tid 9081] [client 35.253.138.190:48082] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.us-war-crimes-commission.blackjobsnetwork.com"] [uri "/.git/config"] [unique_id "aphc7FOr80snK5W5mR2rZQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
openstrike.co.uk
2026-09-02 05:13:45
(13 hours ago)
251 attacks on PHP URLs, config grabbing URLs (type 2), VC URLs, env grabbing URLs:
GET /includes/ph ...
show more
251 attacks on PHP URLs, config grabbing URLs (type 2), VC URLs, env grabbing URLs:
GET /includes/phpinfo.php HTTP/1.1
GET /application_default_credentials.json HTTP/1.1
GET /.git/config HTTP/1.1
GET /config/app/.env HTTP/1.1
show less
Web App Attack
Hacking
๐ณ๐ฑ
ConsulHosting
2026-09-02 01:26:36
(17 hours ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 00:25:34
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.253.138.190 (190.138.253.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.253.138.190 (190.138.253.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 20:25:26.796803 2026] [security2:error] [pid 2782:tid 2782] [client 35.253.138.190:42500] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.unitedletter.com"] [uri "/.git/config"] [unique_id "apds9shsNzIKmRdtA9NxMgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 23:25:05
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.253.138.190 (190.138.253.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.253.138.190 (190.138.253.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 19:25:00.378732 2026] [security2:error] [pid 3833:tid 3833] [client 35.253.138.190:44492] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.united-kingdom-boat-registration.com.boatregistrationdelaware.com"] [uri "/.git/config"] [unique_id "apdezBxreGBhEWQvRdTZSAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Savvii
2026-09-01 22:53:40
(19 hours ago)
20 attempts against mh-misbehave-ban on grass
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 22:13:55
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.253.138.190 (190.138.253.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.253.138.190 (190.138.253.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 18:13:50.283165 2026] [security2:error] [pid 17089:tid 17089] [client 35.253.138.190:42964] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.uniquetreasuresshops.com.uniquetreasuresshoppes.com"] [uri "/.git/config"] [unique_id "apdOHtO08MEL19qFR6HfygAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-09-01 22:00:34
(20 hours ago)
Auto-ban: >3000 req/min op 2026-09-01
Web App Attack
SSH
Hacking
๐ณ๐ฑ
Site.eu
2026-09-01 21:08:59
(21 hours ago)
Excessive 404/403 errors
Brute-Force
๐ฎ๐น
VHosting
2026-09-01 18:40:08
(23 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-01 18:07:07
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
Anonymous
2026-09-01 17:45:03
(1 day ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 17:42:31
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.253.138.190 (190.138.253.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.253.138.190 (190.138.253.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 13:42:27.090532 2026] [security2:error] [pid 8923:tid 8943] [client 35.253.138.190:35140] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.unificationalliance.com.nothingwithoutwater.com"] [uri "/.git/config"] [unique_id "apcOg4Y5PjPDbSgxpFfk_gAAAUE"]
show less
Brute-Force
Bad Web Bot
Web App Attack