🇺🇸
TPI-Abuse
2026-09-04 04:16:36
(34 minutes ago)
(mod_security) mod_security (id:210492) triggered by 35.185.197.114 (114.197.185.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.185.197.114 (114.197.185.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 00:16:32.279857 2026] [security2:error] [pid 27668:tid 27668] [client 35.185.197.114:33560] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.the-practical-pionus.com"] [uri "/@fs/app/.env"] [unique_id "appGIAf83vbMNdZRAMjVfgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 04:14:20
(36 minutes ago)
35.185.197.114 - - [04/Sep/2026:06:13:44 +0200] "GET /@fs/home/ec2-user/.aws/credentials?raw?? HTTP/ ...
show more
35.185.197.114 - - [04/Sep/2026:06:13:44 +0200] "GET /@fs/home/ec2-user/.aws/credentials?raw?? HTTP/2.0" 404 329
35.185.197.114 - - [04/Sep/2026:06:13:44 +0200] "GET /@fs/home/www-data/.aws/credentials?raw?? HTTP/2.0" 404 287
35.185.197.114 - - [04/Sep/2026:06:13:44 +0200] "GET /@fs/root/.aws/config?raw?? HTTP/2.0" 404 329
35.185.197.114 - - [04/Sep/2026:06:13:44 +0200] "GET /@fs/root/.aws/credentials?raw?? HTTP/2.0" 404 329
35.185.197.114 - - [04/Sep/2026:06:13:44 +0200] "GET /@fs/home/debian/.aws/credentials?raw?? HTTP/2.0" 404 329
35.185.197.114 - - [04/Sep/2026:06:13:44 +0200] "GET /@fs/proc/self/environ?raw?? HTTP/2.0" 404 329
35.185.197.114 - - [04/Sep/2026:06:13:44 +0200] "GET /@fs/..%252f..%252f..%252f..%252f..%252fproc/self/environ?raw?? HTTP/2.0" 404 265
35.185.197.114 - - [04/Sep/2026:06:13:44 +0200] "GET /@fs/home/node/.aws/credentials?raw?? HTTP/2.0" 404 265
35.185.197.114 - - [04/Sep/2026:06:13:44 +0200] "GET /@fs/var/www/html/.aws/credentials?raw?? HTTP/2.0" 404 329
35.1
...
show less
Web Spam
Web App Attack
🇬🇧
OptimusGO
2026-09-04 03:54:24
(56 minutes ago)
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show more
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-09-04 04:54:24 UTC
Log evidence:
35.185.197.114 - - [04/Sep/2026:04:54:19 +0100] "GET / HTTP/1.1" 403 180 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
09/04/2026-04:54:23.222849 [wDrop] [**] [1:7000500:1] FINSERV CRITICAL: Aggressive Port Scan [**] [Classification: Attempted Information Leak] [Priority: 2] {TCP} 35.185.197.114:63134 -> 185.127.18.66:443
09/04/2026-04:54:23.222849 [**] [1:9000060:2] AUTONOMOUS Long-term Reconnaissance [**] [Classification: (null)] [Priority: 2] {TCP} 35.185.197.114:63134 -> 185.127.18.66:443
show less
Port Scan
Brute-Force
🇮🇹
CoreTech srl
2026-09-04 03:28:56
(1 hour ago)
cloudlinux2 fail2ban: 2026-09-04 05:23:59,132 fail2ban.actions [1594]: NOTICE [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-04 05:23:59,132 fail2ban.actions [1594]: NOTICE [plesk-modsecurity] Unban 151.240.104.89cloudlinux2 fail2ban: 2026-09-04 05:24:53,173 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 35.185.197.114 - 2026-09-04 05:24:53cloudlinux2 fail2ban: 2026-09-04 05:24:53,244 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 35.185.197.114 - 2026-09-04 05:24:53cloudlinux2 fail2ban: 2026-09-04 05:24:53,194 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 35.185.197.114 - 2026-09-04 05:24:53cloudlinux2 fail2ban: 2026-09-04 05:24:53,261 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 35.185.197.114 - 2026-09-04 05:24:53cloudlinux2 fail2ban: 2026-09-04 05:24:53,210 fail2ban.actions [1594]: NOTICE [plesk-modsecurity] Ban 35.185.197.114cloudlinux2 fail2ban: 2026-09-04 05:24:53,227 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 35.185.197.114 - 2026-09-04 05:24:53cloudlinux2 fail2ban: 2026-09-04 0
show less
Brute-Force
🇺🇸
TPI-Abuse
2026-09-04 03:13:37
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.185.197.114 (114.197.185.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.185.197.114 (114.197.185.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 23:13:30.300420 2026] [security2:error] [pid 10821:tid 10821] [client 35.185.197.114:45116] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.emrob.com"] [uri "/@fs/app/.env"] [unique_id "apo3WhF3Uy8racnOU7w6LwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
BlueWire Hosting
2026-09-04 02:19:47
(2 hours ago)
High-confidence malicious configuration/VCS probe
Web App Attack
Anonymous
2026-09-04 02:05:05
(2 hours ago)
WAF repeated trigger detected by Fail2Ban
Web App Attack
🇳🇱
e.fierstra
2026-09-04 01:38:22
(3 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 01:21:30
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.185.197.114 (114.197.185.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.185.197.114 (114.197.185.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 21:21:23.813215 2026] [security2:error] [pid 20362:tid 20362] [client 35.185.197.114:18702] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.cherryblossomplayers.com"] [uri "/@fs/app/.env"] [unique_id "apodE4D5JvRLR7eNN1ICnwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
rubixstudios
2026-09-04 01:07:03
(3 hours ago)
Excessive HTTP requests consistent with automated attack behaviour detected by Imunify360
DDoS Attack
Brute-Force
Web App Attack
🇬🇧
andypiper
2026-09-04 01:00:53
(3 hours ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
🇲🇾
Rizzy
2026-09-04 00:40:58
(4 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 00:40:38
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.185.197.114 (114.197.185.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.185.197.114 (114.197.185.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 20:40:30.318912 2026] [security2:error] [pid 26297:tid 26297] [client 35.185.197.114:27250] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.randomgroovemusic.com"] [uri "/@fs/app/.env"] [unique_id "apoTfobEaKgAgLxqBWWEfQAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
eposs-it.de
2026-09-04 00:15:12
(4 hours ago)
Blocked by os-abuseipdb; 12 hits, proto=tcp, ports=443,80
Port Scan
Hacking
Anonymous
2026-09-04 00:08:12
(4 hours ago)
Multiple web server 400 error codes from same source ip
Web App Attack