🇧🇪
cmbplf
2026-09-08 22:38:03
(7 hours ago)
1.355 requests with url.path */@fs/*
Brute-Force
Bad Web Bot
🇳🇱
homeshowdomain.nl
2026-09-08 22:03:47
(7 hours ago)
Auto-ban: >3000 req/min op 2026-09-08
Web App Attack
SSH
Hacking
🇺🇸
TPI-Abuse
2026-09-08 20:06:17
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.185.160.128 (128.160.185.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.185.160.128 (128.160.185.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 16:06:10.637998 2026] [security2:error] [pid 32222:tid 32222] [client 35.185.160.128:55290] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.rgvatvrepair.com"] [uri "/@fs/.env"] [unique_id "aqBqsmaflq2VLpEOG5l4_QAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 19:58:21
(9 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-08 19:25:56
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.185.160.128 (128.160.185.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.185.160.128 (128.160.185.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 15:25:49.180895 2026] [security2:error] [pid 26778:tid 26778] [client 35.185.160.128:36790] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.aaabft.com"] [uri "/@fs/.env"] [unique_id "aqBhPfGgQHJDf9oJ0nM5IgAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 19:07:27
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.185.160.128 (128.160.185.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.185.160.128 (128.160.185.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 15:07:23.425488 2026] [security2:error] [pid 11496:tid 11496] [client 35.185.160.128:63728] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.blogs.melton.space"] [uri "/@fs/src/.env"] [unique_id "aqBc6yc0nTTQNFu9ivrqPwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-08 18:58:05
(10 hours ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 18:50:47
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.185.160.128 (128.160.185.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.185.160.128 (128.160.185.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 14:50:39.200187 2026] [security2:error] [pid 11552:tid 11552] [client 35.185.160.128:52030] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.photoservicesgroup.com"] [uri "/@fs/.env"] [unique_id "aqBY_xXtXktkNFcQuMzigwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 18:14:01
(11 hours ago)
PSCSERV WPSCAN 35.185.160.128
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-09-08 18:10:02
(11 hours ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 17:32:40
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.185.160.128 (128.160.185.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.185.160.128 (128.160.185.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 13:32:32.066085 2026] [security2:error] [pid 18929:tid 18929] [client 35.185.160.128:35188] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.markdeacon.com"] [uri "/@fs/root/.env"] [unique_id "aqBGsOKNt-GK4ubMAvkyywAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 16:36:06
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.185.160.128 (128.160.185.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.185.160.128 (128.160.185.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 12:36:02.057327 2026] [security2:error] [pid 21526:tid 21526] [client 35.185.160.128:54810] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.timcsite.com.woosterclassof64.com"] [uri "/@fs/root/.env"] [unique_id "aqA5cvPKpaY4RILDJ8b7TAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-09-08 16:05:59
(13 hours ago)
Scanning/Probing (25)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 15:55:24
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.185.160.128 (128.160.185.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.185.160.128 (128.160.185.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 11:55:19.511506 2026] [security2:error] [pid 30219:tid 30219] [client 35.185.160.128:51540] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.synergystudios.org"] [uri "/@fs/app/.env"] [unique_id "aqAv58GYb2kno35Okc1z6gAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-08 15:44:20
(14 hours ago)
Web attack/malicious scanning detected
Web App Attack