🇺🇸
TPI-Abuse
2026-09-08 11:13:50
(42 minutes ago)
(mod_security) mod_security (id:210492) triggered by 35.185.169.172 (172.169.185.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.185.169.172 (172.169.185.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 07:13:44.716591 2026] [security2:error] [pid 8347:tid 8347] [client 35.185.169.172:43776] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.pcga.golf"] [uri "/@fs/.env"] [unique_id "ap_t6OENktzmRagQ3UwREwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 10:51:01
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.185.169.172 (172.169.185.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.185.169.172 (172.169.185.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 06:50:56.186701 2026] [security2:error] [pid 13028:tid 13028] [client 35.185.169.172:18870] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.karohali.chevronparkett.com"] [uri "/@fs/app/.env"] [unique_id "ap_okMelByGepETREBR4VgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
webanyone
2026-09-08 10:02:13
(1 hour ago)
Repeated 404 errors, blocked by Fail2ban in custom-404 jail
Bad Web Bot
🇬🇧
consul.to
2026-09-08 09:43:38
(2 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 09:36:18
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.185.169.172 (172.169.185.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.185.169.172 (172.169.185.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 05:36:14.395402 2026] [security2:error] [pid 14523:tid 14523] [client 35.185.169.172:49752] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mexicanfriedicecreammix.com"] [uri "/@fs/root/.env"] [unique_id "ap_XDszwgHq9ypI8OWWt0QAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
webanyone
2026-09-08 09:32:44
(2 hours ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
🇫🇷
Octopuce
2026-09-08 09:24:35
(2 hours ago)
Aggressive web search of vulnerable pages: /_nuxt/../.env /.docker/.env /img../.env /v2/.env /app/.e ...
show more
Aggressive web search of vulnerable pages: /_nuxt/../.env /.docker/.env /img../.env /v2/.env /app/.env ...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 09:00:41
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.185.169.172 (172.169.185.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.185.169.172 (172.169.185.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 05:00:37.013610 2026] [security2:error] [pid 25279:tid 25389] [client 35.185.169.172:16502] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.thatspecial.com"] [uri "/@fs/.env"] [unique_id "ap_OtcLcWewEgJa27nJ_EwAAANU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 08:40:20
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.185.169.172 (172.169.185.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.185.169.172 (172.169.185.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 04:40:16.636619 2026] [security2:error] [pid 18680:tid 18680] [client 35.185.169.172:38972] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.kochcreative.com"] [uri "/@fs/app/.env"] [unique_id "ap_J8Ghw5q3tjylDErXOPgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 08:35:13
(3 hours ago)
Bot / seems abusive / Apache connections: 48
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
🇧🇪
cmbplf
2026-09-08 08:24:48
(3 hours ago)
3.668 requests with url.path */@fs/*
898 requests with url.path *.aws/*
625 requests with url.pat ...
show more
3.668 requests with url.path */@fs/*
898 requests with url.path *.aws/*
625 requests with url.path *config.json
598 requests with url.path *credentials.json
594 requests with url.path *.config/*
293 requests with url.path */proc/*
260 requests with url.path *.ssh/*
232 requests with url.path *.azure/*
154 requests with url.path */auth.json
106 requests with url.path *config.php
show less
Brute-Force
Bad Web Bot
🇲🇾
Rizzy
2026-09-08 08:05:14
(3 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
🇳🇱
Site.eu
2026-09-08 07:59:09
(3 hours ago)
Excessive multi-domain requests
Brute-Force
🇺🇸
TPI-Abuse
2026-09-08 06:34:15
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.185.169.172 (172.169.185.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.185.169.172 (172.169.185.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 02:34:11.705037 2026] [security2:error] [pid 23296:tid 23296] [client 35.185.169.172:16402] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.dadhania.net"] [uri "/@fs/.env"] [unique_id "ap-sY-DVzoWGeIOzOv9ZxAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 06:01:10
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.185.169.172 (172.169.185.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.185.169.172 (172.169.185.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 02:01:02.354327 2026] [security2:error] [pid 14332:tid 14332] [client 35.185.169.172:36674] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.cdhcreations.com"] [uri "/@fs/app/.env"] [unique_id "ap-kng-UC-nsY9_segQhIwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack