Anonymous
2026-09-01 07:05:02
(22 minutes ago)
suspicious request in access.log
Web App Attack
π©πͺ
SΓ©fora Srl
2026-09-01 05:45:02
(1 hour ago)
crowdsecurity/http-probing detected by CrowdSec
Web App Attack
Anonymous
2026-09-01 05:09:12
(2 hours ago)
Web scanner: GET /.env.local
Web App Attack
Hacking
π§πΎ
lns.bz
2026-09-01 04:28:36
(2 hours ago)
Too many 404 requests [BY]
Web App Attack
π©πͺ
FD-IX
2026-09-01 04:20:47
(3 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 04:12:40
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.187.23.99 (99.23.187.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.187.23.99 (99.23.187.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 00:12:33.926378 2026] [security2:error] [pid 25922:tid 25922] [client 35.187.23.99:38640] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "villandance.com"] [uri "/.env.save"] [unique_id "apZQsVhO5xF7Y2j1I0hIaAAAACk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
MyGlobalFlowers
2026-09-01 03:16:02
(4 hours ago)
Multiple WAF Violations
Web App Attack
π¬π§
consul.to
2026-09-01 02:38:35
(4 hours ago)
Web attack/malicious scanning detected
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 02:21:08
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.187.23.99 (99.23.187.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.187.23.99 (99.23.187.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 22:21:03.911501 2026] [security2:error] [pid 14217:tid 14217] [client 35.187.23.99:39742] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gransla.com"] [uri "/.env"] [unique_id "apY2j5KiBDfM63bYrkeI6wAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 01:24:33
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.187.23.99 (99.23.187.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.187.23.99 (99.23.187.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 21:24:28.851560 2026] [security2:error] [pid 28779:tid 28779] [client 35.187.23.99:52152] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dryprodrain.com"] [uri "/.env.production"] [unique_id "apYpTCD9kgbuUfAtxcOpVwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΈπͺ
vaia.cloud
2026-09-01 01:15:05
(6 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 01:00:00
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.187.23.99 (99.23.187.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.187.23.99 (99.23.187.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 20:59:55.406286 2026] [security2:error] [pid 30932:tid 30932] [client 35.187.23.99:35288] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "despojosocial.com"] [uri "/.env.production"] [unique_id "apYjixSROk-a0V6VWSa_nQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
Petros Stefanakis
2026-09-01 00:52:23
(6 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 35.187.23.99 (BE/Belgium/99.23.187.35.b ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.187.23.99 (BE/Belgium/99.23.187.35.bc.googleusercontent.com)
show less
SQL Injection
π³πΏ
Tripwire
2026-09-01 00:33:37
(6 hours ago)
Scanning for exploits - /wp-config.php.bak
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 00:29:14
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.187.23.99 (99.23.187.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.187.23.99 (99.23.187.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 20:29:10.467389 2026] [security2:error] [pid 25360:tid 25360] [client 35.187.23.99:50264] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.s1global.net"] [uri "/.env.backup"] [unique_id "apYcVg0UwarC7SeJfWsFKwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack